Slashdot Mirror


Attackers Drain CPU Power From Water Utility Plant In Cryptojacking Attack (eweek.com)

darthcamaro writes: Apparently YouTube isn't the only site that is draining CPU power with unauthorized cryptocurrency miners. A water utility provider in Europe is literally being drained of its CPU power via an cryptojacking attack that was undetected for three weeks. eWeek reports: "At this point, Radiflow's (the security firm that discovered the cryptocurrency mining malware) investigation indicates that the cryptocurrency mining malware was likely downloaded from a malicious advertising site. As such, the theory that Radiflow CTO Yehonatan Kfir has is that an operator at the water utility was able to open a web browser and clicked on an advertising link that led the mining code being installed on the system. The actual system that first got infected is what is known as a Human Machine Interface (HMI) to the SCADA network and it was running the Microsoft Windows XP operating system. Radiflow's CEO, Ilan Barda, noted that many SCADA environments still have Windows XP systems deployed as operators tend to be very slow to update their operating systems." Radiflow doesn't know how much Monero (XMR) cryptocurrency was mined by the malware, but a recent report from Cisco's Talos research group revealed that some of the top un-authorized cryptocurrency campaigns generate over a million dollars per year. The average system would generate nearly $200,000 per year.

2 of 76 comments (clear)

  1. Need for separate browsing and operations by ArtemaOne · · Score: 4, Insightful

    Come on. Don't run your operational systems on the internet, even if they need to be internet connected. Provide your employees with a separate system connected outside the LAN so that such issues are isolated. Another solution in non-sensitive areas is simply giving them Wi-Fi and access to their phones. All of these solutions present fewer problems than having employees on the operational system infecting the operational network.

  2. Stop connecting SCADA stuff to Windows! by Gravis+Zero · · Score: 1, Insightful

    Seriously, stop connecting SCADA systems to computers running Windows. It really doesn't matter what you connect it to as long as it's not running an operating system that is well known for being vulnerable to attack!

    --
    Anons need not reply. Questions end with a question mark.