
Lately, it seems that malicious actors have been turning their ransomware to systems (ICS). According to security researchers, the creation of file-encrypting malware with the aim of infecting computer networks that control operations in manufacturing and utility environments is something that has only recently been observed.
As reported by Cyber-Security firm Dragos, the ransomware called Ekans (also known as Snake) first appeared in December 2019 and is designed to attack Windows used in industrial environments.
Of course, there have been some malware targeting ICS in the past. But the researchers concluded that Ekans appears to be the work of a government-sponsored criminal group involved in this space and that it represents “a unique and specific risk to industrial enterprises that has not been previously observed in ransomware malware operations.”
Researchers discovered that Ekans contains a list of commands and procedures related to various functions of the industrial control system that are intended to disrupt these functions.
The encrypted files are renamed to a random five-character file extension, while a ransom note appears with an email address to contact, to negotiate the amount with the victim.
The attackers behind Ekans likely need to infect the network before executing the ransomware attack. This follows the same process as ransomware variants such as Ryuk and Megacortex. Dragos reports also note that Ekans may be related to the Megacortex ransomware.
Some reports have linked Ekans to Iran, but after analyzing the malware, Dragos concluded that there is no “strong or undeniable evidence” linking this campaign to Iranian.
It is currently uncertain how Eksans is distributed to victims, but to protect them from ransomware attacks, it is recommended to isolate ICS systems from the rest of the network, so even if a standard Windows machine is compromised, an attacker will not be able to proceed to the systems that control the infrastructure.
Organizations should also ensure that they maintain backups that are stored offline. Backups should include the last known configuration data to ensure quick recovery.
