Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

ABTV //

Malware

10/18/2018
11:05 AM
Scott Ferguson
Scott Ferguson
News Analysis-Security Now
50%
50%

GreyEnergy Group Tied to Power Plant Attacks in Ukraine & Poland

Research from ESET has uncovered a new group called GreyEnergy, which appears to have targeted power plants in the Ukraine and Poland. The malware has also been linked to a previous group dubbed BlackEnergy.

A new threat group called GreyEnergy has been targeted power plants and other critical infrastructure in the Ukraine and Poland over the last three years, and the malware used in these attacks has been linked to a previous malicious actor dubbed BlackEnergy.

In addition, the new research from ESET has found similarities between GreyEnergy and Telebots, the group that is believed responsible for the NotPetya ransomware attacks that targeted Ukraine last year, causing wide-spread havoc. (See UK Accuses Russia of Launching NotPetya Attacks.)

The new research is quick to note that it cannot tie all these different attacks to same Advanced Persistent Threat (APT) group or nation-state, but there are specific links between all three including "code similarities, shared C&C infrastructure, malware execution chains, and so on."

It appears that GreyEnergy has been operating in stealth mode for at least three years, and has been carefully targeting critical infrastructure and facilities in Eastern Europe. ESET researchers believes that the malware behind the group is being used specifically for reconnaissance and espionage, including backdoor, file extraction, taking screenshots, keylogging, as well as password and credential stealing.

It's possible that group behind GreyEnergy was conducting research in anticipation of a cyberattack.

The research also found that GreyEnergy does not specifically target Industrial Control Systems (ICS). Instead, the malware focuses on workstations that handle supervisory control and data acquisition (SCADA) systems, which control the critical infrastructure of power plants.(See Industrial Manufacturing Sector Increasingly Susceptible to Cyber Attacks.)

In order to enter these systems, GreyEnergy uses either traditional spearphishing techniques, or it will look for a compromised, public-facing web server. Once inside, the attackers attempt to move laterally from one workstation to the next.

The group also uses some publicly available tools such as Mimikatz, PsExec, WinExe and Nmap as part of its attack.

However, it's the tied between GreyEnergy and BlackEnergy that are the most troubling.

Before disappearing, BlackEnergy conducted an attack against a power plant in the Ukraine that left 230,000 people in the dark. As soon as BlackEnergy vanished, GreyEnergy appeared.

The October 17 ESET research note finds that BlackEnergy and GreyEnergy have zeroed in on similar targets. Besides these shared victims, ESET notes that the malware and techniques used by both groups are similar:

Compared to BlackEnergy, GreyEnergy is a more modern toolkit with an even greater focus on stealth. One basic stealth technique -- employed by both families -- is to push only selected modules to selected targets, and only when needed. On top of that, some GreyEnergy modules are partially encrypted using AES-256 and some remain fileless -- running only in memory -- with the intention of hindering analysis and detection. To cover their tracks, typically, GreyEnergy's operators securely wipe the malware components from the victims' hard drives.

Additionally, BlackEnergy and GreyEnergy each use active Tor relays to connect back to their command-and-control servers, which helps unsure a level of stealth.

During the early part of its investigation, ESET researcher noticed that in December 2016, GreyEnery used an early version of the TeleBots' NotPetya worm. This was about six months before it as altered and used in the 2017 ransomware attack against Ukrainian businesses and other organizations.

These types of attacks against critical infrastructure, as well as the ICS and SCADA systems that help run these facilities, need to serve as a wake-up call, according to Bob Huber, the chief security officer at cybersecurity firm Tenable. He noted that all these types of attacks show how vulnerable some facilities are to groups that are willing to spend the time and effort to plan out these operations.

"Since the blackout in Ukraine in December 2015, and likely long before that, advanced adversaries have been stealthily targeting critical infrastructure around the world, learning more and more about the mission-critical systems as they go. Each new event is a canary in the coal mine that we cannot downgrade to isolated incidents," Huber wrote in an email. "Persistent threats like this one underscore the importance of holistic visibility across IT and OT assets. Blind spots are where advanced adversaries live. Shining a light on those areas is key to stopping an attack in its track."

Related posts:

— Scott Ferguson is the managing editor of Light Reading and the editor of Security Now. Follow him on Twitter @sferguson_LR.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Manchester United Suffers Cyberattack
Dark Reading Staff 11/23/2020
As 'Anywhere Work' Evolves, Security Will Be Key Challenge
Robert Lemos, Contributing Writer,  11/23/2020
Cloud Security Startup Lightspin Emerges From Stealth
Kelly Sheridan, Staff Editor, Dark Reading,  11/24/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-20934
PUBLISHED: 2020-11-28
An issue was discovered in the Linux kernel before 5.2.6. On NUMA systems, the Linux fair scheduler has a use-after-free in show_numa_stats() because NUMA fault statistics are inappropriately freed, aka CID-16d51a590a8c.
CVE-2020-29368
PUBLISHED: 2020-11-28
An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write implementation can grant unintended write access because of a race condition in a THP mapcount check, aka CID-c444eb564fb1.
CVE-2020-29369
PUBLISHED: 2020-11-28
An issue was discovered in mm/mmap.c in the Linux kernel before 5.7.11. There is a race condition between certain expand functions (expand_downwards and expand_upwards) and page-table free operations from an munmap call, aka CID-246c320a8cfe.
CVE-2020-29370
PUBLISHED: 2020-11-28
An issue was discovered in kmem_cache_alloc_bulk in mm/slub.c in the Linux kernel before 5.5.11. The slowpath lacks the required TID increment, aka CID-fd4d9c7d0c71.
CVE-2020-29371
PUBLISHED: 2020-11-28
An issue was discovered in romfs_dev_read in fs/romfs/storage.c in the Linux kernel before 5.8.4. Uninitialized memory leaks to userspace, aka CID-bcf85fcedfdd.