LAS VEGAS — Cyberattacks on operational technology have shifted in recent years from extortion and espionage to destruction, a trend that should alarm those tasked with defending outdated industrial equipment, experts said on Thursday.
The panel discussion at the Black Hat USA cybersecurity conference here highlighted the plethora of risks facing U.S. critical infrastructure operators — many of them poorly staffed and funded — at a time of heightened geopolitical conflict.
“OT attacks are increasingly moving from targeting not just data but physical operations,” said Cheri Benedict, a cybersecurity and supply chain adviser at the White House’s Office of the Federal Chief Information Officer.
“There is a real desire and willingness to cause this impact at scale,” said Matthew Rogers, the operational technology cybersecurity lead at the Cybersecurity and Infrastructure Security Agency (CISA).
Security experts have watched with growing concern over the past few weeks as states have reported Iran-linked intrusions into their water systems. But those attacks failed to compromise the safety and quality of Americans’ drinking water. Meanwhile, Iran has also mounted a campaign to disable safety monitoring systems in water and other sectors.
Those attacks are “what should actually scare you,” Rogers said.
Rogers pointed to an advisory about the Iranian activity that CISA updated on July 22. In it, the agency said that at one organization, Iran-linked threat actors planted malware on a programmable logic controller (PLC) that “overrode specific instruction sets responsible for maintaining safe operating parameters in the victim’s environment.”
One of the first known examples of malware disabling safety systems occurred in 2017, when a tool known as Triton switched off safety equipment at a Saudi Arabian power plant. Since then, hackers have developed new ways to stealthily cripple safety monitoring technology. Because infrastructure operators rarely examine PLCs unless they noticeably malfunction, safety-compromising malware could sit unnoticed for years before an adversary deploys it.
“That PLC is now just a ticking time bomb,” Rogers said.
As these new tools have evolved, the cyber threat environment has shifted to take advantage of them. Groups that previously used ransomware to achieve disruptive effects are now trying to do more serious damage to infrastructure providers.
Wiper malware has become more common than ransomware in some instances, said Neal Pollard, a partner at the consulting firm Control Risks. The volume of threat activity has remained relatively consistent, Pollard said, but there has been “a change in intent and understanding.”
And wipers aren’t even the infrastructure community’s biggest problem. Hackers are also increasingly trying to deploy code that permanently cripples widely used industrial control systems, according to Rogers.
“We do not have enough [ICS devices] to actually replace that equipment at any scale across the United States,” Rogers said. “As people are more willing to destroy our equipment, how do we make sure that doesn’t happen? Because that is such a non-recoverable scenario.”
Familiar gaps, new risk
While the level of danger facing infrastructure providers and their customers has reached new heights over the past year, the underlying causes of that danger are almost as old as the infrastructure itself.
Many OT devices still use simple default passwords, Pollard said, and infrastructure providers routinely use unpatchable, out-of-date devices that they can’t easily replace.
“Nobody’s using TLS,” Rogers said, referring to the Transport Layer Security encryption protocol. “All of this is unencrypted and unsigned.”
Organizations also struggle to understand their supply chains and are regularly surprised by how disruptions at third-party vendors cascade into their own networks, Benedict said.
In addition, incident-response processes that rely on real-time log access often collapse when they encounter isolated OT environments.
“These OT systems, they are operating in a very constrained environment with limited connectivity,” said Vu Nguyen, the chief information security officer at the Department of Justice. “So getting logs off of [these devices] can be very difficult.”
The cybersecurity community needs to come up with solutions to these problems that don’t rely on forcing infrastructure engineers to behave differently, Rogers said.
“We as cyber people are not going to change the engineers’ behavior,” he said. “Any policy that’s based off of, ‘We’re going to get those electrical engineers to change what they’ve been doing for decades’ is a policy failure.”
No need for AI
In their attacks on OT systems, hackers mostly haven’t used cutting-edge AI capabilities or zero-day vulnerabilities. OT is so vulnerable, experts said, that they haven’t needed to.
Out of “all the activity we've seen over the past couple of months,” Rogers said, “none of it is using a single CVE in OT.”
“There are some very scary CVEs [that would] make their attacks much stealthier,” Rogers added. “There’s no need.”