Operational technology is in the crosshairs of hackers, from opportunistic criminal actors through to sophisticated state-sponsored attackers.
When it comes to critical national infrastructure, history has proven that no utility is too small a target. Such was the case when, in 2023, the Littleton Electric Light and Water Departments in Massachusetts found an attacker in its networks. Attackers that had been there for ten months.
The power grid attackers were a group known as Volt Typhoon, which Microsoft has linked to the Chinese government and labelled responsible for targeting US critical infrastructure for espionage purposes. A new case study goes into great depth as to how these power grid attackers operate, including the exfiltration of geographic information system data concerning the spatial layout of energy systems.ย
“Volt Typhoon’s persistent capabilities often begin with the use of zero-days,โ said Gunter Ollmann, CTO at Cobalt. The group targets industries who are often behind in their security procedures.
โWhile the main cause for concern here is certainly the length of time that attackers will dwell within a network to exfiltrate data and move laterally throughout networks,โ said Ollmann, โthe key indicator of how to truly prevent these issues is once again down to having regular assessments of vulnerabilities within the tools you use.โ
Power grid attack upgrades
This combination of zero-days and legacy devices mixed with slow or impossible updates isn’t restricted to power companies. However, in the context of critical national infrastructure the risk becomes magnified exponentially.ย
โOne of the biggest challenges with cybersecurity in critical infrastructure is the long lifespan of the devices,โ Tim Mackey, Head of Software Supply Chain Risk Strategy at Black Duck, told TechFinitive.
โSomething that was designed and tested to the best practices available when it was released can easily become vulnerable to attacks using more sophisticated attacks later in its lifecycle.โ
Since attackers know that critical infrastructure providers are measured in their up-time or service availability, Mackey explained that once such a device is compromised, the attackers are all too aware that they have the luxury of time. This means they can map out and plan a highly targeted attack rather than being opportunistic.
OT data: no opportunism, just opportunity
There is no opportunism involved when it comes to exfiltrating operation technology data (OT data), and Volt Typhoon being an espionage-focused attacker is a great example of this. Just consider, as explained by Donovan Tindill, Director of OT Cybersecurity at DeNexus, what such OT data has the potential to be used for:
- Understanding the configuration and operation of the target system.
- Theft of intellectual property that can aid others in gaining a competitive advantage.
- Identification of supply chain or third-party relationships.
- Gaining knowledge of the system as a whole, including the design, operation and behaviour of a small portion of the electrical grid – and its criticality to the more extensive network.
- Gaining knowledge to allow later manipulation of the OT system towards a specific objective.
All companies are faced with the same challenges. This isn’t something limited to power suppliers or national infrastructure by any means.
Think in terms of limited network visibility, difficulty in identifying vulnerabilities, problems caused by shared networks, and so on. All of which can lead to it being difficult, to say the least, when it comes to the identification and detection of threat actors within an environment.
The fact that Volt Typhoon actor remained undetected for 300 days is as good an example of this as you will get.
โThe most important OT lockdown,โย Tindill advises, is โisolation from the business network, the internet and remote access.โย
Related articles on the supply chain