The Register Home Page

back to article 'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers

Attackers are using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at water, manufacturing, energy, and other critical facilities, in what five US federal agencies on Wednesday called an “active threat.” In this latest round of intrusions against American …

  1. Claptrap314 Silver badge

    Speaking into the void...

    Of course anyone with the slightest understanding of internet security has been screaming this for decades.

    You are the feds. Start fining or shut up.

  2. amanfromMars 1 Silver badge

    Holocaust v2.0 and all too easily within Present 0day Realms of Possibility Programs/Projects

    While the joint alert ..... doesn’t attribute the threats to a particular government or criminal group, Iranian cyber operatives are suspected of being behind recent attacks targeting PLCs at water and wastewater facilities across at least 12 states, including a cyberattack that disrupted more than 30 community water systems in Minnesota in late July.

    “This appears to be a continuation of the same suite of activity we suspect is affiliated with Iran targeting PLCs,” Cynthia Kaiser, Halcyon Ransomware Research Center SVP, told The Register

    Appearances can be deceptive, perverse and subversive, and knowing what is well enough known of the crazed God's chosen few master race behaviour and computer hacking skillsets of a close Iranian neighbour and belligerent enemy, suspicion easily suggests such threats/attacks be trials and provocations of their making .... to create a corrupted reaction that continues to steer and demand an ailing and failing and bankrupted sugar daddy stay the course that leads to an increasingly more evident, self destruction.

    Muppets and puppets in the Great Game running amok and trying out hallucinations as a viable base feed for future realities. And history tells one and all how that always ends for easily led tools and leading fools alike.

    Take care out there. IT is an AI Jungle like nothing ever realised possible before, .... and therefore a very likely highly probable sure fire racing certainty.

    And ..... way beyond all human means and memes of native solo or collective conspiratorial command and control .... so, something completely novel and ideally surprisingly rather than terrifyingly different and fully commensurate for such as be long overdue ... a Worlds Worthy Change.

    And ..... just so that no one cannot plead ignorance to the fact in order to try to escape accountability for one's guilt in thoroughly unpleasant and unnecessary matters, y'all might like to think, accept and realise your actions and reactions responding to emerging freely shared news and remarkable views are directly responsible for the future different choice being surprising and good, or terrifying and bad.

  3. frankyunderwood123 Silver badge

    take them offline FFS!

    who the heck thought it a good idea to put parts of critical infrastructure online?

    I can only imagine it had something to do with cost cutting and convenience - no need for on premises monitoring.

    The solution is obvious but now probably prohibitively expensive. A completely closed wired network. Some monitoring could still be done via the internet with careful system design, but that’s it. Just read only data.

    1. big_D
      Facepalm

      Re: take them offline FFS!

      Who in their right mind puts a PLC on the Internet?

      1. ecofeco Silver badge
        Mushroom

        Re: take them offline FFS!

        Nepo-fail-baby-trustafarians rule the world these days.

        And they are inbreeding. Both genetically and corporate.

        I'm sure it will end well. Just look at history!

        Oh wait. Oh fuck.

    2. You aint sin me, roit Silver badge

      Re: take them offline FFS!

      Profitability.

      It's an easy, lazy solution. Full of security holes, but who cares about that as long as it is cheap?

    3. Rattus

      Re: take them offline FFS!

      How else do you remotely manage a fleet of unmanned locations?

      I would hope that these satellite sites are behind a firewall with only VPN traffic back to the appropriate management 'hub', permitted (no open internet access)

      Of cause as soon as the company LAN is compromised then all devices at your satellite sites are wide open too.

      IT departments may update devices they manage (routers, servers, desktop PCs etc) but lots of other devices get put on company networks which are out of the IT departments control.

      PLCs are but one...

      We all have had to add security to everything with network access - this wasn't something even considered a few years ago, and it has come to applications on servers, and desktop devices, switches and routers, and has arrived on modern embedded systems. However such embedded infrastructure devices are long lived, and may not yet, been replaced with something even vaguely security capable.

