Saturday, August 1, 2020

Ransomware Re-infected from Sensor

Dragonfire Cyber published a report today on a recent ransomware attack on a PLC being used in a safety system at a Louisiana chemical manufacturing plant. There were two unique things about this ransomware attack, the report states. First the ransomware did not encrypt system files, it simply shutdown the safety system and demanded a 100-bitcoin ransom. The second item of interest is that the system was re-infected as soon as the affected PLC was released.

 

The active portion of the ransomware reset the Robotron SicherheitsKontrolle PLC to factory default settings, erasing the programming designed to ensure that the styrene storage tank remained in an inherently safe state. It also erased the control screen on the HMI used by the safety system, replacing the virtual system diagram with the ransomware message.

 

Since the affected system was a safety system, the facility had a preprogramed replacement on hand for both the PLC and the HMI. As soon as the ransomware message was reported, maintenance personnel were contacted and the two devices were replaced within an hour.

 

“The attackers understood how easy it was to replace the affected devices without resorting to paying the ransom,” Kate Libby, spokesperson for Dragonfire, told this reporter; “So they designed their ransomware system so that it would immediately infect the replaced equipment.”

 

The local control system maintenance personnel were not able to find the initial source of the infection or the re-infection. In order to ensure the safety of the facility, the company paid the ransomware and the system was immediately returned to its pre-infection state.

 

Dragonfire was retained to discover the source of the infection, determine how the system was re-infected, and ensure that there were no other problems with the system. The source of the initial infection was the USB that was used to apply the annual system updates for the safety system. The USB, sent from Robotron offices in Germany, was apparently intercepted at the local delivery company office and the infected with the ĀnquánShújīn worm.

 

The USB device was erased when it was removed from the laptop used to update the PLC, but the technician who performed the update copied the update to a backup drive for record keeping purposes. The drive erase program was not transferred as it was hidden USB firmware. The malware programming on the laptop was automatically erased and overwritten with the original update after the safety system was updated.

 

“With a copy of the actual ransomware code on hand, it was easy enough to track down the source of the re-infection,” Libby told me; “A copy of the worm was moved to one of the smart sensors attached to the safety system, in this case a Robotron DSensor”.

 

When the new PLC made initial contact with the infected sensor, the worm reinstalled the malware on the PLC, restarting the whole process.

 

Immanuel C. Securitage, spokesperson for ECS-CERT, said that the malware seen in this attack was much more sophisticated that the GUMMI BAREN ransomware that was seen in earlier attacks on Robotron PLC’s. “Two years allows for a lot of malware advancement,” IC Securitage told this reporter; “We also suspect that there may be a State actor involved which also allows for an entirely different level of sophistication.”

 

The Federal Bureau of Inquiry is reportedly investigating if this incident is the work of the NoReturn group that has been causing problems at a number of chemical companies in the United States. Johnathan Quest refused to comment on that portion of the ongoing investigation, saying: “We are continuing to work with the facility owner, ECS-CERT and Dragonfire on the incident investigation. We currently have no suspects, but we are talking with persons of interest at the GHB Air facility in Shreveport about the Robotron USB delivery.

 

CAUTIONARY NOTE: This is a future news story –


Thursday, July 30, 2020

CyMoTrol Sues ECS-CERT for Libel and Slander

It was announced today that CyMoTrol, a German manufacturer of industrial motor controllers, had filed a libel and slander suit against ECS-CERT for information included in a recent control system cybersecurity alert published by the agency. They are asking for treble damages and punitive damages for publicly disparaging the cybersecurity measures used to protect their motor controllers. The suit also demands that ECS-CERT disclose the identity of the anonymous researcher, cYbrg0D, named in the Alert as the researcher who identified the multiple vulnerabilities so that charges of theft of intellectual property, unlawful access, and industrial espionage can filed on that individual.

 

Wilhelm Pieck, spokesperson for CyMoTrol, said that last week’s alert published by ECS-CERT contained out right lies, fabrications and mischaracterization of device features that had already led to one customer canceling a large order for the CyMo One motor controllers mentioned in the Alert and calls from many irate customers. “ECS-CERT never talked with us about the supposed vulnerabilities,” Pieck told reporters; “If they had we would have explained that the supposed vulnerabilities were carefully controlled features of the devices that improved service and increased production reliability when used in a properly protected industrial environment.”

 

Immanuel C. Securitage, spokesperson for ECS-CERT refused to talk about the pending litigation. He did, however, explain that the agency stood behind the information in the Alert. “Based upon extensive information provided by cYbrg0D, we stand behind the identification of the three vulnerabilities outlined in our Alert,” Securitage told reporters; “And we continue to suggest that device owners face the potential consequences we described for a potential exploit of those vulnerabilities in a production environment.”

 

Shortly after the announcement of the law suit became public cYbrg0D tweeted “CyMoTrol has hard coded backdoors in all of their products and software includes phone-home code to provide info to manufacturer.”

