HomeSecurityResearchers create self-propagating worm targeting SCADA equipment

Researchers create self-propagating worm targeting SCADA equipment

German researchers from OpenSource Security (OSS) have created a proof-of-concept worm that targets programmable logic controllers (PLCs), critical ICS/SCADA equipment.

Their research builds on previous work by fellow German researchers, who presented a port scanner that can detect Internet-accessible PLCsat the Black Hat USA conference last year.

Researchers create self-propagating worm targeting SCADA equipment

The OSS team led by Ralf Spenneberg has created a worm, a self-replicating computer virus, that can live in the small memories of PLC devices, scan the local network and spread to other similar devices.

In their proof-of-concept code, the researchers created a virus that can infect Siemens SIMATIC S7-1200 PLCs. Nicknamed PLC-Blaster, this worm will scan the local network via port 102, together with Siemens devices and the Inter-Control Center Communications Protocol (ICCP), in order to find new targets to replicate itself.

After identifying a new target, the worm-type virus shuts down the device, copies the code, and reboots. Researchers say that the infection process itself works because the worm mimics the Siemens TIA-Portal and also exploits a vulnerability that has already been patched by Siemens.

targets-scada-equipment

The researchers say that this type of attacks will require the malicious actor to have access to the vulnerable network or to compromise the PLCs before sending them to their customers.

Once installed on an industrial network, PLC-Blaster executes, spreads to other devices, and then can execute other types of malicious code that can damage SCADA or create a DoS (Denial of Service) on critical equipment.

The researchers also report that their worm can easily be modified to target other types of PLCs, but it is also easy to detect, thanks to the mandatory ten‑second pause required for the worm to copy itself.

Restoring the SCADA device where the PLC is deployed will not help since the worm is stored in the controller. The only method to remove the threat is to perform a factory reset.

More details about the PLS-Blocker operation can be found in the research paper and the Black Hat Asia 2016 presentation.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS