August 5, 2019 By David Bisson < 1 min read

Researchers spotted a new activity group called HEXANE targeting industrial control systems (ICSs) in the Middle East.

Dragos observed HEXANE targeting ICSs operated by oil and gas companies located in the Middle East and telecommunications providers in the Middle East, Central Asia and Africa. The security firm reasoned that the group was likely pursuing these targets to lay the groundwork to conduct network-based attacks, such as man-in-the-middle (MitM) operations.

Active since at least 2018, HEXANE distinguished itself from similar groups like MAGNALLIUM and CHRYSENE by its unique behaviors, tools and victimology. For instance, the fact that it uses malicious domains leveraging general IT themes and novel detection evasion schemes helped make HEXANE stand out among its peers. That said, Dragos stated that the group neither has the necessary access nor capability to disrupt industrial control systems at this time.

Threats to Industrial Control Systems Abound

HEXANE isn’t the only threat to target organizations’ industrial control systems. Kaspersky Lab observed as much in a March 2019 report when it discovered that almost half of industrial systems exhibited signs of attempted access to their critical assets.

Just a month later, FireEye uncovered a second intrusion involving TRITON, a custom attack framework designed to manipulate industrial safety systems. In June, Trend Micro observed XENOTIME, the threat actor behind TRITON, probing the ICSs associated with U.S. power grids.

How to Defend Against ICS Attacks

Security professionals can help defend their organizations from ICS attacks by establishing testing programs that evaluate all industrial control systems and their components for relevant security threats based on their respective risk profiles.

Companies should also consider strengthening both their incident response and threat intelligence capabilities so they can quickly determine the root cause of a security incident and prevent digital attackers from accomplishing their goals.

More from

Evolving red teaming for AI environments

2 min read - As AI becomes more ingrained in businesses and daily life, the importance of security grows more paramount. In fact, according to the IBM Institute for Business Value, 96% of executives say adopting generative AI (GenAI) makes a security breach likely in their organization in the next three years. Whether it’s a model performing unintended actions, generating misleading or harmful responses or revealing sensitive information, in the AI era security can no longer be an afterthought to innovation.AI red teaming is emerging…

What we can learn from the best collegiate cyber defenders

3 min read - This year marked the 19th season of the National Collegiate Cyber Defense Competition (NCCDC). For those unfamiliar, CCDC is a competition that puts student teams in charge of managing IT for a fictitious company as the network is undergoing a fundamental transformation. This year the challenge involved a common scenario: a merger. Ten finalist teams were tasked with managing IT infrastructure during this migrational period and, as an added bonus, the networks were simultaneously attacked by a group of red…

A spotlight on Akira ransomware from X-Force Incident Response and Threat Intelligence

7 min read - This article was made possible thanks to contributions from Aaron Gdanski.IBM X-Force Incident Response and Threat Intelligence teams have investigated several Akira ransomware attacks since this threat actor group emerged in March 2023. This blog will share X-Force’s unique perspective on Akira gained while observing the threat actors behind this ransomware, including commands used to deploy the ransomware, active exploitation of CVE-2023-20269 and analysis of the ransomware binary.The Akira ransomware group has gained notoriety in the current cybersecurity landscape, underscored…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today