Mysterious safety-tampering malware infects a second critical infrastructure site

Peter Reutemann <[email protected]>
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12Js5Xf6EbLPe=u08zuf08B8EqxNUpFfbFwt=jJOZvg+eQ@mail.gmail.com>
'Sixteen months ago, researchers reported an unsettling escalation in
hacks targeting power plants, gas refineries, and other types of
critical infrastructure. Attackers who may have been working on behalf
of a nation caused an operational outage at a critical-infrastructure
site after deliberately targeting a system that prevented health- and
life-threatening accidents.

Game-changing attack on critical infrastructure site causes outage
There had been compromises of critical infrastructure sites before.
What was unprecedented in this attack—and of considerable concern to
some researchers and critical infrastructure operators—was the use of
an advanced piece of malware that targeted the unidentified site’s
safety processes. Such safety instrumented systems (SIS) are a
combination of hardware and software that many critical infrastructure
sites use to prevent unsafe conditions from arising. When gas fuel
pressures or reactor temperatures rise to potentially unsafe
thresholds, for instance, a SIS will automatically close valves or
initiate cooling processes to prevent health- or life-threatening
accidents.

Russia was likely behind dangerous critical infrastructure attack, report says
By focusing on the site’s SIS, the malware carried the threat of
physical destruction that depending on the site and the type of
accident had the potential to be serious if not catastrophic. The
malware was alternately named Triton and Trisis, because it targeted
the Triconex product line made by Schneider Electric. It’s development
was ultimately linked to a Russian government-backed research
institute.'

-- source: https://arstechnica.com/information-technology/2019/04/mysterious-safety-tampering-malware-infects-a-2nd-critical-infrastructure-site/

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.