      IT & security managers only have so much budget, this sort of infrastructure is was often considered a lower risk of attack... but once the big ticket items became more secure the attackers move to more low hanging fruit. Yes I agree that this *should* have been considered from the very start as critical - but then that is true for everything else connected to the internet, mail severs, databases, cloud storage etc. and look how often they are compromised.

      1. BartyFartsLast Silver badge

        Re: take them offline FFS!

        FML, you monitor them over a leased line, a phone line or some other private connection, these are critical infrastructure and it's worth the money to ensure they stay secure.

        But obviously it costs money and eats into profits when the whole purpose of private business is to squeeze costs to the absolute minimum whilst extracting the maximum amount of profit.

        So, a much as I hate legislation, this is one instance where it should be mandated that such CNI has to be on private networks, totally isolated from the internet

        1. This post has been deleted by its author

        2. Rattus

          Re: take them offline FFS!

          Leased line or VPN, its all the same.... once connected back to the head office LAN

          VPN is still an attack vector. But given how secure most Telco networks are so is a leased line :-(

      2. frankyunderwood123 Silver badge

        Re: take them offline FFS!

        How else do you remotely manage a fleet of unmanned locations?

        You don’t leave them unmanned.

        They were managing just fine before the internet.

        This is critical national infrastructure, the budget has to be found to ensure resilience.

      3. Anonymous Coward
        Anonymous Coward

        Re: take them offline FFS!

        You can use encryption over VPNs to up the security (VPN = IL2, VPN+encryption = IL3)

    4. BartyFartsLast Silver badge

      Re: take them offline FFS!

      Exactly this, there's some numpty in the comments on a similar article suggested hiding it all behind a Raspberry Pi.

      Private circuits should beamdared, with encryption and authentication but still, private circuits.

      Sure, they're expensive but nowhere near as expensive as a breach.

  4. david 12 Silver badge

    memory, configuration data, and ladder logic programs

    These are industrial computers with full network stacks. They can be given "ladder logic programs", but that's the least of their capabilities.

    1. Will Godfrey Silver badge
      Mushroom

      Re: memory, configuration data, and ladder logic programs

      Nooo. Not that god-awful ladder logic. I couldn't get away from it fast enough.

  5. Filippo Silver badge

    Okay. Does this mean that factories are going to start hiring competent network engineers, instead of having the local electrician get another 15$ hub from Amazon and put everything on the same subnet?

    Are they going to set up a proper update procedure for critical systems, instead of running automation-facing software on a box that's never been patched, ever, because stopping production for 10 minutes is unacceptable?

    Oh, and are automation companies going to stop selling software that only runs on Windows 7 with administrator rights? Will they stop saying that the Windows 11 version is only compatible with the newest machinery, so you can't have it unless you upgrade the entire production line for 300K?

    No, not until inspectors start looking for this crap and handing fines.

    1. cyberdemon Silver badge
      Windows

      Windows Embedded

      Oxymoron of the century

      25 years since "Win XP Embedded" poisoned the world's automation systems, and it still can't run without a framebuffer, or persistent, writeable storage (they have a kludge which can make writes to certain files/directories non-persistent i.e. will revert on next reboot, but it still can't boot from 100% read-only media). And SCADA vendors still encourage the use of VNC to administer their logic controllers.

      1. just4this Bronze badge

        Re: Windows Embedded

        Oxymoron is the Oxymoron of the century.

        A sharp dull thing.

  6. Mike 125

    > “If data only needs to leave an OT network, use a data diode,” he said.

    I like it. I like it. Simplicity and common sense.

    1. Pete 2 Silver badge

      > use a data diode

      Even diodes leak current.

      1. You aint sin me, roit Silver badge

        Might get a bit hot, but...

        Go old-fashioned, use a data valve!

    2. Rattus

      nope needs to be bidirectional.... these are command and control networks as well as monitoring nodes

      You need to be able to open and control 'valves', turn on and off pumps etc.

