Wednesday, January 26, 2022

NVR Ransomware Provides Network Access

The National Critical Infrastructure Security Operations Center (CI-SOC) announced today that it had discovered that the recent ransomware attacks by the Blockflötenkollektiv (BFK) on Robotron network video recorders was accompanied by the installation of a root kit utilizing the recently reported VerpfändenBausatz Linux vulnerability. “While the ransom payment for releasing the NVR’s is relatively small (0.03 bitcoin which currently equals about $1,100), the BKF is selling root access to the decrypted systems for 1 bitcoin.” Gen Buck Turgidson, CI-SOC Director, told reporters this morning.

BKF is a hacker collective loosely based out of Germany. It was started in 1990 by technical specialists connected to the East German Stasi, the group has had close ties with Russian cyber gangs.

According to a background briefing provided by an analyst working with the CI-SOC, the organization had received reports from an unnamed US intelligence agency that one of the critical infrastructure organizations protected by CI-SOC had shown up on a dark web site known to be utilized by BFK. BFK was offering to sell root access to one of the corporate networks of the unidentified company. It was one of two hundred such access rights being offered.

Other sources tell me that the intelligence agency bought the rights from BFK and provided the information to CI-SOC. While CI-SOC worked out the details of the system compromise, the intelligence agency was able to use the bitcoin information from their transaction to track back the bitcoin wallet used by BFK. The wallet was seized by the German government and two members of the organization were arrested in Berlin.

CAUTIONARY NOTE: This is a future news story –

Tuesday, December 28, 2021

Airport Ransomware Slows Christmas Returns

Fred P. Ayres, Operations Manager for the Porter Alexander Airport, confirmed today that the flight delays yesterday at the Delano, GA airport were caused by a ransomware attack on the carryon baggage screening equipment being used at the passenger screening checkpoints. He was not able to tell reporters this morning whether a ransom had been paid.

Bessie Coleman, spokesperson for the Airline Transportation Security Agency (ATSA), confirmed that there had been screening delays at Alexander. “We had to go to 100% manual baggage screening of carryon baggage at that airport,” Coleman told reporters; “For security reasons, I cannot discuss what prompted that requirement.”

“We had flight delays of up to two hours to allow for passengers to complete the screening protocols,” Ayers told reporters.

Frank Whittle, who’s son was scheduled to fly back to Ft Carson, Co, after Christmas leave, reported that his son missed his connecting flight in Atlanta. “He ended up spending twelve hours in the Atlanta airport and ended up getting back to his unit three hours late,” Whittle explained; “I hope he does not get in trouble with the Army over the delay.”

The National Critical Infrastructure Security Operations Center (CI-SOC) has been working with the airport and the ATSA on the investigation of the cyberattack. Turgidson told reporters this morning that it is unusual to see a ransomware attack on federal government operations. “Everyone knows that the official policy of the government is to not pay ransoms,” Turgidson explained; “So there is little incentive for a ransomware attack.”

There are rumors circulating that this was not a typical ransomware attack, that files were not encrypted. A security employee of the airport, not associated with ATSA, told me that the screening devices were picking up false weapon returns. Three passengers were apparently pulled aside for additional screening before the ransomware message showed up on the system.

CAUTIONARY NOTE: This is a future news story –

Friday, December 3, 2021

Polymer Hack Via Drive-by Malware

The Federal Bureau of Inquiry confirmed today that the attack earlier this week on the Blew Bayou polymer facility used a new version of the SolarFlare malware that was originally delivered as part of the 2019 Sunburst campaign. “There have been substantial modifications to the malware,” Johnathan Quest, FBI spokesperson, told reporters this morning; “Enough changes in language and syntax that we are not sure if this was produced by the original team or a completely different attacker.”

Kate Libby, a researcher at Dragonfire Cyber that has been working with the FBI on the Blew Bayou investigation, told reporters that the malware was introduced into the polymer control system via a sophisticated phishing attack. “A personal email to the process control engineer directed her to go to the Robotron web site to see a new product introduction,” Libby explained; “The engineer did not click the link in the email but used an existing link from her system to get to the Robotron web site. While on the site she clicked on one of those ubiquitous check boxes accepting site cookies. That action downloaded the malware.”

Erich Mielke, spokesperson for Robotron, confirmed that the company’s web site had been hacked to set up the drive by download. “We use a web privacy compliance company, Datenshutz, to handle all of our website regulatory compliance activities,” Mielke explained; “They were responsible for the cookies notification application on our site. We have been assured that they have corrected the problem.”

Helga Brache, spokesperson for Datenshutz, confirmed that the company was responsible for the application on the Robotron site. “We are currently investigating how the malware download was inserted into our application. We do not believe that any other sites have been affected at this time.”

Libby urged anyone that had visited the Robotron site over the last six months to have their systems checked for the presence of the SolarFlare malware. “The indicators of compromise that were published by CI-SOC for the original malware still apply to the new version,” Kate explained to reporters.

Quest told reporters that the FBI investigation was still progressing. “We are continuing to follow leads and hope to identify the perpetrators of this attack in the coming days,” he explained; “If you have any indications that your systems have been compromised via the Robotron web site, please contact your local FBI office.”

CAUTIONARY NOTE: This is a future news story –

Thursday, December 2, 2021

Water Treatment Chemical Manufacturer Declares Force Majeure

The Blew Bayou Chemical Company in Louisiana announced yesterday evening that their production capacity for polyacrylamide emulsion polymers had been cut in half by a suspected cyberattack on their facility. The Blew Bayou facility is one of only two domestic facilities currently producing these polymers for the municipal water treatment market. The loss of production at the facility could begin impacting drinking water and wastewater treatment facilities across the United States in the next two weeks.

