Or not (yet)?
After all the WannaCry variants and other new attempts to hold computer users and companies around the world to ransom, a new piece of malware has emerged. Its target is not the computer user, the business server or even the mobile user. Instead, hackers are targeting the IT infrastructure behind electricity grids and other utilities.
This is not news in itself. Reports of successful and less successful infiltrations of the IT behind energy supplies have circulated for years. Some have even had a 'positive' angle, such as the Stuxnet worm infections designed by the United States and Israel, which damaged Iranian nuclear installations and kept them out of operation in 2010. In general, however, the intentions are less benign.
The name might sound as though it comes from a Star Wars episode, but Industroyer really does target the destruction or manipulation of industrial automation. It is a flexible form of malware that can be developed further very easily and affect different types of industrial control systems. Researchers say Industroyer is dangerous and could become much more so because it uses the original communication protocols developed decades ago for industrial environments. As security was less of a priority then, these protocols lack security features, allowing the malware to use them easily.
In its current form, Industroyer threatens electricity substations and switching equipment. The malware can control switches and power distribution equipment in ways that not only shut down particular functions but also directly affect all the systems behind them. The resulting domino effect can have major industrial, business-critical and economic consequences.
It is not known whether Industroyer is or has been successful, but the risk is credible and substantial. Industrial systems are updated and upgraded differently and do not always use the latest technologies. This version appears to have been developed with clear knowledge of that world and includes several alternatives should a particular component be discovered or protected. Industroyer is therefore flexible enough to gain access deep inside critical systems.
As we look ahead to widespread use of the Internet of Things (IoT), with a wide variety of simple internet-connected systems collecting and sending information, we must recognise that security needs to be a crucial, inseparable part of every automated system, however simple or complex.
More information from ESET is available here: ESET discovers dangerous malware designed to disrupt industrial control systems