 

When asked about the TWEET® Pieck said “CyMoTrol maintains remote access capabilities in their products for maintenance purposes as part of our customer service program. This includes device reporting of anomalous conditions. These are carefully controlled processes and are an integral part of the service we sell. They are not vulnerabilities and do not provide access to the devices to anyone outside of our organization.”

 

CAUTIONARY NOTE: This is a future news story –


Sunday, July 19, 2020

Control System Ransomware Attack Shuts Down Chem Plant


Blew Bayou Chemical Company announced that it had shut down its Shreveport, LA facility due to a ransomware attack on a control system at the facility. Only one storage tank safety system is currently affected, but the decision was made to shut down the entire plant as a precautionary measure. The Federal Bureau of Inquiry and the ECS-CERT are conducting a joint investigation.

Johnathan Quest, FBI spokesperson, told reporters that since the facility is considered critical infrastructure, a ransomware attack is considered to be a federal crime. “We are working closely with ECS-CERT and the facility owners to determine who is behind this attack;” Quest said.

Immanuel C. Securitage, ECS-CER spokesperson, confirmed that it had investigators onsite.

Issac B Kaghun, CEO of Blew Bayou Chemical, told reporters that the company became aware of the problem when a screen for the safety control system for the styrene monomer tank turned red and an announcement was printed on the screen that said a ransom would have to be paid to regain control of the system. The attackers asked for a ransom of 100 bitcoin for the return of control of the system.

Securitage told reporters: “The screen claimed that the safety PLC for the system was under the control of ‘ĀnquánShújīn’, Chinese for ‘safety ransom’. We have never seen this type of ransomware before.”

An investigator from Dragonfire Cyber working with the ECS-CERT team speaking anonymously said that, instead of encrypting files as is seen in most normal ransomware, the AS ransomware reprogramed the PLC to shutdown all sensors and valve controllers associated with the system.”

Securitage confirmed that the company had removed the affected PLC from the system and replaced it with a preprogramed substitute that was kept on hand for emergency situations. “The replacement worked properly for about five minutes and then it was corrupted as well,” he explained; “That caused us to assume that there was some sort of worm in the system that caused the reinfection. We recommended that the company under take a shutdown of all control systems pending further investigations.”

The company is currently running all safety systems in manual mode.


Monday, July 13, 2020

Army ROWPU Hacked in Iraq

A thread on a logistics discussion board on REDDIT about a water supply issue for a US Army unit in Iraq claims that a cyberattack on a reverse osmosis water purification unity (ROWPU) employed by the 248th Composite Supply Company caused it to stop functioning. Reportedly the Army has had to provide emergency water supplies to the unnamed unit. The Army has refused to comment on the reported incident.

 

The ROWPU is supposed to be a slightly modified version of Robotron Wasseraufbereitungsanlage (WABA) unit. Robotron recently released a security advisory for their WABA unit. According to that advisory there are multiple vulnerabilities in the unit that could be remotely exploited. The advisory explains that exploits could allow the unit to become over pressurized and damage the filtration cartridges.

 

Robotron spokesman Erich Mielke confirmed that the WABA advisory had recently been published on their web site. “The advisory includes mitigation measures to address the vulnerabilities and Robotron continues to work on updated firmware for the equipment,” Mielke said.

 

When asked if the US Army had been notified of the vulnerabilities, Mielke told this reporter: “We published the advisory on our web site. System owners are responsible for monitoring that site and taking appropriate actions.”

 

Kate Libby, a spokesperson for Dragonfire Cyber, confirmed that the Robotron disclosure process was fairly common in the industry. “I am surprised that a military contract would not include a vulnerability disclosure requirement for the vendor, but it could certainly happen,” Libby said.

 

When asked about the mitigation measures outlined in the Robotron advisory, Ms. Libby explained that the generic mitigation measures included not using the remote operation capabilities provided with the unit. She noted: “It would be impracticable to stop using the remote operation controls on a unit employed in Iraq. It would require keeping a person stationed at the unit during routine operations in 120˚ daytime temperatures.”

 

CAUTIONARY NOTE: This is a future news story –


Sunday, July 12, 2020

Acrylamide Producer Declares Force Majeure Because of Storage Tank Hack

Monomère Producteur, a US subsidiary of the French chemical conglomerate Laurent Chimiques, announced today that it was declaring force majeure on all of its contracts for the delivery of acrylamide in North America. It’s Delano, GA facility is the largest manufacturer of acrylamide monomer in the US and it was recently hit by a cyberattack on its monomer storage tanks.

 

The company’s President Charles Moureu told reporters today announced that its four 50,000 gallon acrylamide storage tanks had become contaminated with unacceptable levels of polyacrylamide because the air sparge of the tanks had been shut down by a cyber criminal over the Fourth of July weekend.

 

“The air sparge of the acrylamide storage tanks prevents polymerization of the monomer in the tanks,” Moureu told reporters; “With the high heat levels we have been seeing this summer and the lack of air sparge we have found that there is three to five percent polymer in the monomer storage tanks. This level of polymer makes the product unsuitable for use by our customers.”

