ZeroHour
CyberScooppublished ()ingested @snlyngaas

Botnet traced to computer at hacked Florida water plant

criticalMalware exploited in the wildimportance 60
Full article885 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Two very different types of hackers can be on the same network simultaneously, with the victim none the wiser.

water treatment plant
(Getty Images)

On Feb. 5, an unidentified hacker broke into the computer system of a water treatment plant in the Florida town of Oldsmar and temporarily changed the plant’s sodium hydroxide setting to a potentially dangerous level, according to local officials. It turns out that hacker wasn’t alone on the network.

While law enforcement officials still haven’t publicly identified the perpetrator of the well-publicized hack, industrial security firm Dragos on Tuesday revealed a separate suspected intrusion that same day of one of the Oldsmar Water Treatment Facility’s computers. Dragos has tied the malicious code to a botnet, or horde of infected computers used by spammers, whose code scanned the computers of local water utilities in Florida in recent months.

There is no connection between the incidents — whoever tampered with the Oldsmar facility’s chemical settings is not involved in the botnet — but the revelation shows how two very different types of hackers can be on the same network simultaneously, with the victim none the wiser.

The exposure of the Oldsmar plant’s computer to the botnet began that February morning when a plant employee visited the website of a Florida water infrastructure firm that was infected with malicious code, according to Dragos. Analysts found that, over the course of two months starting in December, over 1,000 computers belonging to municipal water utilities, employees of state and local government agencies and others visited the infected website.

“While the activity appears targeted to the water sector and is malicious it’s nothing impactful and can be considered high-level reconnaissance,” Dragos CEO Robert M. Lee told CyberScoop. “Dozens of other water companies … have been profiled by the malicious actor.” Lee said his firm went public with its findings to remind people why intelligence analysts shouldn’t jump to early conclusions based on incomplete data.

Dragos traced the malicious code to another website that they said was used to communicate with a years-old botnet known as Tofsee. The botnet is known for sending large volumes of spam to users of dating websites in order to generate cryptocurrency. Dragos analysts suspect that the hackers infected the water infrastructure firm’s website to collect user data and fine-tune the malicious software used by the botnet.

As for the attempt to tamper with the Oldsmar water supply, a plant operator reversed the change made by the hacker to the water solution before it entered Oldsmar’s drinking supply. But the incident has prompted scrutiny by U.S. lawmakers as well as calls from security experts for more cybersecurity resources for a cash-strapped water sector.

More Scoops

Arik Ashkenazi, chief engineer at the Ein Netafim wastewater treatment plant, walks between water clarifier basins at the facility in Israel’s southern Red Sea port city of Eilat on July 13, 2023. Hemmed in between the Red Sea and a desert, isolated from the rest of Israel and with no natural freshwater, Eilat’s drinking water is a combination of desalinated groundwater and sea water. After its domestic use turns it into sewage, it is treated and then allocated to farmers, enabling the arid region to support an agricultural industry. While Eilat used to be the exception in Israel’s water management, it is now more of a prototype for the country and perhaps to the world. (Photo by MENAHEM KAHANA / AFP) (Photo by MENAHEM KAHANA/AFP via Getty Images)

Dragos: Despite AI use, new malware targeting water plants is ‘hype’

ZionSiphon was designed to find and sabotage Israelis’ water supply. An OT expert said it appears to be ineffective and the work of amateurs using AI.

Attacks on industrial organizations soared by 87% last year, while the number of ransomware groups impacting the OT/ICS space jumped 60%, according to cybersecurity firm Dragos. (Image Source: Getty Images)

Dragos: Surge of new hacking groups enter ICS space as states collaborate with private actors

Group of high-voltage electric towers next to a power station. (Getty Images)

Confronted with Chinese hacking threat, industrial cybersecurity pros ask: What else is new? 

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/oldsmar-water-plant-botnet-dragos/