July 5, 2021 By David Bisson 3 min read

Low-sophistication operational technology (OT) attacks grew in frequency and relative severity over the previous few years, according to Mandiant. In doing so, they broadened the type of threat against which companies and governments need to defend their OT assets. Attackers in this area target critical infrastructure. Their attacks can have a physical effect on employees and other people around the affected area.

Read on to learn what these attacks look like and how some of them aren’t always as they appear.

Attackers With Limited OT Expertise

When it comes to OT, threat actors don’t always want to disrupt or modify a control process. Sometimes, they want to take control of internet-facing OT assets. From there, they can leverage that access to spread their political ideas, extort owners or secure bragging rights.

In the past, most amateur OT attacks observed by Mandiant were done by attackers looking for money. More recently, the firm has seen a surge in attempts where attackers are trying to gain control of and scout out critical infrastructure.

Attackers targeted solar energy panels, building automation systems (BAS) and home security systems across a variety of industries.

In March 2020, for instance, Mandiant analyzed screenshots shared by a threat actor who claimed to have compromised dozens of control systems. The unknown attacker also shared a video of what they claimed was a compromised Dutch-language temperature control system.

Another threat actor shared a video in which they used remote connections from their desktop to make set point changes to compromised human-machine interfaces. At one point, that attacker appeared to have accessed a BAS at an Australian hotel.

Not everyone always knows what they’re doing, or, for that matter, what they’re even seeing when it comes to critical infrastructure. In one example cited by Mandiant, for instance, a threat actor claimed to have compromised the control system for a German-language railway. A closer look revealed the attacker had really compromised a command system used with model train sets.

In a similar case, someone claimed they had compromised an Israeli ‘gas system.’ It turned out that they had really taken control of a kitchen fan system at a restaurant in Israel.

A Broader View of the Critical Infrastructure Threat Landscape

The amateur attacks fit into a larger trend of increasing threats involving OT systems. Between 2018 and 2020, for instance, researchers saw a 2,000% increase in threat actors’ attempts to target OT assets and industrial control systems. Many of those attacks relied on vulnerabilities in supervisory control and data acquisition systems and brute force attempts.

The events of 2020 didn’t slow attackers down, either. According to Fortinet, nine out of 10 organizations faced an incident involving their OT in the past year. This finding matched the firm’s 2020 study. Moreover, Fortinet observed that more than half (58%) of these victims had reported a phishing attack — up from 43% a year earlier.

Defending Against OT Attacks

Even amateur OT attacks are nothing to dismiss. They give attackers a chance to learn more about critical infrastructure for staging more campaigns in the future. They normalize OT attacks and thereby invite copycat threat actors. And they could disrupt a physical process that’s essential to the business or nation.

So, organizations need to defend themselves against amateur OT attacks. They can do this by using network segmentation to isolate critical infrastructure OT assets from public-facing networks wherever feasible and using access controls to protect those systems that require remote access. They can also use threat intelligence to keep track of threat actors’ interest in OT assets. They can then implement the right defense measures and run a penetration test as a means of checking those controls.

More from News

Hackers are increasingly targeting auto dealers

3 min read - Update as of July 11, 2024 In late June, more than 15,000 car dealerships across North America were affected by a cyberattack on CDK Global, which provides software to car dealers. After two cyberattacks over two days, CDK shut down all systems, which caused delays for car buyers and disruptions for the dealerships. Many dealerships went back to manual processes, including handwriting up orders, so that sales could continue at a slower pace. Car buyers who recently bought a car from…

CISA director says banning ransomware payments is off the table

3 min read - The FBI, CISA and NSA all strongly advise against organizations making ransomware payments if they fall victim to ransomware attacks. If so, why not place a ban on paying ransomware demands? The topic came up at a recent Oxford Cyber Forum. Jen Easterly, Director of CISA, commented on the issue, saying, “I think within our system in the U.S. — just from a practical perspective — I don’t see it happening.” It’s unlikely this was a purely spontaneous remark as the…

A proactive cybersecurity policy is not just smart — it’s essential

3 min read - It’s easy to focus on the “after” when it comes to cybersecurity: How to stop an attack after it begins and how to recover when it's over. But while a reactive response sort of worked in the past, it simply is not good enough in today’s world. Not only are attacks more intense and more damaging than ever before, but cyber criminals also use so many different attack methods. Zscaler ThreatLabz 2024 Phishing Report found that phishing attacks increased by…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today