惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Scott Helme
Scott Helme
有赞技术团队
有赞技术团队
阮一峰的网络日志
阮一峰的网络日志
雷峰网
雷峰网
D
Docker
Stack Overflow Blog
Stack Overflow Blog
Hugging Face - Blog
Hugging Face - Blog
爱范儿
爱范儿
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
MyScale Blog
MyScale Blog
A
About on SuperTechFans
博客园 - 【当耐特】
U
Unit 42
H
Help Net Security
博客园 - 三生石上(FineUI控件)
V2EX - 技术
V2EX - 技术
T
Tor Project blog
博客园 - 叶小钗
G
Google Developers Blog
S
Securelist
Security Latest
Security Latest
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
T
Threat Research - Cisco Blogs
aimingoo的专栏
aimingoo的专栏
C
Cybersecurity and Infrastructure Security Agency CISA
博客园_首页
V
Vulnerabilities – Threatpost
P
Palo Alto Networks Blog
T
The Exploit Database - CXSecurity.com
The Register - Security
The Register - Security
Recorded Future
Recorded Future
NISL@THU
NISL@THU
量子位
L
LangChain Blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
C
Cyber Attacks, Cyber Crime and Cyber Security
C
CERT Recently Published Vulnerability Notes
The Hacker News
The Hacker News
D
DataBreaches.Net
小众软件
小众软件
罗磊的独立博客
Forbes - Security
Forbes - Security
The Last Watchdog
The Last Watchdog
Jina AI
Jina AI
I
InfoQ
S
Schneier on Security
Recent Announcements
Recent Announcements
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
S
Secure Thoughts

The Register - Security: CSO

Anthropic's Mythos has The Kettle crew curious, skeptical 'People's Panel' to check if UK wants controversial Digital ID will cost £630K Top npm package backdoored to drop dirty RAT on dev machines Lightning-fast exploits mean patch fast, says Cisco Talos Lightning-fast exploits mean patch fast, says Cisco Talos Smooth criminals talking their way into cloud environments, Google says Cybercrime up 245% since the start of the Iran war Scattered Lapsus$ Hunters seeks women to defraud helpdesks Every day in every way, passwords are getting worse CISA quietly updated ransomware flags on 59 flaws last year Deepfake job seeker applied to work for an AI security firm Deepfake job seeker applied to work for an AI security firm AI-powered cyberattack kits are 'just a matter of time' AI-powered cyberattack kits are 'just a matter of time' FortiGate SSO bug still exploitable despite December patch FortiGate SSO bug still exploitable despite December patch Judge tosses CrowdStrike shareholder suit over 2024 outage DRAM shortage may drive firewall prices higher: analysts Ransomware attacks kept climbing in 2025 as gangs refused to stay dead Around 1,000 systems compromised in ransomware attack on Romanian water agency 1,000 systems pwned in Romanian Waters ransomware attack Half of exposed React servers remain unpatched amid attacks CISA warns spyware crews are breaking into Signal and WhatsApp accounts FCC guts Salt Typhoon telco rules despite espionage risk CISA orders feds to patch Oracle Identity Manager zero-day SEC drops SolarWinds lawsuit that painted a target on CISOs everywhere SEC bails on SolarWinds lawsuit Palo Alto kit sees massive surge in malicious activity amid mystery traffic flood Palo Alto kit sees massive surge in malicious activity Countries use cyber targeting to plan strikes: Amazon CSO Overconfidence is the new zero-day as teams stumble through cyber simulations UK's Cyber Security and Resilience Bill makes Parliamentary debut Cyber insurers paid out over twice as much for UK ransomware attacks last year Cyberpunks mess with Canada's water, energy, and farm systems Trump's workforce cuts blamed as America's cyber edge dulls Feds flag active exploitation of patched Windows SMB vuln How malware vaccines could stop ransomware's rampage Salesforce refuses to pay ransomware crims' extortion demand Germany slams brakes on EU's Chat Control snoopfest Germany slams brakes on EU's Chat Control snoopfest Employees regularly paste company secrets into ChatGPT Oracle tells Clop-targeted EBS users to apply July patch Red Hat repos raided, claims cybercrew, files stolen Suspected Chinese spies broke into 'numerous' enterprises UK gov acknowledges 'strong case' for JLR financial support JLR extends shutdown – again – as toll on workers laid bare UK chancellor blames cyberattacks on Russia despite evidence Fortra discloses 10/10 severity bug in GoAnywhere MFT Entra ID bug could have granted access to every tenant UEFI Secure Boot for Linux Arm64 – where do we stand? JLR says cyber cleanup to take additional week Insider blamed for FinWise data breach affecting nearly 700K Nork snoops whip up fake military ID with help from ChatGPT UK government dragged for incomplete security reforms Church of England abuse victims exposed by lawyer's email US spy chief claims UK backdown on Apple backdoor demand Workday confirms CRM breach via social engineering Black Hat/DEF CON: AI more useful for defense than hacking Ex-White House cyber guru talks Microsoft security fails CISA releases malware analysis for Sharepoint Server attack China: US spies used Microsoft Exchange 0-day to steal info Security pros drowning in threat-intel data Identity attacks surge 156% as phishermen get craftier Organizations can’t keep up with supply chain security musts Amazon CISO: Iranian hacking crews ‘on high alert’ UK data watchdog fines 23andMe £2.3M over 2023 breach Employers are demanding too much from junior cyber recruits FCA warned four staffers who pocketed regulator data Ransomware just wrecked your network – now what? Ivanti RCE attacks 'ongoing,' exploitation hits clouds Ex-NSA listened to Scattered Spider's calls: 'They're good' Snowflake CISO talks lessons learned from breaches, improv Why CVSS is failing us and what we can do about it Infosec pros still aren't nailing the basics of AI security Why aggregating asset inventory leads to better security NCSC and industry at odds over how to tackle shoddy software Powerschool extortionists may not have deleted stolen data CrowdStrike trims workforce by 5 percent, aims to rely on AI NSO Group must pay Meta $168M in WhatsApp spy case Ghost in the shell script: Boffins seek code correctness How Intruder finds what others miss in cloud security Linux malware can avoid syscall-based endpoint protection Infosec pro blabs about alleged malware mishap on LinkedIn The future of AI in cybersecurity in a word – optimistic CVE board 'kept in the dark' on funding, members say Security snafus caused by third parties up from 15% to 30% Blue Shield shared 4.7M people's health info with Google Ads Who needs phishing when your login's already in the wild? US cyber defenses are being dismantled from the inside Bug hunter obtains an SSL cert for Alibaba Cloud in 5 steps
Ransomware crims targeting systems between IT and operations
Jessica Lyons Jessica Lyons · 2025-05-14 · via The Register - Security: CSO

