Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

ABTV //

Malware

10/18/2018
11:05 AM
Scott Ferguson
Scott Ferguson
News Analysis-Security Now
50%
50%

GreyEnergy Group Tied to Power Plant Attacks in Ukraine & Poland

Research from ESET has uncovered a new group called GreyEnergy, which appears to have targeted power plants in the Ukraine and Poland. The malware has also been linked to a previous group dubbed BlackEnergy.

A new threat group called GreyEnergy has been targeted power plants and other critical infrastructure in the Ukraine and Poland over the last three years, and the malware used in these attacks has been linked to a previous malicious actor dubbed BlackEnergy.

In addition, the new research from ESET has found similarities between GreyEnergy and Telebots, the group that is believed responsible for the NotPetya ransomware attacks that targeted Ukraine last year, causing wide-spread havoc. (See UK Accuses Russia of Launching NotPetya Attacks.)

The new research is quick to note that it cannot tie all these different attacks to same Advanced Persistent Threat (APT) group or nation-state, but there are specific links between all three including "code similarities, shared C&C infrastructure, malware execution chains, and so on."

(Source: iStock)
(Source: iStock)

It appears that GreyEnergy has been operating in stealth mode for at least three years, and has been carefully targeting critical infrastructure and facilities in Eastern Europe. ESET researchers believes that the malware behind the group is being used specifically for reconnaissance and espionage, including backdoor, file extraction, taking screenshots, keylogging, as well as password and credential stealing.

It's possible that group behind GreyEnergy was conducting research in anticipation of a cyberattack.

The research also found that GreyEnergy does not specifically target Industrial Control Systems (ICS). Instead, the malware focuses on workstations that handle supervisory control and data acquisition (SCADA) systems, which control the critical infrastructure of power plants.(See Industrial Manufacturing Sector Increasingly Susceptible to Cyber Attacks.)

In order to enter these systems, GreyEnergy uses either traditional spearphishing techniques, or it will look for a compromised, public-facing web server. Once inside, the attackers attempt to move laterally from one workstation to the next.

The group also uses some publicly available tools such as Mimikatz, PsExec, WinExe and Nmap as part of its attack.

However, it's the tied between GreyEnergy and BlackEnergy that are the most troubling.

Before disappearing, BlackEnergy conducted an attack against a power plant in the Ukraine that left 230,000 people in the dark. As soon as BlackEnergy vanished, GreyEnergy appeared.

The October 17 ESET research note finds that BlackEnergy and GreyEnergy have zeroed in on similar targets. Besides these shared victims, ESET notes that the malware and techniques used by both groups are similar:

Compared to BlackEnergy, GreyEnergy is a more modern toolkit with an even greater focus on stealth. One basic stealth technique -- employed by both families -- is to push only selected modules to selected targets, and only when needed. On top of that, some GreyEnergy modules are partially encrypted using AES-256 and some remain fileless -- running only in memory -- with the intention of hindering analysis and detection. To cover their tracks, typically, GreyEnergy's operators securely wipe the malware components from the victims' hard drives.

Additionally, BlackEnergy and GreyEnergy each use active Tor relays to connect back to their command-and-control servers, which helps unsure a level of stealth.

During the early part of its investigation, ESET researcher noticed that in December 2016, GreyEnery used an early version of the TeleBots' NotPetya worm. This was about six months before it as altered and used in the 2017 ransomware attack against Ukrainian businesses and other organizations.

These types of attacks against critical infrastructure, as well as the ICS and SCADA systems that help run these facilities, need to serve as a wake-up call, according to Bob Huber, the chief security officer at cybersecurity firm Tenable. He noted that all these types of attacks show how vulnerable some facilities are to groups that are willing to spend the time and effort to plan out these operations.

"Since the blackout in Ukraine in December 2015, and likely long before that, advanced adversaries have been stealthily targeting critical infrastructure around the world, learning more and more about the mission-critical systems as they go. Each new event is a canary in the coal mine that we cannot downgrade to isolated incidents," Huber wrote in an email. "Persistent threats like this one underscore the importance of holistic visibility across IT and OT assets. Blind spots are where advanced adversaries live. Shining a light on those areas is key to stopping an attack in its track."

Related posts:

— Scott Ferguson is the managing editor of Light Reading and the editor of Security Now. Follow him on Twitter @sferguson_LR.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Enterprises are Attacking the Cybersecurity Problem
Concerns over supply chain vulnerabilities and attack visibility drove some significant changes in enterprise cybersecurity strategies over the past year. Dark Reading's 2021 Strategic Security Survey showed that many organizations are staying the course regarding the use of a mix of attack prevention and threat detection technologies and practices for dealing with cyber threats.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-34760
PUBLISHED: 2021-10-21
A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient input validation by the ...
CVE-2021-34789
PUBLISHED: 2021-10-21
A vulnerability in the web-based management interface of Cisco Tetration could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack on an affected system. This vulnerability exists because the web-based management interface does not sufficiently validate user...
CVE-2021-39126
PUBLISHED: 2021-10-21
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify various resources via a Cross-Site Request Forgery (CSRF) vulnerability, following an Information Disclosure vulnerability in the referrer headers which discloses a user's CSRF token. The affected versions ar...
CVE-2021-39127
PUBLISHED: 2021-10-21
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to the query component JQL endpoint via a Broken Access Control vulnerability (BAC) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.1.
CVE-2021-40121
PUBLISHED: 2021-10-21
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. For more information about these vulnerabilities, see the Details section of this ad...