 

The Federal Bureau of Inquiry and the ECS-CERT have been conducting a joint investigation of the attack on the Delano chemical facility. When contacted by the company, ECS-CERT investigators quickly discovered a small USB drive in one of the devices in a control system cabinet in the tank farm. Immanuel C. Securitage from ECS-CERT told reporters that the USB device was similar to those used to connect wireless keyboards and mice to home computers.

 

“It provided a Bluetooth connection to a wireless modem that was hidden near the cabinet,” Securitage said; “That provided the access the attackers needed to bypass all of the network security controls put in place by the company and take control of the safety systems that controlled the air sparge and tank monitoring controls for the four large storage tanks.”

 

Johnathan Quest, spokesman for the FBI, told reporters that the device was placed in the cabinet during an apparent physical attack on the facility during the evening of July 3rd. “A perimeter intruder detection system alarmed at 10:00 pm that evening and local police responded but found no sign of intruders that night,” Quest said: “A more detailed inspection the next morning found a rope strung above the fence between two trees that served as the intruders route into and out of the facility.”

 

The Agency for Chemical and Environmental Security spokesman Daniel Varg told reporters that the largest volume use of acrylamide monomer in the United States is in the manufacture of water treating polymer products used in both the cleaning of drinking water and the treatment of municipal and industrial waste water.

 

“The removal of almost 180,000 gallons of acrylamide from the market place is going to have a rapid impact on the water treatment market,” Varg told reporters; “We expect to see shortages start appear in the invert emulsion polymer market place within the next couple of weeks. Depending on how long it takes Monomère Producteur to clean up the material in those tanks we could start to see treatment plants shutting down before the end of the month.”

 

CAUTIONARY NOTE: This is a future news story –


Saturday, June 27, 2020

FDA Confirms Robotron Health Hack

Today the Federal Drug Administration confirmed reports that a death from insulin overdose earlier this week in New York City was the result of the hack of the Robotron IPumpe worn by the patient. FDA spokesperson Clark Stanley told reporters that the unnamed patient had been using the insulin pump for over a year with no problems and that the pump log showed an unauthorized change in pump rate just before the patient went into an insulin shock. The patient was declared dead upon arrival at Emanuel Unity Hospital.

 

“We are working with ECS-CERT and the Federal Bureau of Inquiry in our investigation of this incident,” Stanley told reporters.

 

“The attacker was able to gain access to the pump programing via the Ripple20 vulnerabilities reported earlier this month,” Immanuel C. Securitage, spokesman for the ECS-CERT told reporters; “The access to the device was via the Bluetooth service that is designed for use by physicians to program the device.”

 

Last week Robotron published a security advisory for the Ripple20 vulnerabilities in their Healthcare product line. The IPumpe had been identified as an affected product, but that “there is no risk to the patient because the device is not connected to the Interent.” Robotron has not replied to requests for comment.

 

Johnathan Quest, the FBI spokesperson confirmed that: “The Bureau has identified a person of interest in this case and is continuing its investigation.”

 

CAUTIONARY NOTE: This is a future news story –


Sunday, June 21, 2020

Dragonfire Demonstrates Ripple20 at Cyber Augusta

Yesterday a team of researchers from Dragonfire Cyber provided a live demonstration of the Ripple20 vulnerabilities at the Cyber Augusta cybersecurity conference in Augusta, GA. Using a mini tank whose drive was controlled by the Robotron MotorSteuerung software, the team demonstrated how the known TCP/IP vulnerabilities could be used to take control of the movements of the vehicle.

 

Kate Libby, a Dragonfire spokesperson, told reporters that this demonstration was originally supposed to be done by company founder Dade Murphy, but due to his current incarceration in Singapore pending possible extradition to China, Dade was not able to make the meeting. “Dade spent two years here in Augusta at Army Cyber Command, so he was very committed to supporting Cyber Augusta,” she told reporters; “The team knew that we had to make this presentation for him.”

 

The mini tank used in the demonstration had US Army Cyber Command markings. There was widespread cheering when it rolled out on stage.

 

A member of the Dragonfire team that was not authorized to speak to reporters told me that the demonstration was particularly interesting because on Friday Robotron published an advisory stating that none of their products were affected by the Ripple20 vulnerabilities.

 

Robotron provided the following statement but refused to answer any questions about the demonstration.

 

“We published the Ripple20 advisory based upon the fact that we had not used the affected TCP/IP stack in any of our products. If the Dragonfire demonstration is an accurate portrayal of an attack on our MotorSteuerung software, then we have to conclude that the vulnerable TCP/IP stack is part of a third-party component of the software. We are in the process of working with the appropriate vendors to try to get to the bottom of the issue.”

 

Immanuel C. Securitage from ECS-CERT said: “Third-party software vulnerabilities are an ongoing problem in the cybersecurity arena. Vendors need to understand the vulnerabilities in the software libraries and components that they use and ensure that they are adequately mitigated when used in their products.” He refused to comment on yesterday’s Dragonfire demonstration.

 

CAUTIONARY NOTE: This is a future news story –