HomeSecurityXenotime: The most dangerous hacking group strikes again! What do researchers say?

Xenotime: The most dangerous hacking group strikes again! What do researchers say?

Xenotime: Hackers are behind two potentially deadly intrusions into industrial facilities in America, according to researchers with security firm Dragos.

The hacking group, dubbed Xenotime, quickly gained international attention in 2017 when researchers reported that Xenotime caused a dangerous operational disruption at a critical infrastructure site in the Middle East. Researchers from Dragos have since labeled the group the most dangerous cyber threat worldwide.

Xenotime

The most concerning thing about this attack was the use of unknown malware that targeted the facility’s safety procedures. These systems are a combination of hardware and software that many critical infrastructure sites use to prevent unsafe conditions from occurring. When fuel gas pressures or reactor temperatures rise to potentially unsafe limits, for example, an SIS will automatically close valves or initiate cooling procedures to prevent accidents that threaten health or life.

In April, FireEye reported that SIS-tampering malware, known alternatively as Triton and Trisis, was used in an attack on another industrial facility.

According to Dragos, Xenotime performs network scans and multi-element identification on electrical grids in the U.S. and other regions.

Attacks come in many forms. One is credential-stuffing attacks, which use passwords stolen in previous, sometimes unrelated, breaches in the hope that they will be used against new targets. Then there are network scans, which record the various computers, routers, and other devices connected to it and list the network ports on which they accept connections.

So far, no one knows for sure who is behind Xenotime. Early suspicions suggested that the hackers were working on behalf of Iran. Last October, FireEye assessed with high confidence that Triton was developed with the help of the Central Scientific Research Institute of Chemistry and Engineering in Moscow. Russia has been linked to other critical infrastructure attacks, including one in December 2015 on infrastructure in Ukraine that left hundreds of thousands of people in the Ivano-Frankivsk region of Ukraine without electricity. That attack represented the first known hacker. And almost exactly a year later, a second hack linked to Russia knocked out electricity in Ukraine again.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS