HomeSecurityNew Snake ransomware targets industrial control systems

New Snake ransomware targets industrial control systems

A new file-encrypting ransomware has come to light, leading many users to believe it is linked to Iran, which targets processes and files related to industrial control systems (ICS).

Snake ransomware

It is written in the Golang programming language and is called Snake. The ransomware has been used in targeted campaigns targeting businesses. According to SentinelLabs, which has been tracking attacks involving Snake for the past month, encrypted files from this ransomware are difficult to impossible to recover without paying the ransom demanded by the attackers.

Snake targets a wide range of files, but avoids encrypting system files and folders. However, before it starts encrypting them, it attempts to terminate processes associated with various types of programs, including system utilities and enterprise management tools.

Snake terminates a critical process for the GE Digital Proficy server, which enables connectivity to Proficy HMI/SCADA systems, manufacturing execution systems (MES), and Enterprise Manufacturing Intelligence (EMM) systems. Terminating this process could cause serious problems for operators.

“The damage that Snake can cause is significant,” says Dor Yardeni, head of OTORIO’s incident management team. “Deleting or locking down targeted ICS processes prevents production teams from accessing critical production-related processes, including analytics, configuration, and control.”.

Both OTORIO and SentinelOne pointed out that the ransom note from the creators of Snake instructs victims to contact the attackers at the email address “bapcocrypt@ctemplar.com” to purchase the decryption tool.

snake ransomware

“bapcocrypt” may be a reference to the Bahrain Petroleum Company (Bapco), which hackers recently targeted using a malware strain called Dustman. Dustman has been linked to Saudi Arabia’s National Cybersecurity Authority via ZeroCleare, a wiper that has been used to target energy and industrial organizations in the Middle East.

ZeroCleare has been linked to Iranian hacking groups, and experts believe the same groups are behind Snake. Although SentinelOne says that “there may be some connection between the Snake and Dustman attacks,” OTORIO believes that Snake may have been used in an attack against Bapco.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS