In addition to oil and gas companies, the XENOTIME threat group has begun targeting electric utility organizations located in the U.S. and elsewhere.

In February 2019, Dragos observed XENOTIME probing the networks of electric utility organizations, trying to gather information and enumerate network resources associated with organizations based in the U.S. and the Asia-Pacific region. In so doing, the threat group expanded its range of targets from oil and gas organizations to another critical infrastructure sector.

While Dragos did not observe any of these attack attempts result in a successful intrusion, the digital security firm said that the group’s expansion of malicious activity to the electric utility sector is cause for concern. Specifically, Dragos researchers noted that the threat group could be using these attacks to try to fulfill some of the prerequisites for executing a prolonged disruptive or destructive event on electric utility operations.

XENOTIME: A Growing Threat to Industrial Control Systems

XENOTIME has been a problem for critical infrastructure companies for some time now. Back in December 2017, FireEye discovered that the group had used TRITON/TRISIS malware in an attempt to disrupt the industrial processes at a critical infrastructure organization in the Middle East.

Over the next year, Dragos identified several compromises of industrial control system (ICS) vendors and manufacturers in which XENOTIME was the culprit. In April 1029, FireEye confirmed that it was analyzing an additional intrusion in which XENOTIME deployed TRITON malware at a different critical infrastructure utility.

How to Defend ICS Assets Against Digital Threats

Defending ICS assets against digital threats starts with the creation and implementation of a robust testing program that consists of system and device configuration checks, network traffic analysis, offline vulnerability research and penetration tests on an ongoing basis.

Critical infrastructure organizations should also use device inventories, automated scanning, advanced behavioral analytics and other tools to harden their industrial internet of things (IoT) systems.

More from

Securing Your SAP Environments: Going Beyond Access Control

Many large businesses run SAP to manage their business operations and their customer relations. Security has become an increasingly critical priority due to the ongoing digitalization of society and the new opportunities that attackers exploit to achieve a system breach. Recent attacks related to corrupt data, stealing personal information and escalating privileges for remote code execution all highlight the new and varied entry points threat actors have taken advantage of. Attackers with the appropriate skills could be able to exploit…

Who Carries the Weight of a Cyberattack?

Almost immediately after a company discovers a data breach, the finger-pointing begins. Who is to blame? Most often, it is the chief information security officer (CISO) or chief security officer (CSO) because protecting the network infrastructure is their job. Heck, it is even in their job title: they are the security officer. Security is their responsibility. But is that fair – or even right? After all, the most common sources of data breaches and other cyber incidents are situations caused…

Transitioning to Quantum-Safe Encryption

With their vast increase in computing power, quantum computers promise to revolutionize many fields. Artificial intelligence, medicine and space exploration all benefit from this technological leap — but that power is also a double-edged sword. The risk is that threat actors could abuse quantum computers to break the key cryptographic algorithms we depend upon for the safety of our digital world. This poses a threat to a wide range of critical areas. Fortunately, alternate cryptographic algorithms that are safe against…

Abuse of Privilege Enabled Long-Term DIB Organization Hack

From November 2021 through January 2022, the Cybersecurity and Infrastructure Security Agency (CISA) responded to an advanced cyberattack on a Defense Industrial Base (DIB) organization’s enterprise network. During that time frame, advanced persistent threat (APT) adversaries used an open-source toolkit called Impacket to breach the environment and further penetrate the organization’s network. Even worse, CISA reported that multiple APT groups may have hacked into the organization’s network. Data breaches such as these are almost always the result of compromised endpoints…