惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Fortinet All Blogs
aimingoo的专栏
aimingoo的专栏
V
Visual Studio Blog
罗磊的独立博客
爱范儿
爱范儿
J
Java Code Geeks
博客园 - 司徒正美
N
Netflix TechBlog - Medium
Microsoft Security Blog
Microsoft Security Blog
美团技术团队
小众软件
小众软件
Google DeepMind News
Google DeepMind News
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
V
V2EX
博客园 - 聂微东
云风的 BLOG
云风的 BLOG
WordPress大学
WordPress大学
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Jina AI
Jina AI
Y
Y Combinator Blog
博客园 - 叶小钗
人人都是产品经理
人人都是产品经理
Martin Fowler
Martin Fowler
Vercel News
Vercel News

BlackEnergy Archives - Security Affairs

Russia-linked BlackEnergy backed new cyber attacks on Ukraine’s state bodies Exaramel Malware Links Industroyer ICS malware and NotPetya wiper Trend Micro spotted a new variant of KillDisk wiper in Latin America Experts spotted Industroyer ICS Malware and linked it to Ukraine Power Outage Malware posing as Siemens PLC application is targeting ICS worldwide Ukraine blames Russia for new cyber attacks on its infrastructure 2016 Christmas Ukraine power outage was caused by hackers BlackEnergy hackers, now TeleBots, target Ukrainian banks Experts found a government malware on the Dark Web
Malware experts at ESET released a free tool for ICS Malw...
Pierluigi Paganini · 2017-07-28 · via BlackEnergy Archives - Security Affairs

Security experts from ESET that spotted the Industroyer malware used against Ukraine’s power grid released a free tool for ICS Malware analysis

ESET researchers Robert Lipovsky and Anton Cherepanov have released a free tool for the analysis of ICS malware.

Industroyer ICS malware

The development of the tool was inspired by their investigation, the expert analyzed the ICS malware involved in the attack against Ukraine’s power grid in 2016 that caused a huge power outage in the city of Kiev and neighboring regions.

The researchers developed an IDAPython script for IDA Pro that could be used by malware researchers and cyber security experts to reverse-engineer binaries that employ the OPC Data Access industrial communications protocol.

“An IDAPython script for IDA Pro that helps reverse engineer binaries that are using the OPC Data Access protocol.” reads the description published on GitHub.

The script identifies CLSID, IID, and LIBID constants and creates structures and enumerations. Afterwards, these structures can be used to annotate COM method call parameters.”

Havex is a general purpose Remote Access Trojan (RAT) discovered in June 2015 when malware researchers at F-Secure spotted a cyber espionage campaign based on the Havex malware targeting ICS/SCADA systems and vendors.

The Havex malware has been used in several targeted attacks in the previous months; threat actors used it against different industry sectors.

“If there are other future malware [families] like Industroyer or Havex, [investigators] will have an easier time” finding and analyzing them, Lipovsky says.

“This tool helps you understand what the threat was designed to do,” he says. Detection is important, he says, “but if you want to understand what the attackers are up to, you need to dig in deeply.”

The availability of such kind of open-source tools allows experts to rapidly analyze ICS malware and implement automate defense systems.

Lipovsky and Cherepanov highlighted the importance for ICS/SCADA operators of early detection of the threats.

“A lot of people are downplaying these sorts of things as ‘not an attack.’ Spying is an attack,” said the expert. “These things are detectable.”

Lipovsky announced the tool during a session at the Black Hat hacking conference.

[adrotate banner=”9″]

Pierluigi Paganini

(Security Affairs –  (ICS malware, power outage)

[adrotate banner=”13″]