Sunday, November 22, 2020

LA Sues CI-SOC for Access to Bitcoin Tracking Tool

On Friday, Harry R. Haldeman, the District Attorney for Los Angeles, filed suit in 14th US District Court against asking the Court to order General Buck Turgidson (USA, Ret), the director of the US Critical Infrastructure Security Operations Center to make available to prosecutors in the United States the tool known as “Bitcoin Tracker”. Haldeman claims that the tool used in recent attacks reported by CI-SOC would allow government to track, identify and prosecute the actors behind the recent spate of ransomware attacks.

Haldeman told reporters today that he had talked to Turgidson immediately after the ransom recovery had been announced by CI-SOC last week about obtaining access to the tool. “Buck told me that CI-SOC was not releasing the tool for National Security reasons.” Haldeman said, “I have done some additional checking and it does appear that he has gotten into some hot water with the national security establishment for even announcing that the tool existed. But at this point the cat is out of the bag and we need access to this invaluable tool to put a stop to the ransomware epidemic.”

Turgidson would not comment, citing federal rules about not commenting on ongoing litigation. An official working at CI-SOC who cannot be named confirmed that Turgidson had been reprimanded for discussing the tool. “The counterterror folks have been using this tool for over a year now to track money flow to various terrorist organizations,” the official said, “It has helped them to identify both sources of funding and the places where the moneys have been used to fund operations. The concern is now that the bad guys know that we have the tool, that they will start to use some different method of moving money around.”

According to another source in the government, Turgidson knew about these concerns when he released the information. He reportedly felt that the current ransomware threat was a more immediate and widespread threat to the safety of the country than was the current level of terrorism. The announcement of the possession of the tool, according to sources close to the Director, was made to let the ransomware community know that they were no longer protected by the expected anonymity of the Bitcoin service.

If that was the case, one source was asked, why has Turgidson refused to turn over the tool to prosecutors like Haldeman? “It is not as simple as turning over a disc for someone else to use. The process is complicated and uses resources that not currently available outside of the intelligence community.”

CAUTIONARY NOTE: This is a future news story –

Friday, November 20, 2020

COVID-19 Vaccine Hack

General Buck Turgidson, Director of the Critical Infrastructure Security Operations Center (CI-SOC), told a press conference this morning that the ransomware attack on Mengele Pharma earlier this week used a variant of the WannaControl ransomware. He also noted that investigators working for CI-SOC discovered that the as yet unidentified attackers gained access to the warehouse facility control system via storage batteries associated with the rooftop solar array.

Turgidson told reporters: “There were significant changes made to the ransomware code. We do not believe at this time that those changes were made by Stasi Ehemalige, the authors of the original ransomware.” A manager at CI-SOC told me that there are indications that Stasi Ehemalige has been selling copies of their ransomware on the Dark Web.

A briefing document provided to reporters says that changes to the ransomware include the inclusion of a data exfiltration module as well as a tool specifically designed to make modifications to the programming of the Robotron Kühlsicherheit refrigeration safety system that is used at the facility. The report also notes that the manufacturing control system at the Mengele Pharma vaccine plant adjacent to the warehouse was also infected, but that it had not yet been shut down by the ransomware.

Dade Murphy, CTO at Dragonfire Cyber, said that his team supporting the CI-SOC investigation had been able to deconstruct the ransomware package that shut down the warehouse operations. “The new code that facilitated this particular attack,” Murphy told reporters, “has significant structural and coding differences that indicate that a different team of developers worked on the new modules. There are many similarities between the coding styles used here and that used in the ĀnquánShújīn PLC ransomware used in an attack earlier this summer.” Murphy was unable to explain why those coders would have used Stasi Ehemalige malware for this attack.

Murphy told reporters that they had found one of the affected freezers had an old-style circular chart recorder for temperature still working on the freezer. “This system with its dedicated thermocouple was unaffected by the attack. While the one-week chart had not been changed in a month we can clearly see that the temperature in the freezer rose to -30˚C for extended periods,” Murphy said; “If this chart had been tracked, the problem would have been detected in time to prevent the problems with vaccine storage conditions.”

The attack on the warehouse control system was initiated via the energy storage system associated with the roof top solar array. “The known vulnerability in the direct internet connection of the battery system was used to gain access to the facility maintenance network.” Murphy told reporters, “Once that network access was gained, it was relatively easy for the attackers to pivot into the building automation system and then into the warehouse refrigeration systems.”

Wolfgang Gerhard, President of Mengele Pharma told reporters that the solar system had apparently been installed before the vulnerability was reported. “We have been in contact with the contractor we used for that installation.” Gerhard said, “They are currently working on updating the system and mitigating that particular vulnerability.”

