Remote access exploit
Using the credentials of authorized users, the adversaries tunneled into the ICS/SCADA network using VPNs, bypassing the firewalls. The adversaries' next step was to take control of the operators' workstations and to lock the operators out of their systems. It was a crucial stage of the attack before the attackers could remotely operate the HMIs to trigger power outages in at least, 27 substations. While the attack was in progress, the attackers remotely injected KillDisk malware across the entire environment. KillDisk rendered the Windows systems inoperable by corrupting the master boot record, affecting the boot integrity. On other systems, it deleted log and system event files (this further emphasizes the rationale ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access