🕵️ Sicherheitslücken 🕛 vor 4 Jahren 11 Min Lesezeit CVE-2020-15368
0

AA22-103A: APT Cyber Tools Targeting ICS/SCADA Devices

Cyber Threat & Vulnerability Dossier
ANGRIPPSVEKTOR
💻 Lokal
AUTHENTIFIZIERUNG
🔑 Geringe Nutzerrechte nötig
SCHADENSPROFIL
⛔ Dienstausfall (DoS) / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-94: Code Injection
Handlungsempfehlung: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
Im CVE-Radar öffnen
↗ Quelle (us-cert.cisa.gov)
🔬 IoC Intelligence (1 Indikatoren erkannt)
CVE-2020-15368
🗣️ Stimme:
📑 Inhaltsübersicht
Original release date: April 13, 2022 | Last revised: May 25, 2022

Summary

Actions to Take Today to Protect ICS/SCADA Devices:

• Enforce multifactor authentication for all remote access to ICS networks and devices whenever possible.

• Change all passwords to ICS/SCADA devices and systems on a consistent schedule, especially all default passwords, to device-unique strong passwords to mitigate password brute force attacks and to give defender monitoring systems opportunities to detect common attacks.

• Leverage a properly installed continuous OT monitoring solution to log and alert on malicious indicators and behaviors.



The Department of Energy (DOE), the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI) are releasing this joint Cybersecurity Advisory (CSA) to warn that certain advanced persistent threat (APT) actors have exhibited the capability to gain full system access to multiple industrial control system (ICS)/supervisory control and data acquisition (SCADA) devices, including:



  • Schneider Electric programmable logic controllers (PLCs),

  • OMRON Sysmac NEX PLCs, and

  • Open Platform Communications Unified Architecture (OPC UA) servers.

The APT actors have developed custom-made tools for targeting ICS/SCADA devices. The tools enable them to scan for, compromise, and control affected devices once they have established initial access to the operational technology (OT) network. Additionally, the actors can compromise Windows-based engineering workstations, which may be present in information technology (IT) or OT environments, using an exploit that compromises an ASRock motherboard driver with known vulnerabilities. By compromising and maintaining full system access to ICS/SCADA devices, APT actors could elevate privileges, move laterally within an OT environment, and disrupt critical devices or functions.



DOE, CISA, NSA, and the FBI urge critical infrastructure organizations, especially Energy Sector organizations, to implement the detection and mitigation recommendations provided in this CSA to detect potential malicious APT activity and harden their ICS/SCADA devices. 



to execute malicious code in the Windows kernel. Successful deployment of this tool can allow APT actors to move laterally within an IT or OT environment and disrupt critical devices or functions.



APT Tool for Schneider Electric Devices  



The APT actors’ tool for Schneider Electric devices has modules that interact via normal management protocols and Modbus (TCP 502). Modules may allow cyber actors to:



  • Run a rapid scan that identifies all Schneider PLCs on the local network via User Datagram Protocol (UDP) multicast with a destination port of 27127 (Note: UDP 27127 is a standard discovery scan used by engineering workstations to discover PLCs and may not be indicative of malicious activity);

  • Brute-force Schneider Electric PLC passwords using CODESYS and other available device protocols via UDP port 1740 against defaults or a dictionary word list (Note: this capability may work against other CODESYS-based devices depending on individual design and function, and this report will be updated as more information becomes available); 

  • Conduct a denial-of-service attack to prevent network communications from reaching the PLC;

  • Sever connections, requiring users to re-authenticate to the PLC, likely to facilitate capture of credentials; 

  • Conduct a ‘packet of death’ attack to crash the PLC until a power cycle and configuration recovery is conducted; and 

  • Send custom Modbus commands (Note: this capability may work against Modbus other than in Schneider Electric PLCs).

Refer to the appendix for tactics, techniques, and procedures (TTPs) associated with this tool.



