Thursday, 30 October 2014

BlackEnergy malware has compromised industrial control systems for two years

US CERT logo
THE US DEPARTMENT OF HOMELAND SECURITY Computer Emergency Response Team (US-CERT) has warned that industrial control systems (ICS) in the US have been compromised by the BlackEnergy malware for at least two years.
The BlackEnergy family of malware is believed to be the same used in the cyber attack against Georgia in 2008.
It uses a malicious decoy document to hide its activities, making it easier for the hackers to mount follow-up attacks.
US-CERT said the malware campaign is sophisticated and "ongoing", and attackers taking advantage of it have compromised unnamed ICS operators, planting it on internet-facing human machine interfaces (HMI) including those from GE Cimplicity, Advantech/Broadwin WebAccess, and Siemens WinCC.
It is currently unknown whether other vendors' products have also been targeted, according to US-CERT.
"At this time, Industrial Control Systems-CERT has not identified any attempts to damage, modify or otherwise disrupt the victim systems' control processes," said the team in an alert.
"ICS-CERT has not been able to verify if the intruders expanded access beyond the compromised HMI into the remainder of the underlying control system.
"However, typical malware deployments have included modules that search out any network-connected file shares and removable media for additional lateral movement within the affected environment."
US-CERT describes the malware as "highly modular", and said that not all functionality is deployed to all victims.
An analysis run by the team identified the probable initial infection vector for systems running GE's Cimplicity HMI with a direct connection to the internet.
"Analysis of victim system artefacts has determined that the actors have been exploiting a vulnerability (CVE-2014-0751) in GE's Cimplicity HMI product since at least January 2012," the alert read.
On Monday, US-CERT also warned of attacks spreading the Dyre banking malware, which steals victims' credentials.
The department said that, since mid-October, a phishing campaign had targeted "a wide variety of recipients", but elements, such as the exploits, email themes, and claimed senders of the campaign, "vary from target to target".
"A system infected with Dyre banking malware will attempt to harvest credentials for online services, including banking services," the alert warned.

T-Mobile toughens network encryption against government snooping

cell-hero
(Image: CNET/CBS Interactive)
T-Mobile's networks may have changed for the better — stronger signal, faster speeds, better coverage — but what you probably didn't know is that they're now even more secure.
In upgrading its U.S. networks, the fourth largest cellular giant in the country also bolstered encryption in a number of cities, switching to A5/3 encryption from the A5/1 standard on the older 2G networks, which in some cases still carry calls or text messages when faster data isn't available. Newer technologies, like 3G and 4G (LTE), already offer significantly stronger encryption.

The Washington Post, which first tested the networks in a number of cities, said New York, Washington, and Boulder, Colorado are now using the newer standard, covering tens of millions of customers.
Upgrading the network to the newer A5/3 encryption makes it significantly harder to eavesdrop on calls and text messages. Even for the National Security Agency, which reportedly is able to decode the older, legacy A5/1 encryption, may face headaches with the new standard.
T-Mobile did not comment on the encryption.
In densely populated areas, such as the cities with enhanced encryption, monitoring cellular calls becomes more difficult — simply because of the volume of people. The call and text data is still routed through ground networks, but filtering it becomes difficult. The Post explained that an "IMSI catcher," which can identify an individual cell subscriber, can make it easier to snoop on calls and texts without having to crack the phone or network's encryption.
AT&T said it is already ramping up its encryption efforts by offering A5/3 encryption, but tests by the Post found  in U.S. locations where T-Mobile upgraded, AT&T had not.
In any case, AT&T is shutting down its A5/1-encrypted 2G network by 2017, and replacing it with newer technology.