The Fox is Guarding the Henhouse: Microsoft enters the MSSP Space
Microsoft has decided it's time to dip its big toe in the Managed Security Services Provider (MSSP) space with three brand new products, Microsoft...
Telephone
1 (877) 664-9379
Press "1" for Support
Press "2" for Sales
Press "3" for Finance
Headquarters
861 Lafayette Rd
Unit 4
Hampton, NH 03842
Actions to Take Today to Protect ICS/SCADA Devices:
• Enforce multifactor authentication for all remote access to ICS networks and devices whenever possible.
• Change all passwords to ICS/SCADA devices and systems on a consistent schedule, especially all default passwords, to device-unique strong passwords to mitigate password brute force attacks and to give defender monitoring systems opportunities to detect common attacks.
• Leverage a properly installed continuous OT monitoring solution to log and alert on malicious indicators and behaviors.
The Department of Energy (DOE), the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI) are releasing this joint Cybersecurity Advisory (CSA) to warn that certain advanced persistent threat (APT) actors have exhibited the capability to gain full system access to multiple industrial control system (ICS)/supervisory control and data acquisition (SCADA) devices, including:
The APT actors have developed custom-made tools for targeting ICS/SCADA devices. The tools enable them to scan for, compromise, and control affected devices once they have established initial access to the operational technology (OT) network. Additionally, the actors can compromise Windows-based engineering workstations, which may be present in information technology (IT) or OT environments, using an exploit that compromises an ASRock motherboard driver with known vulnerabilities. By compromising and maintaining full system access to ICS/SCADA devices, APT actors could elevate privileges, move laterally within an OT environment, and disrupt critical devices or functions.
DOE, CISA, NSA, and the FBI urge critical infrastructure organizations, especially Energy Sector organizations, to implement the detection and mitigation recommendations provided in this CSA to detect potential malicious APT activity and harden their ICS/SCADA devices.
Click here for a PDF version of this report.
APT actors have developed custom-made tools that, once they have established initial access in an OT network, enables them to scan for, compromise, and control certain ICS/SCADA devices, including the following:
The APT actors’ tools have a modular architecture and enable cyber actors to conduct highly automated exploits against targeted devices. The tools have a virtual console with a command interface that mirrors the interface of the targeted ICS/SCADA device. Modules interact with targeted devices, enabling operations by lower-skilled cyber actors to emulate higher-skilled actor capabilities.
The APT actors can leverage the modules to scan for targeted devices, conduct reconnaissance on device details, upload malicious configuration/code to the targeted device, back up or restore device contents, and modify device parameters.
In addition, the APT actors can use a tool that installs and exploits a known-vulnerable ASRock-signed motherboard driver, AsrDrv103.sys,
exploiting CVE-2020-15368 to execute malicious code in the Windows kernel. Successful deployment of this tool can allow APT actors to move laterally within an IT or OT environment and disrupt critical devices or functions.
The APT actors’ tool for Schneider Electric devices has modules that interact via normal management protocols and Modbus (TCP 502). Modules may allow cyber actors to:
Refer to the appendix for tactics, techniques, and procedures (TTPs) associated with this tool.
The APT actors’ tool for OMRON devices has modules that can interact by:
Additionally, the OMRON modules can upload an agent that allows a cyber actor to connect and initiate commands—such as file manipulation, packet captures, and code execution—via HTTP and/or Hypertext Transfer Protocol Secure (HTTPS).
Refer to the appendix for TTPs associated with this tool.
The APT actors’ tool for OPC UA has modules with basic functionality to identify OPC UA servers and to connect to an OPC UA server using default or previously compromised credentials. The client can read the OPC UA structure from the server and potentially write tag values available via OPC UA.
Refer to the appendix for TTPs associated with this tool.
Note: these mitigations are provided to enable network defenders to begin efforts to protect systems and devices from new capabilities. They have not been verified against every environment and should be tested prior to implementation.
DOE, CISA, NSA, and the FBI recommend all organizations with ICS/SCADA devices implement the following proactive mitigations:
For additional guidance on securing OT devices, see
For more information on APT actors’ tools and TTPs, refer to:
The information in this report is being provided “as is” for informational purposes only. DOE, CISA, NSA, and the FBI do not endorse any commercial product or service, including any subjects of analysis. Any reference to specific commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by the DOE, CISA, NSA, or the FBI, and this guidance shall not be used for advertising or product endorsement purposes.
