US CISA Warns Hackers are Building Arsenal to Attack Industrial Control Systems

In yet another official warning, US authorities are urging for heightened alertness and a further tightening of security measures inside critical infrastructure. In a mid-April joint cybersecurity advisory, a number of US authorities and institutions, including the FBI, NSA, Cybersecurity and Infrastructure Security Agency (CISA), and the Department of Energy, once again warned that threat actors are gearing up for attack.

Hackers targeting logic controllers

The new security advisory specifically highlighted the potential danger to a number of systems, including several industrial control systems (ICS) and supervisory control and data acquisition (SCDA) devices.

This alert is a little more specific and peculiar than a lot of those that came before it, which were focused on the banking sector or large, essential supplier networks such as fuel suppliers and food manufacturers. However, this warning is about hackers developing tools that can target programmable logic controllers or PLCs.

The alert specifically singles out several PLC manufacturers that the agencies and authorities believe will be specifically targeted. Those include controllers produced by Schneider Electric and Omron Sysmac. The list of potential targets also includes servers running Open Platform Communications Unified Architecture.

The agencies warn that advanced persistent threat actors have developed tools that can target ISC and SCDA devices, first scanning for them and later taking control. Combining this with the ability to infect engineering IT stations that run Windows and elevate access, the possible scenarios painted by the cybersecurity alert are grim.

ASRock driver bug presents dangerous exploit

The security alert goes into further detail to describe the tools believed to be in the hands of the hackers and APTs. Those tools are supposedly modular and provide easy virtual console access, allowing hackers to interface with the hardware. The malware is further described as allowing for "highly automated" exploitation of the targeted hardware.

The alert also singles out a known vulnerability with ASRock motherboards that affects a motherboard driver file named AsrDrv103.sys. Codified under CVE-2020-15368, the vulnerability allows for lateral movement and disruption of critical services. The exploit is particularly dangerous, as it allows arbitrary code execution right down to the Windows kernel level, which is a surefire way to bypass nearly all security software.

April 14, 2022
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.