Tag Archive for: blackout

How Ukraine avoided another blackout attack


LAS VEGAS — The Industroyer malware attack on Ukraine’s energy grid in 2016 caused a significant blackout and marked a turning point for cyber attacks against critical infrastructure.

But the Industroyer2 malware attack, which was more sophisticated than the original, failed to take down Ukraine’s energy grid in March, thanks in part to the lessons learned from the 2016 attack.

During a Black Hat 2022 session Wednesday, researchers from cybersecurity vendor ESET and Victor Zhora, deputy chairman of Ukraine’s State Service of Special Communications and Information Protection (SSSCIP), discussed the Industroyer2 malware and the response to the attack, which was unsuccessful.

The Industroyer2 attack was preceded by several wiper attacks on Ukraine networks, starting with HermeticWiper Feb. 23 — a day before Russia’s invasion of Ukraine. “HermeticWiper was found on hundreds of systems in multiple organizations, and it was a pure act of cyber sabotage,” said Robert Lipovsky, principal threat intelligence researcher at ESET, during the presentation.

The situation escalated; on April 8, ESET was called in to analyze new malware discovered by CERT-UA, the national computer emergency response team for Ukraine, following an incident at an energy provider in the country. “Our analysis found that threat was bigger than expected,” Lipovsky said. “It was a new version of Industroyer, something which we hadn’t seen in the last five years.”

Unlike the original Industroyer malware, the second attempt failed to cause a blackout. But Lipovsky said that had Industroyer2 been successful, it could have left more than 2 million people in Ukraine in the dark.

“The attack was thwarted thanks to a prompt response by the defenders at the targeted energy company, and the work of CERT-UA and our assistance,” he said.

Responding to Industroyer2

Zhora said many private-sector companies have provided invaluable cybersecurity support for Ukraine during Russia’s invasion, but added that Microsoft and ESET have been especially crucial because the two vendors have the biggest presence on Ukraine networks and massive amounts of telemetry data.

That data proved to be extremely valuable in thwarting…

Source…

Internet Blackout Coming To Show The EU Parliament It’s Not Just ‘Bots’ Concerned About Article 13

Last week Glyn mentioned that the German Wikipedia had announced plans to “go dark” this Thursday to protest Articles 11 and 13 of the EU Copyright Directive. And now it appears that a whole bunch of other websites will join in the protest (including us). While we won’t go completely dark, we’ll be putting up a banner in support of the many websites that do plan to go dark — and we’ve heard that an awful lot of websites will be joining in. Supporters keep trying to dismiss these complaints as just being “bots” or the big internet companies, but lots of others will be showing that this is about the broader internet this Thursday. This is just one of many protests happening this week, with in-person protests happening all through the EU this coming weekend as well. Meanwhile there are lots of efforts to get MEPs to pledge to vote against Article 13 that has been gaining momentum as well. I have no idea if these kinds of protests will be as effective as the blackday back during the SOPA fight, but I can say that Article 13 will be way worse for the internet than SOPA ever would have been.

Permalink | Comments | Email This Story

Techdirt.

Venezuela is blaming a crippling 5-day blackout on US cyber warfare — but experts say it’s probably the country’s neglected power network – Business Insider

Venezuela is blaming a crippling 5-day blackout on US cyber warfare — but experts say it’s probably the country’s neglected power network  Business Insider

The power grid is in a state of disrepair because of poor maintenance and underfunding.

“cyber warfare news” – read more