July 5, 2021 By David Bisson 3 min read

Low-sophistication operational technology (OT) attacks grew in frequency and relative severity over the previous few years, according to Mandiant. In doing so, they broadened the type of threat against which companies and governments need to defend their OT assets. Attackers in this area target critical infrastructure. Their attacks can have a physical effect on employees and other people around the affected area.

Read on to learn what these attacks look like and how some of them aren’t always as they appear.

Attackers With Limited OT Expertise

When it comes to OT, threat actors don’t always want to disrupt or modify a control process. Sometimes, they want to take control of internet-facing OT assets. From there, they can leverage that access to spread their political ideas, extort owners or secure bragging rights.

In the past, most amateur OT attacks observed by Mandiant were done by attackers looking for money. More recently, the firm has seen a surge in attempts where attackers are trying to gain control of and scout out critical infrastructure.

Attackers targeted solar energy panels, building automation systems (BAS) and home security systems across a variety of industries.

In March 2020, for instance, Mandiant analyzed screenshots shared by a threat actor who claimed to have compromised dozens of control systems. The unknown attacker also shared a video of what they claimed was a compromised Dutch-language temperature control system.

Another threat actor shared a video in which they used remote connections from their desktop to make set point changes to compromised human-machine interfaces. At one point, that attacker appeared to have accessed a BAS at an Australian hotel.

Not everyone always knows what they’re doing, or, for that matter, what they’re even seeing when it comes to critical infrastructure. In one example cited by Mandiant, for instance, a threat actor claimed to have compromised the control system for a German-language railway. A closer look revealed the attacker had really compromised a command system used with model train sets.

In a similar case, someone claimed they had compromised an Israeli ‘gas system.’ It turned out that they had really taken control of a kitchen fan system at a restaurant in Israel.

A Broader View of the Critical Infrastructure Threat Landscape

The amateur attacks fit into a larger trend of increasing threats involving OT systems. Between 2018 and 2020, for instance, researchers saw a 2,000% increase in threat actors’ attempts to target OT assets and industrial control systems. Many of those attacks relied on vulnerabilities in supervisory control and data acquisition systems and brute force attempts.

The events of 2020 didn’t slow attackers down, either. According to Fortinet, nine out of 10 organizations faced an incident involving their OT in the past year. This finding matched the firm’s 2020 study. Moreover, Fortinet observed that more than half (58%) of these victims had reported a phishing attack — up from 43% a year earlier.

Defending Against OT Attacks

Even amateur OT attacks are nothing to dismiss. They give attackers a chance to learn more about critical infrastructure for staging more campaigns in the future. They normalize OT attacks and thereby invite copycat threat actors. And they could disrupt a physical process that’s essential to the business or nation.

So, organizations need to defend themselves against amateur OT attacks. They can do this by using network segmentation to isolate critical infrastructure OT assets from public-facing networks wherever feasible and using access controls to protect those systems that require remote access. They can also use threat intelligence to keep track of threat actors’ interest in OT assets. They can then implement the right defense measures and run a penetration test as a means of checking those controls.

More from News

Research finds 56% increase in active ransomware groups

4 min read - Any good news is welcomed when evaluating cyber crime trends year-over-year. Over the last two years, IBM’s Threat Index Reports have provided some minor reprieve in this area by showing a gradual decline in the prevalence of ransomware attacks — now accounting for only 17% of all cybersecurity incidents compared to 21% in 2021. Unfortunately, it’s too early to know if this trendline will continue. A recent report released by Searchlight Cyber shows that there has been a 56% increase in…

Cyberattack on American Water: A warning to critical infrastructure

3 min read - American Water, the largest publicly traded United States water and wastewater utility, recently experienced a cybersecurity incident that forced the company to disconnect key systems, including its customer billing platform. As the company’s investigation continues, there are growing concerns about the vulnerabilities that persist in the water sector, which has increasingly become a target for cyberattacks. The breach is a stark reminder of the critical infrastructure risks that have long plagued the industry. While the water utility has confirmed that…

CISA and FBI release secure by design alert on cross-site scripting 

3 min read - CISA and the FBI are increasingly focusing on proactive cybersecurity and cyber resilience measures. Conjointly, the agencies recently released a new Secure by Design alert aimed at eliminating cross-site Scripting (XSS) vulnerabilities, which have long been exploited to compromise both data and user trust. Cross-site scripting vulnerabilities occur when a web application improperly handles user input, allowing attackers to inject malicious scripts into web pages that are then executed by unsuspecting users. These vulnerabilities are dangerous because they don't attack…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today