APT Tool for OMRON 



The APT actors’ tool for OMRON devices has modules that can interact by:



  • Scanning for OMRON using Factory Interface Network Service (FINS) protocol;

  • Parsing the Hypertext Transfer Protocol (HTTP) response from OMRON devices;

  • Retrieving the media access control (MAC) address of the device;

  • Polling for specific devices connected to the PLC;

  • Backing up/restoring arbitrary files to/from the PLC; and

  • Loading a custom malicious agent on OMRON PLCs for additional attacker-directed capability.

Additionally, the OMRON modules can upload an agent that allows a cyber actor to connect and initiate commands—such as file manipulation, packet captures, and code execution—via HTTP and/or Hypertext Transfer Protocol Secure (HTTPS). 



Refer to the appendix for TTPs associated with this tool.



APT Tool for OPC UA 



The APT actors’ tool for OPC UA has modules with basic functionality to identify OPC UA servers and to connect to an OPC UA server using default or previously compromised credentials. The client can read the OPC UA structure from the server and potentially write tag values available via OPC UA.



The threat from this tool can be significantly reduced by properly configuring OPC UA security. Refer to the Mitigations below for more information. 



Refer to the appendix for TTPs associated with this tool.


Mitigations

Note: these mitigations are provided to enable network defenders to begin efforts to protect systems and devices from new capabilities. They have not been verified against every environment and should be tested prior to implementing.



DOE, CISA, NSA, and the FBI recommend all organizations with ICS/SCADA devices implement the following proactive mitigations:



  • Isolate ICS/SCADA systems and networks from corporate and internet networks using strong perimeter controls, and limit any communications entering or leaving ICS/SCADA perimeters. 

  • Enforce multifactor authentication for all remote access to ICS networks and devices whenever possible.

  • Have a cyber incident response plan, and exercise it regularly with stakeholders in IT, cybersecurity, and operations.

  • Change all passwords to ICS/SCADA devices and systems on a consistent schedule, especially all default passwords, to device-unique strong passwords to mitigate password brute force attacks and to give defender monitoring systems opportunities to detect common attacks.

  • Ensure OPC UA security is correctly configured with application authentication enabled and explicit trust lists. 

  • Ensure the OPC UA certificate private keys and user passwords are stored securely. 

  • Maintain known-good offline backups for faster recovery upon a disruptive attack, and conduct hashing and integrity checks on firmware and controller configuration files to ensure validity of those backups. 

  • Limit ICS/SCADA systems’ network connections to only specifically allowed management and engineering workstations.

  • Robustly protect management systems by configuring Device Guard, Credential Guard, and Hypervisor Code Integrity (HVCI). Install Endpoint Detection and Response (EDR) solutions on these subnets and ensure strong anti-virus file reputation settings are configured.

  • Implement robust log collection and retention from ICS/SCADA systems and management subnets.

  • Leverage a continuous OT monitoring solution to alert on malicious indicators and behaviors, watching internal systems and communications for known hostile actions and lateral movement. For enhanced network visibility to potentially identify abnormal traffic, consider using CISA’s open-source , 

  • .  

For additional guidance on securing OPC UA enabled devices, see: 




  • Dragos’ Blog – framework for all referenced threat actor tactics and techniques.



    Table 1: APT Tool for Schneider Electric ICS TTPs

























    Tactic Technique
    ]
    Scripting [ Modify Program []
    Valid Accounts [ Remote System Discovery []
    ]
    Program Download []
    ]
    Program Upload [T0845]
    Monitor Process State [ Commonly Used Port []
    ]
    Block Command Message []
    Data Destruction []
    System Firmware [ Modify Parameter []
    ]
    Denial of View []
    Loss of Control []
    Manipulation of Control []

     