The DOE, CISA, NSA, and the FBI would like to thank Dragos, Mandiant, Microsoft, Palo Alto Networks, and Schneider Electric for their contributions to this joint CSA.
See tables 1 through 3 for TTPs associated with the cyber actors’ tools described in this CSA mapped to the MITRE ATT&CK for ICS framework. See the ATT&CK for ICSframework for all referenced threat actor tactics and techniques.
Table 1: APT Tool for Schneider Electric ICS TTPs
Tactic | Technique |
---|---|
Execution | Command-Line Interface [T0807] |
Scripting [T0853] | |
Persistence | Modify Program [T0889] |
System Firmware [T0857] | |
Valid Accounts [T0859] | |
Discovery | Remote System Discovery [T0846] |
Remote System Information Discovery [T0888] | |
Lateral Movement | Default Credentials [T0812] |
Program Download [T0843] | |
Valid Accounts [T0859] | |
Collection | |
Monitor Process State [T0801] | |
Program Upload [T0845] | |
Monitor Process State [T0801] | |
Command and Control | Commonly Used Port [T0885] |
Standard Application Layer Protocol [T0869] | |
Inhibit Response Function | Block Reporting Message [T0804] |
Block Command Message [T0803] | |
Denial of Service [T0814] | |
Data Destruction [T0809] | |
Device Restart/Shutdown [T0816] | |
System Firmware [T0857] | |
Impair Process Control | Modify Parameter [T0836] |
Unauthorized Command Message [T0855] | |
Impact | Denial of Control [T0813] |
Denial of View [T0815] | |
Loss of Availability [T0826] | |
Loss of Control [T0827] | |
Loss of Productivity and Revenue [T0828] | |
Manipulation of Control [T0831] | |
Theft of Operational Information [T0882] |
Table 2: APT Tool for OMRON ICS TTPs
Tactic | Technique |
---|---|
Initial Access | Remote Services [T0886] |
Execution | Command-Line Interface [T0807] |
Scripting [T0853] | |
Change Operating Mode [T0858] | |
Modify Controller Tasking [T0821] | |
Native API [T0834] | |
Persistence | Modify Program [T0889] |
Valid Accounts [T0859] | |
Evasion | Change Operating Mode [T0858] |
Discovery | Network Sniffing [T0842] |
Remote System Discovery [T0846] | |
Remote System Information Discovery [T0888] | |
Lateral Movement | Default Credentials [T0812] |
Lateral Tool Transfer [T0867] | |
Program Download [T0843] | |
Remote Services [T0886] | |
Valid Accounts [T0859] | |
Collection | Detect Operating Mode [T0868] |
Monitor Process State [T0801] | |
Program Upload [T0845] | |
Command and Control | Commonly Used Port [T0885] |
Standard Application Layer Protocol [T0869] | |
Inhibit Response Function | Service Stop [T0881] |
Impair Process Control | Modify Parameter [T0836] |
Unauthorized Command Message [T0855] | |
Impact | Damage to Property [T0879] |
Loss of Safety [T0837] | |
Manipulation of Control [T0831] | |
Theft of Operational Information [T0882] |
Table 3: APT Tool for OPC UA ICS TTPs
Tactic | Technique |
---|---|
Execution | Command-Line Interface [T0807] |
Scripting [T0853] | |
Persistence | Valid Accounts [T0859] |
Discovery | Remote System Discovery [T0846] |
Remote System Information Discovery [T0888] | |
Lateral Movement | Valid Accounts [T0859] |
Collection | Monitor Process State [T0801] |
Point & Tag Identification [T0861] | |
Command and Control | Commonly Used Port [T0885] |
Standard Application Layer Protocol [T0869] | |
Impact | Manipulation of View [T0832] |
Theft of Operational Information [T0882] |
Microsoft has decided it's time to dip its big toe in the Managed Security Services Provider (MSSP) space with three brand new products, Microsoft...
As if any well-minded cybersecurity professional would be trusting of the little buggers in the first place. Anywho, there's a new malware making the...
Aamir Lakhani, a global security strategist, and researcher at Fortinet's FortiGuard Labs, has shared an article on ThreatPost where he discusses the...