Showing posts with label Black Energy. Show all posts
Showing posts with label Black Energy. Show all posts

Wednesday, February 10, 2016

ICS-CERT Updates Black Energy Alert Yet Again

This afternoon the DHS ICS-CERT updated their alert on Black Energy that was originally published in October and most recently updated on February 1st. As with most of the updates that have been published, today’s modifies the way that the Yara rules for detecting Black Energy are listed.

Today’s update provides a link to the latest version of the Yara tool on GitHub, a separate text file for the Black Energy signature and the Yara documentation site.

It certainly seems like ICS-CERT is going to be using the Yara tool for helping folks detect systemic attacks like Black Energy. While this looks like a very valuable tool for Windows® based systems (and a lot of ICS components are Windows based) ICS-CERT notes that there may be problems in using this tool on other ‘high-end’ ICS components and it almost certainly cannot be used on ‘the majority of field devices’.

It would be extremely helpful is ICS-CERT could do (or have someone else do) some additional research on the use of the Yara tool on some common control system components. This would allow them to provide more information than just the two sentences provided in the Alert:

“Test the use of the signature in the test/quality assurance/development ICS environment if one exists. If not, deploy the signature against backup or alternate systems in the top end of the ICS environment; this signature will not be usable on the majority of field devices.”


The use of tools like Yara will be very valuable as the ICS threat environment continues to get more complex. ICS-CERT should be a leader in developing the use of such tools and helping get them into use in the field. Lacking their leadership, we are going to have to rely on vendors to develop these types of tools for specific use on their systems, and I don’t see any beyond maybe the top three or so having the resources to do that.

Monday, February 1, 2016

ICS-CERT Updates Black Energy Alert Again

For the second time in a month the DHS ICS-CERT updated their alert for the Black Energy campaign. Last month the advisory was updated to reflect new information from the Ukraine power outage incident. Today’supdate provides revisions of the Yara rules for detecting Black Energy 2 and Black Energy 3 that also detect newer versions of the malware.

ICS-CERT continues to report that they have a more detailed version of this report available for limited distribution. The note that: “Asset owners and operators can request access to this information by emailing ics-cert@dhs.gov.”

Today’s update was listed on the ICS-CERT landing page, but you have to have been really alert to have noticed the change in the listing under the “Most Downloaded” section of the page. As I have noted frequently of late, it was also announced on TWITTER®.


BTW: Neither today’s Siemens’ update or last Friday’s update were mentioned on the ICS-CERT web site today.

Wednesday, October 29, 2014

ICS-CERT Adds Hash Validations for Yara Downloads

This afternoon the DHS ICS-CERT published its first update for yesterday’s alert about the newly identified (but old in the field) Black Energy compromise of control systems from multiple vendors. Today’s update provides the information necessary to complete a validation of the Yara binaries that ICS-CERT provided for download.

Those binaries were provided to allow owner/operators to check their systems to see if they were part of the compromised control system environment. Unfortunately, unless you are part of the twisted minority that can actually read binaries, downloading and executing binary that have not been verified is probably the single most unsecure action anyone can do on the internet. And there was ICS-CERT asking critical infrastructure owners to do just that.

Now, to be fair, I did not point this out last night because I made the same assumption that ICS-CERT probably expected everyone to make. These files came publicly from ICS-CERT so they were properly vetted, verified and safe. And that is almost certainly true (I don’t know because I can’t read binaries) if you downloaded them from the ICS-CERT site (unless of course someone hacked the ICS-CERT site and modified the binaries posted there). If you downloaded them from a bogus copy of the ICS-CERT site, or got them from some other site as a ‘true copy’ of the ICS-CERT supplied, or you got them in an email that appeared to come from someone you should be able to trust, or any number of alternative methods, then you would need some independent method of insuring that the binaries are the ones that ICS-CERT provided in the first place.

Fortunately, there are some people around who are less trusting. One such last night was OMG ‘H’AXOR (@SynAckPwn) who noted: “Juicy watering hole target identified: ICSCERT just reco'd control sys owners go to gDrive linked from github, DL EXE, run on ICS systems”. That comment spawned a very interesting series of Twitversations last night. Apparently, ICS-CERT was listening as they quickly (for a government agency VERY QUICKLY) provided the necessary data to verify the binaries.

Is it enough? It depends on how many noids you have. If you have a pair you might point out that anyone could still set up a mirror site and post modified binaries with modified hash information and they would still own any system upon which this binary was used to check for the Black Energy compromise. In a truly paranoid world you would want the two items to come from different sources with appropriate separate authentication for each source. But, let’s face it; even that could be hacked.

BTW: The REALLY PARANOID would never have seen this information in the first place because it was published in a .PDF document; and NOBODY in the right mind would open a .PDF.

But, I think that ICS-CERT should still be given credit for taking the effort. This time. They really should come up with a better method for sharing this information in any future action of this sort.

Tuesday, October 28, 2014

ICS-CERT Publishes Long Term Anti-ICS Campaign Advisory

This evening the DHS ICS-CERT published an alert about a long term anti-ICS campaign that has been compromising various control systems from multiple vendors since at least 2011. ICS-CERT is reporting that, at a minimum, HMI from GE, Advantech and Siemens have been compromised in this campaign. They are not currently reporting any damage to control systems or to operations that are controlled by those systems.

ICS-CERT is publicly providing detailed information about how these compromised HMI can be identified and it is asking all potentially affected system owners to check their systems and notify ICS-CERT if evidence of compromise exists.

As one would suspect with something that is apparently as serious as this, ICS-CERT has released an alert (ICS-ALERT-14-281-01P) on the US-CERT secure portal and has already published an update to that alert. ICS-CERT is also taking the unusual step of publicly describing that alert and notifying “US critical infrastructure asset owners and operators” that they can request a copy of the alert by email (ICS-CERT@HQ.DHS.gov).

As I have already mentioned on TWITTER®, this is the most detailed ICS-CERT alert that I have ever seen, especially on an initial publication. This is the type of information that we should be able to expect from ICS-CERT. This is also the type problem that we really need to be able to expect them to delve deeply into. I suspect, however, that we will be receiving the bulk of our information on this from private sector researchers who will have more resources and expertise to throw at this problem. That would be a good topic for a congressional investigation.

BTW: Here is an interesting question about this issue from Chris Sistrunk: “Could the BlackEnergy ICS malware be related to the vulns discovered by Z0mb1E and amisto0x07 from ZDI and the Metasploit mods they wrote?”

BTW: The alert contains a link to the GE security page. Nothing specific there except a brief note that: “The CIMPLICITY Webview server that existed in prior versions of CIMPLICITY, has been removed due to security concerns.” No further information available.


BTW: Siemens Product-CERT also is saying nothing. 
 
/* Use this with templates/template-twocol.html */