  7. Pete 2 Silver badge

    Ostrich management

    > internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at water, manufacturing, energy, and other critical facilities

    Everybody with more than the vaguest notions about the internet and/or computer security has known that exposing critical infrastructure is a very bad idea. Yet decision makers continue to deny the possibility that vulnerabilities (of any sort) need to be removed.

    The problem with such a "head in the sand¹" approach is that sooner or later someone will use you as a bike stand

    [1] Yes, I know

    1. Anonymous Coward
      Anonymous Coward

      Re: Ostrich management

      I usually say when your head is in the sand your arse is in the air......are you sure about that?

  8. Anonymous Coward
    Anonymous Coward

    We've known this since the mid-1990s. I place all of the blame on personnel, humarn resources, whatever they're called these days. You should be hiring network administrators who are cynical bastards. We don't trust application developers or process control engineers when it comes to our networks, what so ever. That's not to say we don't like or respect them. Some of them would be in the running for the title of Smartest Person in the room, even if that room was The Superdome. However, just because they have multiple PhD's in chemistry or mechanical engineering on their wall, doesn't mean they understand anything about network security.

    If you're in network security, and you don't upset important people on a regular basis, either you and your management aren't doing your jobs well enought, or you and your management are doing your jobs very well.

    1. cyberdemon Silver badge
      Devil

      humarn resources, whatever they're called these days

      That would be Human Remains

      Anyone who works in HR starts out as a bright-eyed, bushy-tailed fluffy bunny rabbit that loves hiring people and helping them in their careers, and quickly turns into a soulless hollowed-out husk as corporate reality bites.

      As one cynical HR droid told me: "The role of HR is to protect the organisation from its employees." Unfortunately that often means firing / not hiring anyone with a clue, lest they embarass the executive management.

    2. Cav

      "I place all of the blame on personnel, humarn resources, whatever they're called these days. "

      HR - "a decent network engineer costs $xK"

      Bean counters - "Here's a dollar and some change"...

  9. steviebuk Silver badge

    Pointless

    until agent orange and all the GOP are out of office. Because we already know they have a corrupt FBI and the other agencies currently aren't any better, all because they are run by agent orange jackboots.

  10. VoiceOfTruth Silver badge

    I give two Fs to America

    Shucks. They illegally bombed Iran, murdering how many?

    Now I'm supposed to care two eurocents when there's a bit of payback?

    Clue to the USA: Stop bombing whoever you feel like.

    1. Lon24 Silver badge

      Re: I give two Fs to America

      Except disasters tend to hit the vulnerable hardest while the comfortable plutocrats will blame it on another lot.

      More than half of America did not vote this administration in. Telling them 'I told you so and stuff you' is unhelpful as many of them have been saying that since 2016. Resistance is futile is the administration's playbook. Only the brave might question that. Most will hope democracy corrects itself. To even have doubts it will is truly shocking but the alternative is too horrible to contemplate.

  11. ecofeco Silver badge
    Mushroom

    WHOCOULDAKNOWED?!

    Oh wait. Everyone without recto-cranial-inversion knew.

  12. Anonymous Coward
    Anonymous Coward

    Again a new acronym?

    OT? What happened to SCADA?

    Just curious and yes, the security profession has been warning for decades now that it is a monumentally BAD to hang things raw off the Net - I'd call all of this negligence coming home to roost..

  13. andy the pessimist Bronze badge

    enforcement?

    The FBI say to do some thing and say it's bad.

    If the accountants/management don't say do this work to IT what happens?

    I would expect IT to do the prep work. Taking external access down needs approval.

    If the acces isn't revoked what happens do the FBI visit, local police visit? Is there a law that says do this?

  14. just4this Bronze badge

    Not a theoretical

    https://www.bbc.co.uk/news/articles/ce9793g34yvo

    Iran-linked hackers behind cyber attack that shut down power plant, reports say

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon