Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cyberwarfare

Energy Companies in Europe, US Hit by Sophisticated Attack Campaign

Researchers at Symantec released a report today going inside an ongoing attack campaign targeting the energy sector.

Researchers at Symantec released a report today going inside an ongoing attack campaign targeting the energy sector.

According to Symantec, the attackers have compromised a number of different organizations during the past few years for the purposes of spying – and possibly, sabotage. Also known as ‘Energetic Bear’, the Dragonfly group is believed to have been in operation since at least 2011. Initially, its targets were in the defense and aviation industry in the United States and Canada. In early 2013, it shifted its focus to energy firms in the U.S. and Europe.

Energy Firms Targeted With Malware

“Among the targets of Dragonfly were energy grid operators, major electricity generation firms, petroleum pipeline operators, and energy industry industrial equipment providers,” researchers explained in a blog post. “The majority of the victims were located in the United States, Spain, France, Italy, Germany, Turkey, and Poland.”

The report builds on information released earlier this year by security firms CrowdStrike – which publicized the attack in January – and F-Secure. 

The attacks on the energy sector began with malware sent via phishing emails to targeted personnel. Symantec observed the spear phishing attempts hitting organizations in the form of PDF attachments between February 2013 and June 2013, mostly targeting the US and UK. They emails were disguised as messages about administration issues such as delivery problems or issues with an account.

Later on, the group added watering hole attacks into its repertoire by compromising websites likely to be visited by people working in the industry and redirecting them to sites hosting an exploit kit known as Lightsout. The Lightsout kit has been upgraded over time, and eventually became known as the Hello exploit kit.

The third phase of the campaign involved the Trojanizing of legitimate software bundles belonging to three different industrial control system (ICS) equipment manufacturers using malware detected as Backdoor.Oldrea (Havex), according to Symantec’s report (PDF).

The researchers reported that the first piece of Trojanized software was a product used to provide VPN access to programmable logic controller (PLC) type devices. The vendor discovered the attack shortly after it began, but by then there had already been 250 unique downloads of the compromised software. In the second incident, a European manufacturer of specialist PLC devices was compromised and had a software package containing a driver for one of its devices was compromised. According to Symantec, the software was available for download for at least six weeks between June and July in 2013.

The third firm was a European company that designs systems for managing wind turbines, biogas plants and other technology. In that case, the compromised software is believed to have been available for download for roughly 10 days in April 2014.

“Oldrea appears to be custom malware, either written by the group itself or created for it,” according to the researchers. “This provides some indication of the capabilities and resources behind the Dragonfly group. Once installed on a victim’s computer, Oldrea gathers system information, along with lists of files, programs installed, and root of available drives. It will also extract data from the computer’s Outlook address book and VPN configuration files. This data is then written to a temporary file in an encrypted format before being sent to a remote command-and-control (C&C) server controlled by the attackers.”

Advertisement. Scroll to continue reading.

The majority of the command and control servers appear to be hosted on compromised servers running content management systems. Oldrea was linked to the vast majority of the infections caused by the group.

A second piece of malware used by the group was a Russian remote access Trojan known as Karagany, which was found in about five percent of the infections. The Karagany Trojan is available on the underground market. The source code for the first version of the malware was leaked in 2010. Symantec researchers suspect the Dragonfly group may have taken this source code and modified it for the group’s own use. The malware can upload stolen data, download new files and run executable files on an infected machine. It is also capable of running additional plugins such as tools for collecting passwords and taking screenshots, according to Symantec.

“The attacks do have the hallmarks of a state-sponsored operation,” said Vikram Thakur, principal security response manager at Symantec. “The attackers are well resourced, with a high degree of technical capability and have a lot of tools at their disposal. Their targets are of strategic interest. Their motivations appear to be espionage rather than cybercrime. As an example, we see the threat not only targeting specific industries, but also stealing credentials to connect into networks with industrial equipment. Such activity maps to espionage. Coupled with the sophistication of the campaigns, this activity lends itself to being perceived as being state sponsored.”

*This story was updated with additional information.

Written By

Marketing professional with a background in journalism and a focus on IT security.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

Professional services company Slalom has appointed Christopher Burger as its first CISO.

More People On The Move

Expert Insights

Related Content

Cyberwarfare

WASHINGTON - Cyberattacks are the most serious threat facing the United States, even more so than terrorism, according to American defense experts. Almost half...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Cyberwarfare

Russian espionage group Nomadic Octopus infiltrated a Tajikistani telecoms provider to spy on 18 entities, including government officials and public service infrastructures.

Cyberwarfare

Several hacker groups have joined in on the Israel-Hamas war that started over the weekend after the militant group launched a major attack.

Cyberwarfare

An engineer recruited by intelligence services reportedly used a water pump to deliver Stuxnet, which reportedly cost $1-2 billion to develop.

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...

Cyberwarfare

The war in Ukraine is the first major conflagration between two technologically advanced powers in the age of cyber. It prompts us to question...