Skip to content
info@johnstek.com Corporate HQ: Coral Gables, FL, USA +1.786.375.9020 Latin American HQ: Asuncion, Paraguay +595.213.277.395
Search:
Search
JohnsTek
Strategic Technology Engineering
JohnsTekJohnsTek
  • About
  • Products & Services
  • Cyber Risk
    • Managed Security Services Provider (MSSP)
    • Cyber Risk Management Solution
  • Markets
    • Commercial
    • Government
  • Resource Center
  • Contact
  • About
  • Products & Services
  • Cyber Risk
    • Managed Security Services Provider (MSSP)
    • Cyber Risk Management Solution
  • Markets
    • Commercial
    • Government
  • Resource Center
  • Contact

Alert: CrashOverride Targets Critical Infrastructure and Energy

You are here:
  1. Home
  2. Blog
  3. Alert: CrashOverride Targets Critical Infrastructure…
Jun152017
BlogCyberSecurityCyberScape

In January of this year we reported on the potential rise of Cyber attacks on Industrial Control Systems and SCADA (ICS, SCADA and Ransomware). It is now being reported that ‘CrashOverride’, an attack vector that targeted the Ukraine electric grid last year, is now threatening Natural Gas and other infrastructure sectors across the globe. The National Cybersecurity and Communications Integration Center (NCCIC) is concerned, and is closely watching for any indication of this malware (Source: US-CERT June 12, 2017). As of today, the NCCIC risk rating for an attack in the US is Yellow (Medium).

The malware is active outside the US.  It seems to focus on critical infrastructure organizations using ICS protocols in the electric power control systems: IEC101, IEC104, and IEC61850. However, US-based companies are warned not to get too complacent.  CrashOverride could be strengthened without warning, and exploit existing protocols in the US through advancements in the attack vector.

Victims will experience a degradation of power grid reliability, denial of service to COM ports on devices, network mapping of the environment for propagation of the attack deeper into the enterprise, and requirement for manual reset of systems…not an easy task for many remote controls stations.

What is the solution? Layered cybersecurity defenses is a good start.  Proper network hygiene which includes strong passwords, active monitored security, and closely management Role Based Access Controls would create a very serious barrier to penetrate the critical nodes of the network. Some Cyber Risk Management firms that deploy advanced managed security services with threat correlation services are generally able to detect these malware protocols.

All organizations in this industry are cautioned to remain vigilant! More will be reported as we get updates.

 

Please contact us for more information!

Author:  Scott A. Johnston @JTI_SJohnston (Twitter)
Scott A. Johnston is the President and Founder of JohnsTek, Incorporated.
www.johnstek.com
@JOHNSTEK (Twitter)

 

 

Categories: Blog, CyberSecurityBy Scott JohnstonJune 15, 2017
Tags: CybersecurityEnergyICSInfrastructure

Author: Scott Johnston

https://johnstek.com

Post navigation

PreviousPrevious post:JAFF Ransomware Booty Available on Dark WebNextNext post:The Intel Brief 16JUN17 ~ By JohnsTek

Related posts

CyberShield
Stay Secure During the Holiday Season!
December 13, 2020
Cafe Photo
Data Protection In Cafes And Restaurants
February 10, 2019
JohnsTek Capability Statement 2019
February 9, 2019
EOC_ops
Five Things Local Governments Can Do Now To Prepare For Disaster Response
January 11, 2019
Cyber_Pentagon_Transparent
Five Things You Can Do Now To Implement Or Improve Cybersecurity
January 8, 2019
IBM_JohnsTek
JohnsTek Partners with IBM Security!
November 19, 2018
Shortcuts
  • About Us
  • Offerings
  • Products & Services
  • Commercial
  • Government
  • Privacy
  • Terms
JohnsTek News
  • CyberShield
    Stay Secure During the Holiday Season!
    December 13, 2020
  • Cafe Photo
    Data Protection In Cafes And Restaurants
    February 10, 2019
  • JohnsTek Capability Statement 2019
    February 9, 2019
Security Alerts
  • Alert Dispatch 23JUN17 ~ By JohnsTek
    June 23, 2017
  • Alert Dispatch 5JUN17 ~ By JohnsTek
    June 5, 2017
  • Alert Dispatch 18MAY17 ~ By JohnsTek
    May 18, 2017
Intel Brief
  • The Intel Brief 02OCT17 ~ By JohnsTek
    September 28, 2017
  • The Intel Brief 16AUG17 ~ By JohnsTek
    August 16, 2017
  • The Intel Brief 16JUN17 ~ By JohnsTek
    June 16, 2017
Press Releases
  • JohnsTek Capability Statement 2019
    February 9, 2019
  • IBM_JohnsTek
    JohnsTek Partners with IBM Security!
    November 19, 2018
  • Veterans Day
    JOHNSTEK WISHES YOU A HAPPY VETERAN’S DAY!
    November 10, 2017
Copyright © 2022 JohnsTek | All Rights Reserved.
  • About Us
  • Offerings
  • Products & Services
  • Commercial
  • Government
  • Privacy
  • Terms
Footer