The chemical reaction vessel was damaged when the mixing system was interrupted in the early stages of a polymerization process. The lack of agitation prevented adequate cooling and the exothermic reaction ran out of control. Safety systems stopped a catastrophic overpressure situation from occurring, but the vessel and many of its attached lines were damaged in the incident. Engineers are currently assessing how much damage actually occurred and what repairs will be necessary to return the facility to operation.

An older sister plant in Mississippi was taken out of operation early in the pandemic because of efficiency issues and limited monomer availability. Blew Bayou is reportedly considering reopening that plant.

Blew Bayou CEO Issac B Kaghun told reporters this morning that the agitator stoppage was apparently caused by a cyberattack. “Our engineers have log data showing that the agitator motor was turned off remotely, even while the control room computers were showing continued agitation,” Kaghun said.

The Federal Bureau of Inquiry has confirmed that they are investigating a potential cyber attack at the facility. “We have a cyber investigation team at the site,” Johnathan Quest, FBI spokesperson, said at a news conference this morning.

CAUTIONARY NOTE: This is a future news story –

Monday, November 15, 2021

Server Crash Due to Building Control Hack

Yesterday’s Baton Rouge refinery shutdown was ultimately due to an attack on a building control system, according to reports this morning by Dragonfire Cyber. The Ravard Refinery was shutdown Sunday by three crashing servers supporting the facility control systems. Kate Libby from Dragonfire reports that those servers failed due to overheating when attackers took over control of the server room cooling system.

“Attackers changed the PLC programming for the HVAC system,” Libby told reporters this morning; “They changed room temperature set points and bypassed the temperature reporting process so that only expected temperatures were reported to the facility control room.”

Reportedly, no vulnerabilities in the PLC were involved in the attack. Access to the Robotron GS Building Control System (BCS) provided the necessary authorization to access to the PLC and change its programming. “This should require physical access to the GS BCS controls in the server room,” Libby explained; “But someone had set up port forwarding on the system firewall enabling remote access to Port 3671 on the BCS. No authentication is required when accessing the system through that port.”

A technician working with Dragonfire that is not authorized to talk to reporters told me that it looked like an integrator had set up the port forwarding to provide remote access for maintenance support for the building control system. Maintenance of the HVAC system and its associated controls is handled by a local vendor, not the refinery staff.

The Federal Bureau of Inquiry is investigating the attack on the refinery. “There is no indication that this was a terrorist attack,” FBI spokesman Johnathan Quest told reporters; “We are currently looking at the possibility that this was an economic attack.”

The refinery recently switched over their production mix to produce #2 fuel oil. This household heating fuel is shipped to the northeastern United States via pipeline. Heating oil stocks in New England are at historic lows for this time of year and the Ravard Refinery is a prime supplier into that market. It will take at least two weeks for the refinery to restart because of minor equipment damage sustained in the emergency shutdown. This will lead to shortages in heating oil supply as people are trying to fill their tanks for the coming winter season.

CAUTIONARY NOTE: This is a future news story –

Sunday, November 14, 2021

Multiple Server Failures Shuts Down Refinery

The Rafael Ravard Refinery outside of Baton Rouge, LA went into an emergency shutdown early this morning. According to Cesar Chavez, spokesperson for the refinery, the cause of the shutdown was due to multiple servers in the process control system crashing at nearly the same time. “Automatic backups did not come online,” Chavez reported; “But local safety systems throughout the plant did allow for a safe shutdown.”

There were local reports of people observing widespread flaring throughout the refinery during the shutdown. “Flaring is a normal occurrence in safety shutdowns,” Chavez explained.

Dragonfire Cyber has a team on site. Kate Libby, a spokesperson for Dragonfire said: “We are working with the Ravard Refinery to determine the cause of the shutdown. We have no news at this time beyond being able to report that three Robotron servers at the facility all shut down. This was the proximate cause of the facility shutting down.”

A technician working with Dragonfire who is not authorized to talk to reporters told me that the server room had apparently overheated. “This was probably the reason that the three initial servers crashed,” she said; “Two other servers crashed shortly after our team arrived on site.”

CAUTIONARY NOTE: This is a future news story –

Tuesday, November 9, 2021

Semiconductor Designs Compromised

Robotron announced today that it has received reports of attacks on customers using the Robotron RoboHD semiconductor design software. The Robotron press release notes that one customer has reported a chip design compromise as a result of an attack by the AngryHD malware. Robotron is cooperating with national computer security agencies around the world on an ongoing investigation into the attacks.

Gen Turgidson, Director of the National Critical Infrastructure Security Operations Center (CI-SOC), told reporters this morning that the CI-SOC was working with Robotron on the investigation. “We know of one instance in the US where a chip design was compromised,” Turgidson reported, “The design flaw was found before the chip went into production, so no hardware has been compromised that we know of.”

Kate Libby of Dragonfire Cyber explained on background this morning that the Robotron Kern real-time operating system (RTOS) (acquired in the recent buyout of Beratergrafik) has been found to contain a number of vulnerabilities that could be remotely exploited to compromise products like RoboHD. “We have seen similar vulnerabilities in a large number of RTOS in recent years,” she explained; “So the problems in Kern are not unusual, unfortunately.”

A technician working with CI-SOC who is not authorized to talk to reporters told me that the agency has a copy of the AngryHD malware. “This is definitely advanced stuff,” she said, “We are probably looking at a state sponsored attack here, not cyber criminals.”

Dragonfire Cyber has released indicators of compromise that will allow users of RoboHD to determine if their systems have been compromised by the AngryHD malware. Dade Murphy, chief technical officer of Dragonfire told reporters that they were working with Robotron to develop methods of blocking such attacks while Robotron was continuing to work on an update for the Kern RTOS and RoboHD products.

CAUTIONARY NOTE: This is a future news story –