Slashdot Mirror


Western Energy Companies Under Sabotage Threat

An anonymous reader writes In a post published Monday, Symantec writes that western countries including the U.S., Spain, France, Italy, Germany, Turkey, and Poland are currently the victims of an ongoing cyberespionage campaign. The group behind the operation, called Dragonfly by Symantec, originally targeted aviation and defense companies as early as 2011, but in early 2013, they shifted their focus to energy firms. They use a variety of malware tools, including remote access trojans (RATs) and operate during Eastern European business hours. Symantec compares them to Stuxnet except that "Dragonfly appears to have a much broader focus with espionage and persistent access as its current objective with sabotage as an optional capability if required."

3 of 86 comments (clear)

  1. Dragonfly by Symantec by OzPeter · · Score: 5, Funny

    I read The group behind the operation, called Dragonfly by Symantec as that Symantec had a group called Dragonfly, and they were performing the espionage.

    And my thought processes didn't toss that out as being unreasonable.

    --
    I am Slashdot. Are you Slashdot as well?
  2. Re:No airgap? by swb · · Score: 5, Insightful

    I've done a couple of projects with engineering companies including one at a power plant. From what I've seen, the thing that tends to lead from air gapping to lack of airgapping is support.

    The engineering companies don't have the IT infrastructure experience or skills in their engineering practice. They hired me to do basic stuff like SAN setup, switch configuration, VMware, etc.

    The engineering company is required to provide support for their subsystem for a period of a couple of years and this includes everything IT related. Their office is hundreds of miles from the plant so problems with the IT environment require them to fly someone out. This is expensive, the guy who goes out has limited troubleshooting and they turn to me.

    But they don't want to pay for my services on site, so ultimately they end up ungapping the environment so it can be supported with less cost. They have some security -- VPN only and possibly other restrictions which limit VPN connectivity, but they break the air gap.

    They could maintain the air gap, but it would cost money -- support and travel costs, etc.

    Ideally the engineering company would make IT systems part of their practice, but I think a lot of engineers have an "I'm an engineer" mentality which makes them they're good at everything, so they see this as unnecessary. They could negotiate with the plant to engage their IT resources, but that would cost them money.

  3. Re:perhaps a slice of crow for the US? by flyingsquid · · Score: 5, Interesting
    It's unquestionable that the U.S. has let this thing loose; the U.S. has perhaps the most advanced cyberwarfare capabilities (at least in terms of offense) as any country on earth, having developed these weapons and techniques they can't complain too much if other countries start using them as well. However the idea is that cyberwarfare, just like conventional warfare, can and should be governed by a code of conduct. The idea would be that targets that would be considered off-limits to conventional attacks would also be off-limits to cyber-attacks. So it would be considered acceptable to attack the enemy's command-and-control network, their radars, their weapons systems, or military shipping and transport... but not to attack civilian infrastructure such as electricity, water supply, trains, banks, the stock market, etc. etc. So far, U.S. actions are consistent with this policy; we have attacked Iran's nuclear facilities but haven't tried to take down their banks or power plants, even though we probably could. You can see this policy in action where the U.S. recently accused a number of Chinese soldiers of engaging in cyberwarfare against the U.S. The issue wasn't that they engaged in cyberwarfare, which we expect the Chinese to do. It was that they were attacking civilian targets for corporate espionage, and the U.S. wanted to send a message that while they expect the military to be attacked by the Chinese, and it's a legitimate target, it's not OK to target U.S. companies.

    In the current case, it would appear that Russia doesn't accept the U.S. argument that civilian infrastructure should be off-limits. Whether the U.S. can complain here or not is debatable. The U.S. has targeted civilian infrastructure during conventional operations; they knocked out the power in Serbia during actions in Kosovo, for example. So the Russians could easily argue- and not without merit- that if it's OK to take out the power in Serbia using a stealth bomber and a conventional bomb, it ought to be OK to turn out the lights in the U.S. using a logic bomb.