Summary
Actions to Take Today to Protect ICS/SCADA Devices:
• Enforce multifactor authentication for all remote access to ICS networks and devices whenever possible.
• Change all passwords to ICS/SCADA devices and systems on a consistent schedule, especially all default passwords, to device-unique strong passwords to mitigate password brute force attacks and to give defender monitoring systems opportunities to detect common attacks.
• Leverage a properly installed continuous OT monitoring solution to log and alert on malicious indicators and behaviors.
The Department of Energy (DOE), the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI) are releasing this joint Cybersecurity Advisory (CSA) to warn that certain advanced persistent threat (APT) actors have exhibited the capability to gain full system access to multiple industrial control system (ICS)/supervisory control and data acquisition (SCADA) devices, including:
- Schneider Electric programmable logic controllers (PLCs),
- OMRON Sysmac NEX PLCs, and
- Open Platform Communications Unified Architecture (OPC UA) servers.
The APT actors have developed custom-made tools for targeting ICS/SCADA devices. The tools enable them to scan for, compromise, and control affected devices once they have established initial access to the operational technology (OT) network. Additionally, the actors can compromise Windows-based engineering workstations, which may be present in information technology (IT) or OT environments, using an exploit that compromises an ASRock motherboard driver with known vulnerabilities. By compromising and maintaining full system access to ICS/SCADA devices, APT actors could elevate privileges, move laterally within an OT environment, and disrupt critical devices or functions.
DOE, CISA, NSA, and the FBI urge critical infrastructure organizations, especially Energy Sector organizations, to implement the detection and mitigation recommendations provided in this CSA to detect potential malicious APT activity and harden their ICS/SCADA devices.
to execute malicious code in the Windows kernel. Successful deployment of this tool can allow APT actors to move laterally within an IT or OT environment and disrupt critical devices or functions.
APT Tool for Schneider Electric Devices
The APT actors’ tool for Schneider Electric devices has modules that interact via normal management protocols and Modbus (TCP 502). Modules may allow cyber actors to:
- Run a rapid scan that identifies all Schneider PLCs on the local network via User Datagram Protocol (UDP) multicast with a destination port of 27127 (Note: UDP 27127 is a standard discovery scan used by engineering workstations to discover PLCs and may not be indicative of malicious activity);
- Brute-force Schneider Electric PLC passwords using CODESYS and other available device protocols via UDP port 1740 against defaults or a dictionary word list (Note: this capability may work against other CODESYS-based devices depending on individual design and function, and this report will be updated as more information becomes available);
- Conduct a denial-of-service attack to prevent network communications from reaching the PLC;
- Sever connections, requiring users to re-authenticate to the PLC, likely to facilitate capture of credentials;
- Conduct a ‘packet of death’ attack to crash the PLC until a power cycle and configuration recovery is conducted; and
- Send custom Modbus commands (Note: this capability may work against Modbus other than in Schneider Electric PLCs).
Refer to the appendix for tactics, techniques, and procedures (TTPs) associated with this tool.
APT Tool for OMRON
The APT actors’ tool for OMRON devices has modules that can interact by:
- Scanning for OMRON using Factory Interface Network Service (FINS) protocol;
- Parsing the Hypertext Transfer Protocol (HTTP) response from OMRON devices;
- Retrieving the media access control (MAC) address of the device;
- Polling for specific devices connected to the PLC;
- Backing up/restoring arbitrary files to/from the PLC; and
- Loading a custom malicious agent on OMRON PLCs for additional attacker-directed capability.
Additionally, the OMRON modules can upload an agent that allows a cyber actor to connect and initiate commands—such as file manipulation, packet captures, and code execution—via HTTP and/or Hypertext Transfer Protocol Secure (HTTPS).
Refer to the appendix for TTPs associated with this tool.
APT Tool for OPC UA
The APT actors’ tool for OPC UA has modules with basic functionality to identify OPC UA servers and to connect to an OPC UA server using default or previously compromised credentials. The client can read the OPC UA structure from the server and potentially write tag values available via OPC UA.
The threat from this tool can be significantly reduced by properly configuring OPC UA security. Refer to the Mitigations below for more information.
Refer to the appendix for TTPs associated with this tool.
Mitigations
Note: these mitigations are provided to enable network defenders to begin efforts to protect systems and devices from new capabilities. They have not been verified against every environment and should be tested prior to implementing.
DOE, CISA, NSA, and the FBI recommend all organizations with ICS/SCADA devices implement the following proactive mitigations:
- Isolate ICS/SCADA systems and networks from corporate and internet networks using strong perimeter controls, and limit any communications entering or leaving ICS/SCADA perimeters.
- Enforce multifactor authentication for all remote access to ICS networks and devices whenever possible.
- Have a cyber incident response plan, and exercise it regularly with stakeholders in IT, cybersecurity, and operations.
- Change all passwords to ICS/SCADA devices and systems on a consistent schedule, especially all default passwords, to device-unique strong passwords to mitigate password brute force attacks and to give defender monitoring systems opportunities to detect common attacks.
