Password Recovery Tool Infects Industrial Systems With Malware

Share post:

Security researchers at Dragos have uncovered the activities of a threat actor that uses password recovery tools to infect industrial control systems (ICS).

After analyzing an incident involving Automation Direct’s DirectLogic PLCs, the researchers discovered that the cracking software exploited a known vulnerability in the device to extract the password.

The software also dropped a malware known as Sality during the recovery process. Sality is a malware that creates a peer-to-peer botnet for various tasks that require the power of distributed computing to complete faster actions such as password cracking or cryptocurrency mining.

Sality can also inject itself into running processes and abuse the Windows autorun function to copy itself into network shares, external drives, and removable storage devices that could transfer it to other systems.

The malicious software and vulnerability identified have been reported to Automation Direct and the manufacturer has released fixes to address them.

Administrators of PLC from other providers should be aware of the risk of using password cracking in ICS environments. Operational technology engineers are also advised to avoid password cracking tools, especially if the source is unknown.

The sources for this piece include an article in BleepingComputer.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Cyber Security Today, Week in Review for week ending Friday April 19, 2024

On this episode Jen Ellis, co-chair of the Ransomware Task Force, talks about ways of fighting one of the biggest cyber threats to IT d

Cyber Security Today, April 19, 2024 – Police bust phishing rental platform, a nine-year old virus found on Ukrainian computers, and more

This episode reports on a threat actor targeting governments in the Middle East with a novel way of hiding malware is going international

Controversial expansion of US surveillance powers nears Senate vote

The US Senate is poised to vote on a significant expansion of Section 702 of the Foreign Intelligence...

Russian-linked hackers target U.S. and European water systems

A Russian military-affiliated hacking group, Sandworm, is suspected of coordinating recent cyberattacks on water utilities in the U.S.,...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways