Russian spies from APT29 responded to Western agencies outing their tactics by adopting a red-teaming tool to blend into targets' networks as a legitimate pentesting exercise. Now, the UK's National Cyber Security Centre (NCSC) and the US warn, the SVR is busy exploiting a dozen critical-rated vulns (including RCEs) in …

  1. thejynxed

    I've said this for three decades now - connecting any utility or related infrastructure to the general publicly accessible internet is always a (very stupid) mistake and should be regulated against.

    Russia was probing connected oil refineries and traffic systems in the 1980's and I can imagine since then so have plenty of bored teenagers.

    3. Anonymous Coward
      Anonymous Coward

      If only it were that simple to put it all offline. Virtually everything and it's dog insists on being internet connected to register or update. Firmware updates via serial lead need a regular laptop attached to deliver the update. Cue, vulnerability. Outputs of control systems and measures have to be broadcast somehow (typically a serial.comms format) and interference is possible in between).

      I have in the wild seen malware modulating the CPU fan speed to send audio signals to microphones on less secure hardware, so airgapping is not a defence against stealing data.

      Microcontrollers aren't going away in utility environments, but securing the Comms loop is an incredibly difficult challenge. Imagine if you own 500 installations all over the UK, all built to different standards that applied on that given day, and you aren't funded by the public to refresh all that equipment regularly.

      There is something to be said for electromechanical relays manned by staff, but then you have the permanent staffing overhead instead. Counter to the never ending cost challenges posed by Ofwat, Ofgem and other such bodies.

      A/C because obviously, I have some knowledge of such environments. I will reiterate that the funding to do what is necessary isn't strictly there. someone determined, probably could get in, eventually.

      See Black Energy in the Ukraine for examples.

    4. Eclectic Man Silver badge


  2. Eclectic Man Silver badge

    Covert pen testers

    "... the SVR is also posing as legitimate red-team pentesters ..."

    On one bid, the HMG Agency client insisted (and I mean insisted) that their IT people should have the right to conduct unannounced technical security testing on the supplier's network management system (which was used to support other clients) including DoS attacks.

    I refused point blank. I pointed out that this would provide an attack vector for a subverted IT person in their team to probe defences. If caught (s)he would claim it was an unannounced pen test, and still gain valuable information. I further pointed out that if while monitoring their network, it appeared to be under attack from something like, Melissa, or 'The Love Bug', the appropriate action to protect the network might just be to turn it all off, without notice. And whilst the sales team really wanted to comply with the client's repeated insistence on this (they were motivated by a 'win bonus', I think), they were somewhat unwilling to insert a contract clause that the client would indemnify us, the supplier, against any adverse effects the client's 'unannounced technical security testing' had on their own and other clients' networks supported from the same service desk. The sales team were similarly unwilling to inform other existing clients that their service desk would suddenly be contractually attackable by a new client (probably without compensation).

    Other issues, of course, include whether we could have obtained relief from SLAs had there been an attack by them, and the service had fallen below required levels, if we couldn't prove it was the client, rather than a failing on our part. And of course, selling a service one client has the contractual right to attack without notice to other clients would be an 'interesting' legal challenge.

    Eventually, after much effort, I did get my way (the clause giving them unannounced pen testing rights was deleted). But of all the BONE-HEADED, IDIOTIC and DOWNRIGHT STUPID things to ask for, this one has got to take the biscuit, in my experience. I don't think any of them worked for the SVR, or whatever they were calling themselves then, but it would have made sense.

    Anyone beat that?

    "D'oh" icon for idiocy, I wanted to include the explosion and the FAIL icons too, but you're only allowed one per post, it seems :o(

  3. mark l 2 Silver badge

    But the thing is while the US and UK might have outed the techniques the Russians were doing, I have no doubt the 5 eyes countries are doing the same back to Russia, China etc. Heck we know from the Snowden leaks the US were spying on their allies such as Germany. And what makes you think they have stopped now?

    1. Pascal Monett Silver badge

      Re: "what makes you think they have stopped now?"

      Nobody but the NSA is saying that they've stopped.

      Repeatedly, each time they're caught doing it.

      1. Eclectic Man Silver badge

        Re: "what makes you think they have stopped now?"

        It is like smoking or alcohol: giving up is easy, the trick is not starting again.

    2. Danny Boyd

      I surely hope they didn't stop. Spies spy. It's in their job description. Every country worth mentioning has external intelligence service, and this country better make sure the service is functional.

      By the same token, every country has counter-intelligence service, which better be functional as well (or else.)

      This time Russian intelligence outplayed the US and UK counter-intelligence for a while, but then the counter-intelligence caught up. Good for them.

      1. Jan 0 Silver badge

        I'm with all people I knew who'd fought in WWII. They said it simply: "All spies should be shot". They didn't mention any exceptions.

    3. Claptrap314 Silver badge

      You might be a disciple of President Wilson, but that naive view is at best highly irresponsible. People have things that are private. Governments have real secrets. Many of these are completely legit. Some are much more debatable. It is the absolute duty of every national government to spy on their allies. Indeed, to spy on their friends The difference is that you play nicer with your friends--no honey traps, no executions, heck unless it's the Jews, you don't even put them in jail for very long (if at all) when you catch them.

    4. Binraider Silver badge

      There's a well documented case of western cyber antics leading to a full blown pipeline explosion in the Soviet Union. One wonders if such antics were motivating factors in Russia prioritising the development of it's own capabilities.

      Of course it was...

  4. Dataspace

    Russian government agents from APT29 reacted to the Western office’s trip