Wolfgang was able to update reporters on the effect of the refrigeration attack on the inventory of COVID-19 vaccine stored on the premises. Each box is equipped with a chemical temperature warning decal that changes color when the temperature rises above a set point. “We have examined each of the boxes in all five of the freezers on site,” Gerhard said; “About 80% of the indicators show that the packages had been exposed to temperatures above the -50˚C limit set by the Federal Drug Administration in their approval of the vaccine.” Mengele is turning over all of those cases to the FDA for study and disposal.

Clark Stanley, spokesperson for the FDA, told reporters that the agency would be storing each of the affected boxes in the appropriate conditions. “We will be conducting efficacy testing on samples from each of the boxes to determine what effect the unfortunate temperature excursions had on the vaccine,” Stanley said; “We may be able to provide box-by-box approval for the use of some of the vaccine. We do understand the importance of having a COVID-19 vaccine available as quickly as possible, but we want to ensure that it is an effective vaccine that the public can rely on.”

CAUTIONARY NOTE: This is a future news story –

Tuesday, November 17, 2020

COVID-19 Vaccine Storage Hit by Ransomware

Mengele Pharma announced this morning that their Schenectady, NY warehouse had been hit by a ransomware attack. All facility control systems, including the ultra-refrigeration system for the storage of the initial manufacturing run of their new COVID-19 vaccine were shut down. Wolfgang Gerhard, company President, acknowledged that there are concerns about the potential effects on the efficacy of the 20 million doses of vaccine stored in the facility.

General Buck Turgidson, Director of the Critical Infrastructure Security Operations Center, confirmed that the CI-SOP was working with Mengele Pharma on rectifying the problem. “Our investigators are on the scene and working with the facility security team to determine the extent of the problem,” Turgidson told reporters; “Preliminary indicators would seem to tell us that the attackers had been active on the system for at least a week prior to the shutdown.”

The Mengele vaccine requires storage at -50˚C. It can be held briefly, for up to a day at temperatures as high as 0˚C. Higher temperatures cause the vaccine to break down and quickly loose efficacy.

Clark Stanley, spokesperson for the Federal Drug Administration (FDA), told reporters that Mengele will have to be able to demonstrate that the storage conditions, including ultra-refrigeration met the required standards set for this vaccine before any distributions will be able to be made from this warehouse. “Failure to be able to document storage temperatures will not be acceptable,” Clark said.

Clark did tell reporters that Mengele was in the final stages of receiving emergency approval of their vaccine. The FDA and the company were making plans to be able to start distribution sometime in early December.

Sources at Mengele that are not authorized to talk to the press report that the company has paid the 1-milllion bit coin ransom but has not received the code necessary to regain control of their systems.

Sen TJ Kong told reporters this morning that his Committee would be looking at requiring the CI-SOP to begin providing cyber-protection to all vaccine manufacturers whether or not they had requested protection. “Vaccine manufacturers that are planning on taking Federal money for vaccine distribution or manufacture should be required to cooperate with CI-SOP.”

Mengele has not received any federal research funding for the development of their vaccine.

CAUTIONARY NOTE: This is a future news story –

Thursday, November 12, 2020

CI-SOC Recovers Bitcoin Ransom

The Critical Infrastructure Security Operations Center (CI-SOC) announced today that it had successfully conducted operations today against a North Korean ransomware gang that was operating out of Soul, South Korea. The bitcoin ransom paid by three separate, unidentified companies in the United States was recovered, the small server farm used by the gang was seized and four North Korean agents were arrested.

General Buck Turgidson, Director of CI-SOC, told reporters that his group, working with the South Korean government and elements of US Special Operations Command, tracked the gang by following the bitcoin trail to a compound on the outskirts of Soul. “A special team of Army Special Forces that included cyber-operators worked with a team from the South Korean Army to enter the compound and seize computer equipment before any information could be destroyed,” Turgidson told reporters.

Special Operations Command confirmed that special operations forces were involved but refused to comment on the identity of the team. They explained the participation of the military by noting that the underlying cyberattacks had been performed by agents of a foreign government. There have been rumors circulating in Washington of the formation of a Cyber A-team being formed to work on this type of operation, but there has been no confirmation from Special Operations Command or the Pentagon.

The four North Koreans captured in the raid are being held in Soul pending extradition to the United States. There are rumors that the Justice Department has concerns about trying them for their alleged cyber crimes because of search and seizure implications. A national security warrant had been issued for tracking the bitcoins, but the rules of evidence for supporting that type of warrant are different from those that would be used in a criminal court case in the United States. The tools used to track the bitcoin trail were developed by the National Security Agency and that agency would not be prepared to share the technology upon which that trace was based with the defense team. It is suspected that any criminal defense attorney would move to have the identification of his clients by such undisclosed technology suppressed.

