The group behind Trisis has expanded its targeting to the U.S. electric sector
Full article878 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
ICS security firm Dragos has briefed over 20 utilities on the new activity.
The notorious hacking group behind the Trisis malware, which is designed to disrupt industrial safety systems, has expanded its targeting to include U.S. electric utilities, according to new research.
The group, known as Xenotime, most famously deployed the Trisis malware on a Saudi petrochemical plant in the summer of 2017, forcing it to shut down. But starting in late 2018, according to analysts at industrial cybersecurity company Dragos, Xenotime went beyond its focus on oil and gas sector to probe the networks of electric utilities in the U.S. and elsewhere.
“While there is no evidence at this time that Xenotime has successfully breached any of the entities it has probed in U.S. electric utilities, the fact that this actor – which has already demonstrated the willingness and capability to execute a disruptive ICS [industrial control system] attack – is now actively gathering information on electric utilities is deeply concerning,” Joe Slowik, an adversary hunter at Dragos, told CyberScoop.
The recent Xenotime activity against American electric utilities includes gathering open-source information, scanning networks and “likely probing for vulnerable, external-facing services,” Slowik said. “While very early in the intrusion lifecycle, these all represent necessary prerequisites for follow-on intrusion attempts and are precursors to further activity.”
The recent activity did not include deploying the actual Trisis malware, a sophisticated package of code that had the security world spooked when it first surfaced.
Slowik said Dragos had briefed over 20 utilities on the new Xenotime activity. Most of them are in the United States but some are in the Asia-Pacific region, where activity from Xenotime was detected starting in late 2018. In May 2018, CyberScoop reported that Xenotime had expanded its operations to include targeting U.S. industrial firms. That activity covered the oil and gas sector, whereas the more recent probing from Xenotime has been of electric utilities. Dragos detected the new activity earlier this year and discovered it stretched back to mid-2018, Slowik said.
In research on Xenotime published Friday, Dragos pointed out that the field of hackers targeting ICS, once confined to a few groups because of the heavy investments in tooling required, has expanded significantly in recent years.
“[A]s more players see value and interest in targeting critical infrastructure – and those already invested see dividends from their behaviors – the threat landscape grows,” the company said in a blog post.
E&E News was first to report on the new Xenotime activity.
More Scoops
Dragos: Despite AI use, new malware targeting water plants is ‘hype’
ZionSiphon was designed to find and sabotage Israelis’ water supply. An OT expert said it appears to be ineffective and the work of amateurs using AI.
After major Poland energy grid cyberattack, CISA issues warning to U.S. audience
Dragos: Surge of new hacking groups enter ICS space as states collaborate with private actors
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/trisis-xenotime-us-electric-sector/