    Table 2: APT Tool for OMRON ICS TTPs

























    Tactic Technique
    ]
    ]
    Scripting []
    Modify Controller Tasking []
    ]
    Valid Accounts [ Change Operating Mode [ Network Sniffing []
    Remote System Information Discovery [ Default Credentials []
    Program Download []
    Valid Accounts [ Detect Operating Mode []
    Program Upload [ Commonly Used Port []
    ]
    ]
    Unauthorized Command Message [ Damage to Property []
    Manipulation of Control []

     



    Table 3: APT Tool for OPC UA ICS TTPs














    Tactic Technique
    ]
    Scripting [ Valid Accounts [ Remote System Discovery []
    ]
    ]
    Point & Tag Identification [ Commonly Used Port []
    ]
    Theft of Operational Information [ or (888) 282-0870 and/or to the FBI via your . When available, please include the following information regarding the incident: date, time, and location of the incident; type of activity; number of people affected; type of equipment used for the activity; the name of the submitting company or organization; and a designated point of contact. For NSA client requirements or general cybersecurity inquiries, contact the Cybersecurity Requirements Center at 410-854-4200 or and this Privacy & Use policy.


    Vollständiges Original-Advisory
    Ausführliche Details, Exploit-Analyse & Hersteller-Stellungnahme auf us-cert.cisa.gov.
    ↗ Original-Artikel auf us-cert.cisa.gov lesen
    Wie bewertest du diesen Beitrag?
    1 Klick Feedback
    Teilen mit Netzwerk & Team:
    Community Threat-Level Barometer
    Live Votum

    Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

    Noch keine Stimmen — schätze das Risiko als Erster ein.

    Community-Analysen & Experten-Meinungen 0

    Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
    Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
    Community Pulse: Relevanz-Einschätzung
    1 Klick Experten-Votum
    🔴 Akute Relevanz 0%
    🟡 In Evaluierung 0%
    🟢 Keine Auswirkung 0%
    Spannende Innovation 0%
    Verwandte Story-Cluster & Quellen (Vektor-KI)
    Port 8095 Engine
    9 Quellen
    CVE-2022-44169 | Tenda AC15 15.03.05.18 formSetVirtualSer buffer overflow (EUVD-2022-47119)
    1 Quelle
    Best early October Prime Day deals: Save on TVs, smartwatches, and more tech
    1 Quelle
    I gave Claude Code $100 and 30 days to make a profit. Day 1, it built a product. Here's the pattern it used.
    Ähnliche Beiträge
    🔍 Verwandte News

    Auch interessante Nachrichten AA22-103A: APT Cyber Tools Targeting ICS/SCADA Devices

    Thematisch verwandte Begriffe: AA22103A, Cyber, Tools, Targeting · 6 Treffer

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    tsecurity.de-Newsletter

    Wöchentliche Top-CVEs, 0-Day-Intelligence & Incident-Reports — kostenlos, jederzeit abbestellbar.

    © 2015 - 2026 tsecurity.de — Nachrichten- & Content-Portal. Alle Rechte vorbehalten.

    SSL 256-bit DSGVO Konform
    Themen-Radar & Intelligence Matrix
    Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen
    🔖 Gespeicherte Artikel
    📂 Keine gespeicherten Artikel vorhanden.
    News ⏱️ 3 Min vor 10 Min
    Artikeldaten werden geladen...

    ↗ Original-Quelle
    Zum Aktualisieren ziehen
    ZERO-DAY Kritische Sicherheitsmeldung
    Advisory →
    TTS Reader • tsecurity.de Voice
    tsecurity.de Icon
    tsecurity.de App
    Offline-Lesen, Eilmeldungen & 0ms Ladezeit

    Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

    Nächster Beitrag
    Community Radar & Live Chat
    Sentinel Bot online • Live-Stream
    Dein Cluster: Security Explorer
    Match:
    lädt…
    Verbindung zum Community-Stream wird aufgebaut...
    Aktivitäten deiner Analysten
    lädt…
    Neues Thema oder Eilmeldung einreichen

    Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

    Heiß diskutierte Einreichungen