There are rumors circulating that the Justice Department is considering certifying the ransomware attacks as terrorist attacks and allowing the foreign nationals to be tried by a military tribunal.

CAUTIONARY NOTE: This is a future news story –

Saturday, September 26, 2020

Hearing at CI-SOC on Recent Ransomware Attacks in Delano

Rep. Tucker Watts (R,GA) was on site today at the Critical Infrastructure Security Operations Center (CI-SOC) to participate in a virtual hearing of the House Subcommittee on Cybersecurity Oversight looking at the recent ransomware attacks on two facilities in Delano, GA that appeared to be related. Watts is the Ranking Member of the Committee and requested the hearing.

In his opening statement, Chairman Richard Gil (D,NY) explained that todays meeting was called to look at both the root cause of the two attacks and the role that IC-SOC could have played in preventing such attacks. “Let us be clear,” Gil explained; “Neither the Intershop Meat Plant nor the Delano Waste Water Treatment Plant had signed up to be covered by the IC-SOC, so the IC-SOC team was not setup to protect those facilities. And, even if they had, since the attacks were both initiated by an onsite insertion of a USB device, as currently configured, IC-SOC would not have been able to prevent the attacks.”

General Buck Turgidson, the Director of the National Critical Infrastructure Security Operations Center, present onsite with Congressman Watts, testified that away teams from IC-SOC responded to both incidents at the request of ECS-CERT. “Our teams only had to drive a couple of minutes across town,” Turgidson said; “The ECS-CERT team would have taken a day or more to get here.”

Immanuel C. Securitage, ECS-CERT spokesperson, testified by a video link from Washington. “We asked for assistance for two reasons,” he explained as a response to a question by Watts; “First the IC-SOC away teams were already in Delano. Second, and maybe more importantly, our staffing was cut in half to provide investigative personnel to IC-SOC.”

Horst Sinderman, the facility manager at the Delano meat plant that was attacked, testified remotely from the corporate headquarters in Birmingham, AL. He explained that, when it became obvious that the investigation team was not going to be able to fix the problem, corporate management contacted the company’s cyber-insurance provider who provided the funds to pay the ransom.

Dragonfire Cyber assisted in the investigation of attack on the meat plant and was on hand when the ransom was paid. “We were able to intercept the decryption key when it was sent to the facility,” Dade Murphy testified by video remote; “Having copies of both the encryption software from the USB devices and the decryption key, we were able to put together a decryption key for the attack on the Delano Waste Water Treatment Plant.”

That plant was able to restart about two hours after it had started discharging untreated wastewater into the Flint River. That discharge resulted in a large fish-kill and two cities downstream had to slow their processing of drinking water from the River to ensure that all contaminants and bacteria from the discharge were removed. Cities further downstream noticed little additional contamination in their intake testing.

Mayor Arrington Carter provided a written statement that was read into the record of the hearing. In part she said, “We are very grateful for the assistance that IC-SOC provided to the two facilities in the city during these attacks on our essential infrastructure. A major employer and our city services would have been affected much more severely if the government team had not stepped in with their expertise.”

The Federal Bureau of Inquiry is still investigating the two attacks. Johnathan Quest, spokesperson for the FBI, answered my questions this morning in a telephone interview about the investigation. The FBI continues to investigate both incidents as part of a larger plot by TrabajoSeUnen to affect operations at meat packing plants around the country. “While they are employing typical labor jargon in their messaging,” Quest said; “We can find no evidence of collusion between the group and local labor organizations. We believe that this is a straightforward ransomware campaign executed with the intent to make money.”

Congressman Watts told this reporter that he intended to introduce legislation that would require municipal water treatment facilities and wastewater treatment facility to either join IC-SOC or some other cybersecurity monitoring service. “We just cannot afford to have these facilities shut down by either criminals or terrorists,” he said.

CAUTIONARY NOTE: This is a future news story –

 

Thursday, September 24, 2020

Water Treatment Plant Hit by Ransomware Attack

The Delano Waste Water Treatment Plant (WWTP) announced this morning that its computer systems that control the physical operation of the facility have been shutdown by a ransomware attack. The attackers, reportedly the same group that shutdown the operation of the Intershop Meat Plant last week, are demanding 1,000 bitcoin from the City of Delano to unlock the facility control systems.

George Funderburke, the director of the Delano Water Maintenance Department (DWMD) told reporters at a brief news conference that both the Federal Bureau of Inquiry and the Environmental Process Protection Agency (EPPA) about the attack. “EPPA and ECS-CERT will be sending teams to help us get our plant back in operation,” Funderburke said; “We have about six hours of storage capacity available for incoming sewage, after that we will have to start discharging untreated sewage into the Flint River.”