- Ensure OPC UA security is correctly configured with application authentication enabled and explicit trust lists.
- Ensure the OPC UA certificate private keys and user passwords are stored securely.
- Maintain known-good offline backups for faster recovery upon a disruptive attack, and conduct hashing and integrity checks on firmware and controller configuration files to ensure validity of those backups.
- Limit ICS/SCADA systems’ network connections to only specifically allowed management and engineering workstations.
- Robustly protect management systems by configuring Device Guard, Credential Guard, and Hypervisor Code Integrity (HVCI). Install Endpoint Detection and Response (EDR) solutions on these subnets and ensure strong anti-virus file reputation settings are configured.
- Implement robust log collection and retention from ICS/SCADA systems and management subnets.
- Leverage a continuous OT monitoring solution to alert on malicious indicators and behaviors, watching internal systems and communications for known hostile actions and lateral movement. For enhanced network visibility to potentially identify abnormal traffic, consider using CISA’s open-source ,
- .
For additional guidance on securing OPC UA enabled devices, see:
- Dragos’ Blog – framework for all referenced threat actor tactics and techniques.
Table 1: APT Tool for Schneider Electric ICS TTPs
Tactic
Technique
]
Scripting [
Modify Program []
Valid Accounts [
Remote System Discovery []
]
Program Download []
]
Program Upload [T0845]
Monitor Process State [
Commonly Used Port []
]
Block Command Message []
Data Destruction []
System Firmware [
Modify Parameter []
]
Denial of View []
Loss of Control []
Manipulation of Control []
Table 2: APT Tool for OMRON ICS TTPs
Tactic
Technique
]
]
Scripting []
Modify Controller Tasking []
]
Valid Accounts [
Change Operating Mode [
Network Sniffing []
Remote System Information Discovery [
Default Credentials []
Program Download []
Valid Accounts [
Detect Operating Mode []
Program Upload [
Commonly Used Port []
]
]
Unauthorized Command Message [
Damage to Property []
Manipulation of Control []
Table 3: APT Tool for OPC UA ICS TTPs
Tactic
Technique
]
Scripting [
Valid Accounts [
Remote System Discovery []
]
]
Point & Tag Identification [
Commonly Used Port []
]
Theft of Operational Information [ or (888) 282-0870 and/or to the FBI via your . When available, please include the following information regarding the incident: date, time, and location of the incident; type of activity; number of people affected; type of equipment used for the activity; the name of the submitting company or organization; and a designated point of contact. For NSA client requirements or general cybersecurity inquiries, contact the Cybersecurity Requirements Center at 410-854-4200 or and this Privacy & Use policy.
↗ Original-Artikel auf us-cert.cisa.gov lesenVollständiges Original-AdvisoryAusführliche Details, Exploit-Analyse & Hersteller-Stellungnahme auf us-cert.cisa.gov.Wie bewertest du diesen Beitrag?1 Klick FeedbackTeilen mit Netzwerk & Team:Community-Analysen & Experten-Meinungen 0
Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf „ Eigene Analyse verfassen“!Community Pulse: Relevanz-Einschätzung1 Klick Experten-Votum🔴 Akute Relevanz 0%🟡 In Evaluierung 0%🟢 Keine Auswirkung 0%Spannende Innovation 0%Port 8095 EngineVerwandte Story-Cluster & Quellen (Vektor-KI)
Tipp: Mit Pfeiltasten [ ← ] und [ → ] blättern
Ähnliche Beiträge
🔍 Verwandte NewsAuch interessante Nachrichten AA22-103A: APT Cyber Tools Targeting ICS/SCADA Devices
Thematisch verwandte Begriffe: AA22103A, Cyber, Tools, Targeting · 6 Treffer
CVE-2022-44171 | Tenda AC18 15.03.05.19 form_fast_setting_wifi_set buffer overflow (EUVD-2022-47121)
Laden...Videos werden geladen ...
Laden...Beiträge werden geladen ...
Laden...Videos werden geladen ...
Laden...Beiträge werden geladen ...
Laden...Videos werden geladen ...
Laden...Beiträge werden geladen ...
Laden...Videos werden geladen ...
Laden...Beiträge werden geladen ...
Laden...Videos werden geladen ...
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformentsecurity.de Live Threat Radar
🔴 LIVE RADAR🔍🛡️ 📰 Alle Kategorien 2.655.091🤖 🔧 AI Nachrichten 32.632📺 🎥 Video | Youtube 36.382🛡️ 🔧 Programmierung 437.505🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.News ⏱️ 3 Min vor 10 MinArtikeldaten werden geladen...Zum Aktualisieren ziehen
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms LadezeitInstalliere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.
Nächster BeitragCommunity Radar & Live Chat
Sentinel Bot online • Live-StreamDein Cluster: Security ExplorerMatch:lädt…Aktivitäten deiner Analysten
lädt…Neues Thema oder Eilmeldung einreichen
Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.
Heiß diskutierte Einreichungen
SOCIAL SHARE CARD GENERATOR