HomeRisk ManagementsIranian Hackers Attack Siemens and Schneider Industrial Systems

Iranian Hackers Attack Siemens and Schneider Industrial Systems

Published on

spot_img

Iranian Cyber Campaign Targets US Critical Infrastructure

Recent reports highlight a concerning trend involving Iranian cyber adversaries systematically targeting internet-exposed industrial systems linked to multiple well-known brands, including Rockwell Automation, Allen-Bradley, Schneider Electric, and Siemens. This escalation in cyber threats was underscored in an advisory update released by the US Cybersecurity and Infrastructure Security Agency (CISA) on July 22. Notably, the advisory details the FBI’s observations of Iran-affiliated cyber threat actors downloading a malicious project file onto a targeted programmable logic controller (PLC) situated within a US-based critical infrastructure organization, utilizing specialized configuration software.

This alarming development extends beyond the initial download; the FBI also detected instances where data manipulation occurred on human-machine interface (HMI) and supervisory control and data acquisition (SCADA) displays. Such manipulations resulted not only in operational disruptions but also significant financial losses for the affected organizations.

Upon further investigation, analysts discovered that the compromised project file preserved the ladder logic essential for downstream functions. However, it contained additional logic that overrode specific instruction sets crucial for maintaining safety within the operational parameters of the victim’s environment. This revelation raises substantial concerns regarding the security measures in place for critical infrastructure across various sectors.

Dynamics of the Ongoing Cyber Threat

This situation is further compounded by an earlier advisory issued in April, warning about an ongoing cyber campaign orchestrated by Iranian actors targeting US critical infrastructure. CISA indicated that these cyber attacks have notably affected several vital sectors, including government services, water systems, wastewater management, and energy production and distribution.

In their initial warning, CISA specifically identified PLCs from Rockwell Automation and its subsidiary, Allen-Bradley, as primary targets. These warnings arose following the detection of malicious changes in reusable code modules within Rockwell Automation PLC programs, compelling the agency to take proactive steps to protect US critical infrastructure.

The July update from CISA revealed that the same advanced persistent threat (APT) actors have broadened their scope to include PLCs manufactured by Schneider Electric and Siemens. This assessment emerges from discoveries that APT actors have been leveraging configuration software—such as Rockwell Automation’s Studio 5000 Logix Designer, Schneider Electric’s EcoStruxure Control Expert, and Siemens’ Totally Integrated Automation (TIA) Portal—on leased, third-party-hosted infrastructure. Through these methodologies, they have been able to exfiltrate device project files from PLC devices to locations controlled by the cyber adversaries.

CISA has specifically named several targeted models, which include Allen Bradley’s CompactLogix and Micro850 PLCs, Schneider Electric’s BMX P34 and Modicon M340 models, as well as Siemens’ S7-1200 series PLCs. However, the advisory also cautioned that PLCs from other manufacturers could also be susceptible to similar threats.

While the advisory refrained from naming particular threat groups, it acknowledged that the ongoing campaign exhibits striking similarities to an operation carried out in November 2023. This operation was attributed to a group affiliated with Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC CEC). The group, commonly referred to as ‘CyberAv3ngers,’ is recognized by cybersecurity firms under various aliases, including Bauxite, Hydro Kitten, the Shahid Kaveh Group, Soldiers of Solomon, Storm-0784, and UNC5691.

Recommendations for Mitigating Cyber Threats

In light of these alarming developments, CISA has issued several critical recommendations aimed at equipping US critical infrastructure (CNI) organizations with the necessary tools to mitigate these persistent threats effectively. The advisory encourages CNI providers to take the following protective measures:

  1. Follow Manufacturer Guidelines: Organizations should ensure that PLCs are installed in strict accordance with the manufacturers’ guidelines and recognized security best practices.

  2. Limit Internet Exposure: It is imperative to remove PLCs from direct internet exposure by implementing secure gateways and firewalls to protect sensitive infrastructures.

  3. Monitor for Indicators of Compromise: Organizations should actively query available logs for the designated indicators of compromise (IOCs) and scrutinize logs for any suspicious traffic on ports commonly associated with operational technology (OT) devices, specifically ports such as 44818, 2222, 102, and 502.

  4. Physical Security Measures: For devices manufactured by Rockwell Automation, it is crucial to position the physical mode switch on the controller into the run position to ensure enhanced security protocols are in effect.

As cyber threats continue to evolve, ensuring the safety and security of critical infrastructure is of paramount importance. The ongoing vigilance and robust cybersecurity practices recommended by CISA are essential for defending against potential incursions that could disrupt operations and pose risks to public safety. The need for proactive measures can’t be overstated in an age where cyber adversaries are persistently seeking vulnerabilities to exploit for their malicious intents.

Source link

Latest articles

FakeAgent Campaign Utilizes Malicious Claude Artifact to Distribute SectopRAT to 29 Organizations

Malvertising Campaign Exploits Anthropic's Claude.ai to Distribute SectopRAT Trojan Researchers at Huntress recently uncovered a...

CISA Issues New Warning About Exposed PLCs

Internet-Exposed Programmable Logic Controllers Present an Easy Target for Hackers In a troubling revelation this...

Security Teams Transition from AI-Only to Hybrid Penetration Testing

Shift from Full AI Automation in Penetration Testing: A Return to Human Expertise In a...

Check Point Vulnerability Allows Unauthenticated Attackers to Access Full SmartConsole Admin Privileges

Challenges of IP Address Restrictions in Cybersecurity In today's increasingly digital landscape, cybersecurity remains a...

More like this

FakeAgent Campaign Utilizes Malicious Claude Artifact to Distribute SectopRAT to 29 Organizations

Malvertising Campaign Exploits Anthropic's Claude.ai to Distribute SectopRAT Trojan Researchers at Huntress recently uncovered a...

CISA Issues New Warning About Exposed PLCs

Internet-Exposed Programmable Logic Controllers Present an Easy Target for Hackers In a troubling revelation this...

Security Teams Transition from AI-Only to Hybrid Penetration Testing

Shift from Full AI Automation in Penetration Testing: A Return to Human Expertise In a...