Showing posts with label BlackEnergy. Show all posts
Showing posts with label BlackEnergy. Show all posts

Monday, January 11, 2016

ICS-CERT Updates BlackEnergy Advisory

Today the DHS ICS-CERT updated their advisory on “Ongoing Sophisticated Malware Campaign Compromising ICS”, or BlackEnergy. The original advisory was published in October 2014 and updated in October and December of that year.

The update is based on information about the recent cyber based attack on Ukrainian power distribution systems over the Christmas holidays. More detailed information on that attack can be found on the SANS ICS Blog. The ICS-CERT update makes the point that a new variant of BlackEnergy (BlackEnergy 3) has been associated with this event and that the vector for the delivery of the malware appears to have been via “spear phishing via a malicious Microsoft Office (MS Word) attachment”.

The second addition to this advisory deals with the use of YARA rules to detect BlackEnergy infections. ICS-CERT maintains that the originally published YARA rules “has been shown to identify a majority of the samples seen as of this update and continues to be the best method for detecting BlackEnergy infections”. They also point out that using YARA signature with a control system must be done carefully since there are potentials for unintended interactions with control systems. They note:

“ICS-CERT has published instruction for how to use the YARA signature for typical information technology environments. ICS-CERT recommends a phased approach to utilize this YARA signature in an industrial control systems (ICSs) environment. Test the use of the signature in the test/quality assurance/development ICS environment if one exists. If not, deploy the signature against backup or alternate systems in the top end of the ICS environment; this signature will not be usable on the majority of field devices.”


NOTE: ICS-CERT continues to not list updates on their main landing page. For an update that is potentially important as this, it defies explanation why they did not at least make an exception in for this particular update. The only saving grace is that they did announce the update on TWITTER®.

Tuesday, December 16, 2014

ICS-CERT Publishes Schneider Advisory – Misses (again) Siemens Update

This afternoon the DHS ICS-CERT published a new advisory for five command injection vulnerabilities reported by Schneider last week and missed the latest BlackEnergy Siemens update for PCS 7.

Schneider Advisory

This advisory describes the five vulnerabilities reported by researchers Ariele Caltabiano, Andrea Micalizzi, and Brian Gorenc via ZDI in Schneider Electric’s ProClima software package. The ActiveX vulnerabilities are:

• MDraw30.ocx control, 3 vulnerabilities: CVE-2014-8513, CVE-2014-8514, and CVE-2014-9188;
• Atx45.ocx control , 2 vulnerabilities: CVE-2014-8511 and CVE-2014-8512.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit these vulnerabilities to induce a buffer overflow situation that could allow for remote code execution. The link to Schneider advisory is currently reporting ‘http status 404’.

ICS-CERT reports that Schneider has produced an update that mitigates the vulnerabilities. The do not say that the researchers have verified the efficacy of the fix.

Siemens Update


This morning Siemens ProductCert tweeted that they had just updated their WinCC/PCS 7 advisory that ICS-CERT had previously linked with some of the BlackEnergy attacks.  Siemens reported that they had produced an update for PCS 7 V7.1 SP4. This only leaves WinCC V7.0 SP3 without a fix in place. Siemens is working on that and will further update their advisory when that becomes available. ICS-CERT will presumably get around to updating their advisory.

Thursday, December 11, 2014

ICS-CERT Updates Siemens Advisory

This afternoon the DHS ICS-CERT updated their advisory for the Siemens vulnerability that they recently noted may be involved in some of the BlackEnergy attacks. Siemens reported two additional product variants for which there is now version that is resistant to the exploit of this vulnerability. Neither Siemens nor ICS-CERT have yet identified exactly what the vulnerabilities are; just what could result from a successful exploit. Hopefully that will change when the last two products are also protected.


I was a little surprised to see ICS-CERT get this update out this afternoon; after all Siemens only published their version this morning. I guess that now that ICS-CERT thinks that this might be involved in the BlackEnergy series of attacks (that ICS-CERT is only really explaining in classified briefings), they think that it may be important to get this information out to owners of  potentially affected systems.

Wednesday, December 10, 2014

ICS-CERT Updates Their Alert on Ongoing Malware Campaign

Today the DHS ICS-CERT published the second update of their alert concerning the BlackEnergy malware campaign. The first update was published on October 29th and the original alert was published the day before.

This update provides a little more information on the probable existence of a Siemens WinCC attack vector involved in the campaign. The original alert only provided the vaguest hint about the use of WinCC which ICS-CERT plainly said they could not confirm. They now say:

“While ICS-CERT lacks definitive information on how WinCC systems are being compromised by BlackEnergy, there are indications that one of the vulnerabilities fixed with the latest update for SIMATIC WinCC [link added] may have been exploited by the BlackEnergy malware. ICS-CERT strongly encourages users of WinCC, TIA Portal, and PCS7 to update their software to the most recent version as soon as possible.”

This version of the alert also updates the Yara Rules that allow organizations to interpret the results of scan conducted with the Yara pattern matching tool. ICS-CERT recommends that organizations running the updated scan and the application of the updated Yara Rules send copies of the results to ICS-CERT for more detailed interpretation of the data if there are any indications of potential compromise in the results.


ICS-CERT does not specifically state in this update that even those organizations that have already run the earlier version should run the updated scan. Since this apparently checks for later versions (or at least different versions) of the malware associated with BlackEnergy, it would seem to me that it would only be prudent to run this latest version and any new versions that ICS-CERT might publish in the future.
 
/* Use this with templates/template-twocol.html */