Criminals who attempt to damage critical infrastructure are increasingly targeting the systems that sit between IT and operational tech.

These in-between systems are no man's land, according to Tim Conway, the technical director of SANS Institute industrial control systems (ICS) programs. They're not classic IT systems that run core business applications, or operational tech (OT) that drives heavy industrial infrastructure.

In the case of a petroleum pipeline, middle systems live in the facilities that store and distribute fuel, and separate home heating oil from gasoline, diesel, and jet fuel.

"It's the system in the middle, and the impact of ransomware [on in-between systems] affects the integrity of the product," Conway told The Register. Back to that petroleum pipeline, where if the wrong product comes down the line the system isn’t sound.

"You can't continue to operate from a safety perspective. You're not going to put jet fuel in a car. You're not going to put home heating oil in a jet,” Conway said.

Getting to yes

All businesses have these middle systems, and digital crooks realize that encrypting them isn't as difficult as developing ransomware to target OT. But the operational impacts of attacks on in-between tech can be worse than the effects of attacks on IT or OT, and this means the victims are more likely to pay the extortion demands.

"The IT side is how we manage our business, the OT side is why we're a business, and as ransomware groups start to move closer and closer to those OT assets, it becomes a completely different discussion in boardrooms on do we pay, and how quickly do we pay," Conway said.

He used an example of a pharmaceutical company at which attackers target in-between systems that print product labels to illustrate how these attacks change decision-making processes.

"If you were a pharmaceutical [company], and we wanted to cause problems in the batch or the dosage or blend of a particular drug. We might not be able to get deep into the network to those industrial control systems, but we could manipulate the product labeling so the label that gets stamped onto a particular pill is wrong," Conway said. "It has the same result. All those things go out in the market. People get poisoned, people die."

