New Russia-linked malware aimed at disrupting power grids has been identified by Mandiant threat researchers, urging energy companies to take steps to mitigate this ‘imminent threat’ .
A specialized operational technology (OT) malware called COSMICENERGY has similarities to malware used in previous attacks targeting power grids, including the 2016 “Industroyer” power outage in Kiev, Ukraine.
COSMICENERGY is designed to disconnect power by interacting with IEC 60870-5-104 (IEC-104) standard devices such as remote terminal units. These devices are commonly used in power transmission and distribution operations in Europe, the Middle East and Asia.
Similarly, in the 2016 Industroyer attack believed to be carried out by the Russian APT group Sandworm, the malware issued IEC-104 ON/OFF commands to interact with the RTU and used MSSQL as a conduit system for access. You may have used the server. OT.
This allowed attackers to send remote commands to influence the operation of power line switches and circuit breakers, causing power outages.
Mandiant said COSMICENERGY was uploaded to a public malware scanning utility by a Russian submitter in December 2021. Interestingly, from subsequent analysis, the company believes that Russian cybersecurity firm Rostelecom Solar or its contractors may have originally developed the malware for training purposes. Recreate real-world attack scenarios against energy grid assets.
Mandiant researchers said the attackers may have reused code related to cyber scope to develop this malware, with or without permission.
This distinguishes COSMICENERGY from previous OT malware aimed at disrupting energy grids. The threat actor leverages knowledge gained from previous attacks to create new attack tools, thereby lowering the barriers to entry for attacks on her OT systems.
This is of particular concern. “Because we typically observe that this kind of capability is limited to well-resourced or state-supported actors.”
Therefore, researchers cautioned that: “Given the use of red team tools and public exploitation frameworks by threat actors in real-world targeted threat campaigns, we believe that COSMICENERGY poses a plausible threat to affected power grid assets. OT asset owners utilizing IEC-104 compliant devices should take steps to pre-empt the potential wild deployment of COSMICENERGY.”
The team noted that COSMICENERGY lacks detection capabilities, “meaning that a successful attack would require malware operators to conduct internal reconnaissance to obtain environmental information.”