Malicious Cyber Tools to Sabotage Energy and Other Critical Industries Have Been Discovered: US Agencies

Evidence suggests that Russia could be behind these industrial control system-disrupting tools.

Advertisement
By Associated Press | Updated: 14 April 2022 16:39 IST
Highlights
  • Mandiant, called the tools “exceptionally rare and dangerous"
  • The US government has warned of possible cyberattacks from Russia
  • The malware could be used to shut down critical machinery

One of the cybersecurity firms involved, Mandiant, called the tools “exceptionally rare and dangerous”

Photo Credit: Pexels/ Sora Shizamaki

Multiple US government agencies issued a joint alert Wednesday warning of the discovery of a suite of malicious cyber tools created by unnamed advanced threat actors that are capable of sabotaging the energy sector and other critical industries.

The public alert from the Energy and Homeland Security Departments, the FBI and National Security Agency did not name the actors or offer details on the find. But their private sector cybersecurity partners said the evidence suggests Russia is behind the industrial control system-disrupting tools — and that they were configured to initially target North American energy concerns.

One of the cybersecurity firms involved, Mandiant, called the tools “exceptionally rare and dangerous.”

Advertisement

In a report, it called the tools' functionality was “consistent with the malware used in Russia's prior physical attacks” though it acknowledged that the evidence linking it to Moscow is “largely circumstantial.”

Advertisement

The CEO of another government partner, Robert M. Lee of Dragos, agreed that a state actor almost certainly crafted the malware, which he said was configured to initially target liquified natural gas and electric power sites in North America.

Lee referred questions on the state actor's identity to the US government and would not explain how the malware was discovered other than to say it was caught "before an attack was attempted.”

Advertisement

“We're actually one step ahead of the adversary. None of us want them to understand where they screwed up,” said Lee. “Big win.”

The Cybersecurity and Infrastructure Security Agency, which published the alert, declined to identify the threat actor.

Advertisement

The US government has warned critical infrastructure industries the gird for possible cyberattacks from Russia as retaliation for severe economic sanctions imposed on Moscow in response to its February 24 invasion of Ukraine.

Officials have said that Russian hacker interest in the US energy sector is particularly high, and CISA urged it in a statement Wednesday to be especially mindful of the mitigation measures recommended in the alert. Last month, the FBI issued an alert saying Russian hackers have scanned at least five unnamed energy companies for vulnerabilities.

Lee said the malware was “designed to be a framework to go after lots of different types of industries and be leveraged multiple times. Based on the configuration of it, the initial targets would be LNG and electric in North America.”

Mandiant said the tools pose the greatest threat to Ukraine, NATO members and other states assisting Kyiv in its defence against Russian military aggression.

It said the malware could be used to shut down critical machinery, sabotage industrial processes and disable safety controllers, leading to the physical destruction of machinery that could lead to the loss of human lives. It compared the tools to Triton, malware traced to a Russian government research institute that targeted critical safety systems and twice forced the emergency shutdown of a Saudi oil refinery in 2017 and to Industroyer, the malware that Russian military hackers used the previous year to trigger a power outage in Ukraine.

Lee said the newly discovered malware, dubbed Pipedream, is only the seventh such malicious software to be identified that is designed to attack industrial control systems.

Lee said Dragos, which specialises in industrial control system protection, identified and analysed its capability in early 2022 as part of its normal business research and in collaboration with partners.

He would offer no more specifics. In addition to Dragos and Mandiant, the U.S. government alert offers thanks to Microsoft, Palo Alto Networks and Schneider Electric for their contributions.

Schneider Electric is one of the manufacturers listed in the alert whose equipment is targeted by the malware. Omron is another. Mandiant said it had analysed the tools in early 2002 with Schneider Electric.

In a statement, Palo Alto Networks executive Wendi Whitmore said: “We've been warning for years that our critical infrastructure is constantly under attack. Today's alerts detail just how sophisticated our adversaries have gotten.”

Microsoft had no comment.


Can OnePlus 10 Pro beat iPhone 13 Pro and Galaxy S22 Ultra? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Russia, Ukraine, Malware
Advertisement

Related Stories

Popular Mobile Brands
  1. Google's Pixel Upgrade Program Lets You Get the Latest Model Every Year
  2. Here's When the Realme 16 Pro Series Will Launch in India
  3. OTT Releases This Week: Thamma, Mrs Deshpande, Raat Akeli Hai The Bansal Murders, and More
  4. Here's How Much The Redmi Note 15 5G Could Cost in India
  5. Redmi Pad 2 Pro 5G Will Launch in India Soon: See Expected Features
  6. Oppo Reno 15 Pro, Reno 15 Pro Max Global Variants Surface on Geekbench
  7. Samsung Announces Exynos 2600 as World's First 2nm Chipset
  8. Vivo X200T Tipped to Feature This Dimensity Chipset Ahead of India Launch
  9. Oppo Reno 15 Pro Mini Tipped to Launch as First Compact Reno Smartphone
  10. Samsung Galaxy Z Fold 8 May Offer These Notable Camera Upgrades
  1. Dominic and The Ladies Purse Out on OTT: Know Everything About Streaming, Plot, Cast, and More
  2. Sony Announces Year-End Holiday Sale in India on PS5 Accessories, Games
  3. Xiaomi 17 Ultra Battery, Charging Specifications and Colourways Tipped Ahead of Launch
  4. Redmi Note 15 5G Price in India, Storage Configurations Tipped Ahead of January 6 Launch
  5. Little Hearts Streaming Now on Netflix: Know Everything About Plot, Cast, and More
  6. Crypto Traders Remain Cautious Amidst Tight Liquidity and Mixed Global Cues
  7. Oppo Reno 15 Pro Global Variant Reportedly Surface on Geekbench Alongside Reno 15 Pro Max
  8. Vivo X200T Key Specifications Tipped Ahead of India Launch; Could Feature Three 50-Megapixel Cameras
  9. Meta Reportedly Building Three New Generative AI Models With Focus on Image and Video Generation
  10. Google Pixel Upgrade Program Launched in India With Assured Buyback of Pixel 10 Series Models
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.