IOTW: Ukraine thwarts Russian cyber-attack on power grid

Russian cyber-criminal group Sandworm is believed to be responsible for the attack

Add bookmark
Ukraine thwarts Russian cyber-attack on power grid

Ukraine’s Governmental Computer Emergency Response Team of Ukraine (CERT-UA) confirmed on 12 April that it had taken urgent measures in response to a security incident related to a targeted cyber attack on Ukraine’s energy facilities.

The victim organization has not been disclosed by CERT-UA.

Since the start of the Russian invasion of Ukraine in late February 2022 it has been expected that Russia would use cyber-attacks as part of its campaign, with critical infrastructure a valuable target.

The attack involved the decommissioning of several infrastructural elements of the target of the attack. These included high-voltage electrical substations.

The incident occurred in two phases with the first compromising power networks in February before moving on to shut a substation and harm infrastructure on 8 April – a plan that was ultimately foiled.

New malware

In a statement, CERT-UA said the attack was carried out by the Sandworm group using malware including Industroyer2 and CaddyWiper.

Industroyer malware was used in an attack against Ukraine’s power grid in 2016, which caused a power blackout in Kiev. According to cyber security firm ESET, Industroyer2 is a new variant of the malware deployed during the 2016 incident.

ESET has worked closely with CERT-UA to remediate and protect the critical infrastructure network.

The company explained that alongside Industroyer2, Sandworm used several destructive malware families including CaddyWiper, Orcshred, Soloshred and Awfulshred.

CaddyWiper was first discovered in 2014 when it was used against a Ukrainian bank.

Become a Cyber Security Hub member and gain exclusive access to our upcoming digital events, industry reports and expert webinars

“Ukraine is once again at the center of cyberattacks targeting its critical infrastructure,” said ESET in an article on 12 April. “This new Industroyer campaign follows multiple waves of wipers that have been targeting various sectors in Ukraine. ESET researchers will continue to monitor the threat landscape in order to better protect organizations from these types of destructive attacks.”

It is understood that Microsoft has also played a part in identifying and mitigating cyber-attacks in Ukraine.

Putin’s cyber army

It is well known now that cyber-attacks are part of Vladimir Putin’s arsenal of weaponry.

Speaking to CS Hub earlier in 2022, Charles Denyer, an Austin-based cybersecurity and national security expert, said, “Putin is throwing digital bombs from his doorsteps, courtesy of Russia’s vast cybersecurity arsenal.”

Regarding who is behind the attacks that are hitting the Ukraine, and possibly the rest of the world, Denyer explained that Russia’s Foreign Intelligence Service of the Russian Federation (SVR), the Main Directorate of the General Staff (GRU), the Federal Security Service (FSB), the Federal Protective Service (FSO), the GRU’s cyber military Unit 26165, Unit 74455 (more commonly known as Sandworm), the Internet Research Agency and others are all involved.

For organizations throughout the globe, protecting their assets comes back to basic cyber hygiene 101, Denyer explained. This includes limiting access to systems, running anti-virus scans, monitoring all user activity, scanning for network vulnerabilities, performing penetration testing and, in the long term, training employees on security awareness issues.


Recommended

info@cshub.com/r/n

We hope you enjoy All Access from CS Hub!!<\/p>\r\n<p>Best Regards,<\/p>\r\n<p><a href=https://www.cshub.com/"https:////www.cshub.com///" target=\"_blank\">CS Hub Team<\/a><\/p>\r\n<p>P.S. Be sure to check out our other upcoming <a href=https://www.cshub.com/"https:////www.cshub.com//events?filter_format=ONLINE\%22 target=\"_blank\">All Access events here<\/a>.<\/p>\r\n<p>--------------------------------<\/p>\r\nConnect with us on Social Media: <a href=https://www.cshub.com/"https:////www.linkedin.com//groups//12067996///" target=\"_blank\">LinkedIn<\/a> | <a href=https://www.cshub.com/"https:////twitter.com//CSHubUSA/" target=\"_blank\">Twitter<\/a><\/p>\r\n<p>--------------------------------<\/p>\r\n<p>FAQS<\/p>\r\n<p><b>Can I invite my colleagues?<\/b><br>Yes of course! Please send them this link so they can register for free! [WebUrl]<\/p>\r\n\r\n<p><b>How do I access the sessions?<\/b><br>\r\nAll Access is run on Zoom Events. You should receive an email shortly from Zoom Events with your unique All Access link to the event lobby. Please hold on to that email ahead of the event. We\u2019ll also send you a reminder 24 hours before we go live!<\/p>\r\n\r\n<p><b>Will the agenda be updated?<\/b><br>\r\nYes, the agenda will be continuously updated on the website with the latest sessions & speakers. As we get closer to the event, also look out for our weekly updates which will also include the latest updates information and link to access the event.<\/p>\r\n<p><b>Can I access the sessions On Demand?<\/b><br>\r\nEvery session will be available after the event via the event lobby. We\u2019ll also send you a reminder about the On Demand sessions which will be sent to you after the event is over.<\/p>\r\n<p>--------------------------------<\/p>\r\n<p>RELATED RESOURCES TO READ BEFORE YOUR EVENT<\/p>\r\n<ul>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//executive-decisions//reports//cs-hub-mid-year-market-report-2022?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CS Hub Mid-Year Market Report 2022<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//ciso-strategies-for-proactive-threat-prevention?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CISO strategies for proactive threat prevention<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//how-to-strengthen-email-security-and-protection-against-advanced-ransomware-attacks?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">How to strengthen email security and protection against advanced ransomware attacks<\/a><\/li>\r\n<\/ul>","event_registration_srs_confirmation_email":null,"assets_from_cdn":true},"bant_disabled":0,"sponsorship_disclaimer":null,"sponsorship_disclaimer_text":null,"sponsorship_disclaimer_checkbox_disabled":0,"ext_treat_id":null,"recording_url":null,"file_attachment":null,"ingo_enabled":null,"ingo_activator_id":null,"ingo_autofiller_id":null,"ingo_amplifier_id":null,"ingo_authorizer_id":null,"restricted_content":0,"featured_events_embedded":[],"featured_content_embedded":[],"featured_content_portal_embedded":null}" >