"If you start from the perspective of: ‘We don't negotiate with terrorists, or we won't pay ransom’ it's one thing if you're talking about data," he added. "It's another thing if you're talking about human health and safety, and then it's a completely different equation of: ‘Do we pay to save lives?’ And that's an easy answer."

A growing threat

Every year, SANS Institute experts research the most dangerous new attack techniques, then decide on the five they believe pose the greatest risk.

This year, two of the top five are specific OT and ICS in critical infrastructure: Ransomware and destructive cyber-attacks.

Ransomware gangs have shown a "definite movement toward critical infrastructure" according to Conway, who said there's a simple reason for their changed behavior.

If you're talking about human health and safety, then it's a completely different equation of: ‘Do we pay to save lives?’ And that's an easy answer

When it comes to critical services like water stations and energy grids, it's easier for ransomware operators to infect the IT side of the house. This is what they did with the Colonial Pipeline attack. While that attack hurt the organization’s billing systems and led to panic buying and shortages at gas stations along the US East Coast, it’s OT such as pumping systems remained operational.

The Change Healthcare attack also involved ransomware aimed at IT systems and had a similarly disruptive impact on America's healthcare system. While the malware encrypted the payment processing and claims systems, it ultimately prevented pharmacies from filling patients' prescriptions and meant hospital patients couldn't receive needed medical treatment.

In the ransomware race, crims are moving closer to those OT assets.

Prior to 2024, just seven known malware variants targeted ICS systems. Last year, criminals created and deployedtwo more specifically designed to disrupt critical industrial processes.

"This is the sector to go after," Conway said. "It's faster to pay, and get back online quickly, so this is certainly shaping the behaviors of criminal financial groups to go after in big ways."

Destructive ICS attacks

Ransomware crews aren't the only miscreants targeting these sectors, however. Russia, China, and Iran have all tried to inflict damage on critical safety systems. And this brings us to SANS' second ICS-specific threat: destructive ICS attacks from sophisticated nation-state actors.

"When we're talking nation-state [attacks], you have a series of geopolitical events that have to occur before you start seeing activity in this area," Conway noted, adding that during his nearly three decades in security, he can't remember a time with so many simultaneous geopolitical conflicts.

"You look at the geopolitical situation with China and Taiwan, and you have that as a backstory of supply chain concerns," he added.

This led to Chinese government groups burrowing into American energy grids, prepositioning for future destructive attacks, and attacking government, telecommunications, and IT service providers' networks in the US and abroad.

"You look at what's happening in Eastern Europe, with Ukraine and Russia, and we're seeing more and more and more critical infrastructure focused attacks since 2022 than we had ever seen before," Conway continued.

In a particularly grim scenario, Russian malware called FrostyGoop targeted temperature controllers that supplied central heating to more than 600 apartment buildings in Lviv, Ukraine, and shut off the heat to thousands of civilians during a period of sub-zero temperatures in January 2024.

If you just cause an outage, you've taken the bullet out of the gun, and that can be recovered in hours

"And then you look to the Middle East and the events that occurred in Israel on October 7 with groups coming out of Iran that say: 'We are going to go after any country that's using technology that's made by Israel,'" Conway said.

He's talking about CyberAv3ngers, an Islamic Revolutionary Guard Corps (IRGC)-affiliated group that broke into water systems in late 2023 and was later spotted using custom malware called IOCONTROL to attack and remotely control US and Israel-based water and fuel management systems.

This ability to remotely control and manipulate critical system is especially dangerous, and it signals a shift in what attackers are doing with this illicit access, Conway added.

They're no longer just trying to cause an outage. Instead, government-backed goons want to keep the systems up and running so they can cause damage across longer periods of time.

"If you just cause an outage, you've taken the bullet out of the gun, and that can be recovered in hours," he explained.

On the other hand, if the ICS system remains "up and operational, you can manipulate it in ways where you cause equipment damage in that substation that take[s] anywhere from four to 18 weeks to replace," Conway noted. "A large water pump or an aquifer could take years to replace."

This requires a different approach to defending critical networks, he said. "Instead of thinking: How quickly can we restore? We need to pivot to [asking]: how quickly can we detect if an adversary is manipulating the system to cause destruction?" ®