Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

The_jackalope

(1,660 posts)
Mon Jun 12, 2017, 01:21 PM Jun 2017

U.S. Power Companies Warned Nightmare Cyber Weapon Already Causing Blackouts

U.S. Power Companies Warned ‘Nightmare’ Cyber Weapon Already Causing Blackouts
http://www.thedailybeast.com/newly-discovered-nightmare-cyber-weapon-is-already-causing-blackouts

Seven minutes before midnight last Dec. 17, a bomb of sorts went off in a high-voltage substation north of Kiev.

But if you were standing outside the 20 acres of gleaming metal transformers and coils, you wouldn’t have heard a bang or seen a flash. It wasn’t that kind of bomb. It was a piece of malicious software that had been hiding in a control-room computer miles away, waiting for the right time to reveal itself. At 11:53 p.m., the logic bomb transmitted a staccato burst of pre-programmed commands to the substation, popping one circuit breaker after another until a strip of houses in and around western Kiev were plunged into darkness.

Technicians responded to the Pivnichna substation and took the circuit breakers off computer control, restoring power a little after 1 a.m. It was only the second confirmed case of a computer attack triggering an electrical blackout, and compared to the first, 12 months earlier—also in Ukraine—it was a fizzle, affecting far fewer customers and for a fraction of the time. In the six months since the Kiev attack, security researchers have wondered why the hackers even bothered with such a fleeting disruption and speculated that someone was using Ukraine as a testing ground for a more serious attack.

Now that dark assessment seems to be confirmed. Researchers at two security companies on Monday announced they’ve finally found and analyzed the malware that triggered the Kiev blackout, and it’s far worse than imagined. The computer code, dubbed “CrashOverride” by Maryland-based Dragos, and “Industroyer” by ESET in Slovakia, is a genuine cyber weapon that can map out a power station’s control network and, with minimal human guidance, issue malicious commands directly to critical equipment. Only once before has the world seen malware designed for such sabotage, with the 2010 Stuxnet virus used against Iran’s nuclear program. CrashOverride is the first to target civilians and the first such malware built to target a nation’s power supply.

It’s unclear who created CrashOverrride. Both ESET and Dragos say it was built from scratch, leaving none of the usual fingerprints that allow analysts to link one hacking campaign to another. Ukraine has faced a near-biblical plague of cyberattacks since entering into hostilities with Russia three years ago, and many have led unequivocally to Moscow. But not so with CrashOverride. The only thing that’s certain, says security researcher Robert Lee, CEO of Dragos, is that the malware wasn’t built as a one-time weapon. It’s designed from the ground up to be easily reconfigured for a variety of targets and contains some payloads that weren’t even fired off in the Kiev attack.

“It’s a nightmare,” Lee said. “The malware in its current state would be usable for every power plant in Europe. This is a framework designed to target other places.”

9 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
U.S. Power Companies Warned Nightmare Cyber Weapon Already Causing Blackouts (Original Post) The_jackalope Jun 2017 OP
Wonder how wide spread stuff like this is? Throck Jun 2017 #1
This is my nightmare for the US! TheDebbieDee Jun 2017 #2
I honestly believe that most Americans have no clue how tenuous our reality is. -nt CrispyQ Jun 2017 #5
And from WaPo The_jackalope Jun 2017 #3
We are horribly unprepared to deal with a massive emergency like this. -nt CrispyQ Jun 2017 #4
True. Duppers Jun 2017 #6
That claim is wildly overblown kristopher Jun 2017 #7
Like hacking our voting systems could never give us a president like Trump? The_jackalope Jun 2017 #8
That was addressed in the first and second... kristopher Jun 2017 #9
 

TheDebbieDee

(11,119 posts)
2. This is my nightmare for the US!
Mon Jun 12, 2017, 01:36 PM
Jun 2017

Our nation could be crippled in a matter of days if only 2 or 3 good-sized cities were hit with power black-outs! The potential for expanding civil unrest would devastate and end us as a nation...

The_jackalope

(1,660 posts)
3. And from WaPo
Mon Jun 12, 2017, 01:36 PM
Jun 2017
https://www.washingtonpost.com/world/national-security/russia-has-developed-a-cyber-weapon-that-can-disrupt-power-grids-according-to-new-research/2017/06/11/b91b773e-4eed-11e7-91eb-9611861a988f_story.html

Russia has developed a cyberweapon that can disrupt power grids, according to new research

Hackers allied with the Russian government have devised a cyberweapon that has the potential to be the most disruptive yet against electric systems that Americans depend on for daily life, according to U.S. researchers.

The malware, which researchers have dubbed CrashOverride, is known to have disrupted only one energy system — in Ukraine in December. In that incident, the hackers briefly shut down one-fifth of the electric power generated in Kiev.

But with modifications, it could be deployed against U.S. electric transmission and distribution systems to devastating effect, said Sergio Caltagirone, director of threat intelligence for Dragos, a cybersecurity firm that studied the malware and issued a report on Monday.

And Russian government hackers have already shown their interest in targeting U.S. energy and other utility systems, researchers said.

“It’s the culmination of over a decade of theory and attack scenarios,” Caltagirone warned. “It’s a game changer.”

kristopher

(29,798 posts)
7. That claim is wildly overblown
Mon Jun 12, 2017, 02:57 PM
Jun 2017

In the first place we are extremely cognizant of threats to our grid.
In the second we are moving with great deliberation to a much more redundant, resilient and stable grid designed around distributed renewable energy resources and island-able microgrids.
Thirdly, here is the study remark on the very limited expected effects:
"CRASHOVERRIDE could be leveraged at multiple sites simultaneously, but the scenario is not cataclysmic and would result in hours, potentially a few days, of outages, not weeks or more."

The_jackalope

(1,660 posts)
8. Like hacking our voting systems could never give us a president like Trump?
Mon Jun 12, 2017, 03:24 PM
Jun 2017

Ten years ago that might have been true. While the risk to the grid may be minimal now, dark forces never stop developing their capabilities. I'm far less copacetic about the future impacts of electronic hacks on essential systems, especially when the dark forces have already shown an interest in targeting them.

Panicking never helps, but I do think it might be a good idea to take the long-term risks seriously, and start putting in multi-layered defenses against something like this. Or we could wake up one morning to find the metaphorical equivalent of "Two Scoops Quisling the Puppet POTUS" sitting in the heart of our power grid. I'd rather that didn't happen.

Latest Discussions»Issue Forums»Environment & Energy»U.S. Power Companies Warn...