Jay Muir, spokesperson for the EPPA, told this reporter that the EPPA was sending an action team to Delano, but that it would probably be the ECS-CERT that would be the lead agency on the investigation. “The team we are sending are process engineering types,” Muir said; “They will be responsible for helping the WWTP operate as effectively as possible in a manual operating mode. They should arrive on site before it is necessary to start discharging untreated sewage.”

The WWTP has only limited capacity to continue operation under manual conditions. The facility will continue to be discharging treated water through manual operations. A warning will be issued before any untreated sewage is discharged. Cities downstream of Delano have been warned that a sewage discharge may be required.

The DWMD does not have funds available in their budget to pay the ransom. Mayor Arrington Carter has scheduled an emergency meeting of the Delano City Council for later this morning to see what actions the City will be taking. “The DWMD has had problems with cash flow since the COVID-19 epidemic hit last spring. They have had a much larger than normal non-payment rate on water bills for both household and commercial accounts. We have been using the City’s rainy day fund to supplement their accounts for the last two months, so we may have problems coming up with the money for the ransom.”

Kate Libby, a spokesperson for Dragonfire Cyber, said that the Company has not yet been notified about this ransomware attack, but was working with the ECS-CERT on the investigation at the Intershop Meat Plant. “We have discovered that the source of that attack was a USB drive inserted into one of the PLC’s at the facility; it was apparently an insider attack.”

Funderburke has asked residents and businesses in Delano to reduce their water use and waste generation while the City works to correct this problem. Commercial and industrial facilities with large volume discharges have been notified to stop those discharges as soon as possible. This does include the Intershop Meat Plant that just reopened yesterday.

The Critical Infrastructure Security Operations Center (CI-SOC) would not comment on this attack.

CAUTIONARY NOTE: This is a future news story –

Sunday, September 13, 2020

Meat Packing Plant Closed by Ransomware Attack

 

The Intershop Meat Plant in Delano, GA was shut down over the weekend when the control system at the plant was hit by a ransomware attack. The facility was hit with the WannaControl ransomware that specifically targets industrial control systems made by the Robotron Company.

Immanuel C. Securitage, spokesperson for ECS-CERT told reporters this morning that that the company’s control systems at the Delano facility were locked out on Saturday morning as the first shift started work. After briefly trying to operate the facility’s chicken deboning production line manually, management sent the shift home early and announced that it would let workers know when they should return to the plant.

Horst Sinderman, the facility manager, told reporters that the company would not be meeting the ransom demand. “We have been having a hard-enough time keeping the facility open during the COVID-19 pandemic,” he said: “The increased cleaning costs and other COVID prevention measures have already cut deeply into our profit margin. There is no money available to pay for the demanded 1,000-bitcoin ransom demanded by Trabajo Se Unen, a previously unidentified malware group.

A tweet by TrabajoSeUnen that was quickly taken down on TWITTER® said: “We have struck down Intershop to take care of our sick brothers and sisters and their families.”

When Sinderman was asked about the tweet he acknowledged that over three hundred employees have contacted COVID-19. “Our company has covered the medical bills for all of the sick employees,” he said; “And we continued the employees pay checks during their recovery at half-pay even though we believe that most of the infections came from exposures outside of the facility.”

Dade Murphy, CTO of Dragonfire Cyber, said that his company has long thought that the WannaControl malware was the work of Stasi Ehemalige, the German hacking collective. “They have a long history of penetration of Robotron,” he told this reporter; “There are many coding similarities between WannaControl and other malware that affects Robotron products. We also suspect that they have organizational roots that trace back to European radical groups that were financed by the East Germans during the Cold War.”

Johnathan Quest, spokesperson for the Federal Bureau of Inquiry, told reporters that information gleamed from the dark web indicated that the authors of WannaControl have recently started to advertise cut-rate sales of their ransomware to radical labor activists in Europe and the United States. “According to some dialogs that we have intercepted, the WannaControl ‘sales team’ is recommending that ransomware attacks be used to punish companies that fail to properly take care of their employees during the COVID-19 pandemic,” Quest explained; “They are apparently selling the use of the malware for such attacks at a reduced rate. In at least one case the use was sold for 10% of the normal price.”

Vicente Lombardo Toledano, the President of Amalgamated Meat Cutters Local 1936 (AMC 1936), said that closing the plant was not in the best interest of the employees. “Our people are not going to get paid for sitting home waiting for the company to resolve this problem,” he told reporters at the local union hall; “Any claim that our union or our members had anything to do with this ransomware attack is completely unfounded and untrue.”

CAUTIONARY NOTE: This is a future news story –