Russia-linked new malware can cause electric power disruption globally


San Francisco, May 26 (IANS): Cyber-security researchers have spotted a new Russia-linked malware that is designed to cause electric power disruption via attacking critical infrastructure systems and electric grids.

Mandiant identified the malware, dubbed as CosmicEnergy, that can cause electric power disruption by interacting with devices such as remote terminal units (RTUs) that are commonly leveraged in electric transmission and distribution operations in Europe, the Middle East, and Asia.

"Analysis into the malware and its functionality reveals that its capabilities are comparable to those employed in previous incidents and malware, which were deployed in the past to impact electricity transmission and distribution," the researchers noted in a blog post.

The team believes CosmicEnergy poses a plausible threat to affected electric grid assets.

The new malware was possibly developed by either Rostelecom-Solar or an associated party to recreate real attack scenarios against energy grid assets.

"It is possible that the malware was used to support exercises such as the ones hosted by Rostelecom-Solar in 2021 in collaboration with the Russian Ministry of Energy or in 2022 for the St. Petersburga¿s International Economic Forum (SPIEF)," the report informed.

While its capabilities are not significantly different from previous malware families, its discovery highlights several notable developments in the operational technology (OT)A threat landscape.

"The discovery of new OT malware presents an immediate threat to affected organisations, since these discoveries are rare and because the malware principally takes advantage of insecure by design features of OT environments that are unlikely to be remedied any time soon," said the researchers.

The organisations in this field should take mitigating actions against CosmicEnergy to preempt in the wild deployment and to better understand common features and capabilities that are frequently deployed in OT malware, they suggested.

 

  

Top Stories


Leave a Comment

Title: Russia-linked new malware can cause electric power disruption globally



You have 2000 characters left.

Disclaimer:

Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Daijiworld.com will not be responsible for any defamatory message posted under this article.

Please note that sending false messages to insult, defame, intimidate, mislead or deceive people or to intentionally cause public disorder is punishable under law. It is obligatory on Daijiworld to provide the IP address and other details of senders of such comments, to the authority concerned upon request.

Hence, sending offensive comments using daijiworld will be purely at your own risk, and in no way will Daijiworld.com be held responsible.