HomeSecurityExperts warn: We don't know if we can protect ourselves from PIPEDREAM...

Experts warn: We don't know if we can protect ourselves from PIPEDREAM malware

The world's most advanced industrial malware, PIPEDREAM, could be lurking within critical infrastructure control systems, ready to unleash its "war capabilities", a management consultancy has warned.

PIPE DREAM

In a paper published this week, global business consulting firm Ankura Consulting Group said that a worrying aspect of PIPEDREAM, developed by the Russian team Chernovite, is its immunity to patching.

"This new-age malware is so dangerous because, to neutralize the threat, you have to patch the entire system rather than just patching the software vulnerability, a feat that is much more costly, impractical, and time-consuming.".

In a recent report, industrial cybersecurity firm Dragos said that the emergence of PIPEDREAM amounts to “a significant escalation of capabilities” for hacking groups targeting Industrial Control Systems (ICS).

“PIPEDREAM is the first reusable, cross-industry capability that leverages native functionality across industrial protocols and a wide variety of devices,” the company wrote.

Pipedream was first detected in early 2022, and Ankura said that while there were no known implementations of the malware, that doesn't mean it doesn't pose a risk.

"The malware could still be lurking on ICS devices waiting to be executed, or newer, more dangerous versions could be in development. If PIPEDREAM or malware with similar capabilities were deployed on a country 's critical infrastructure , it could lead to power outages , inaccessible water systems, dangerous conditions at nuclear sites, and more."

In February, Politico reported that Dragos CEO Robert M. Lee said Chernovite had attempted to use PIPEDREAM to destroy “about a dozen” American power and liquefied natural gas facilities in 2022.

In her post this week, Ankura stated that there is sufficient evidence to “strongly suggest” that the group behind PIPEDREAM is funded by Russia.

Events in early 2022, including “the conjunctural timing of Russia of Ukraine, its posture vis-à-vis Europe and North America, and the White House’s early warning of the risk of disruptive Russian cyberattacks, help seal their connection to PIPEDREAM,” it said.

In February of this year, amid concerns about threats posed by PIPEDREAM and other malware, members of the House Homeland Security Committee asked the Department of Homeland Security and the Cybersecurity and Infrastructure Security Agency to provide information on potential cyberattacks that domestic terrorists could launch against U.S. energy infrastructure.

Experts warn: We don't know if we can protect ourselves from PIPEDREAM malware

Lee has previously noted that PIPEDREAM represents just the seventh piece of ICS-specific malware that security researchers have discovered so far, which is “extremely capable and worth paying attention to” due to its adaptability .

PIPEDREAM was developed to target protocols to two specific programmable logic controllers (PLCs) manufactured by Schneider Electric and OMRON, both of which are primarily used in the energy sector.

Ankura warns, however, that even small modifications can make PIPEDREAM adaptable to a much wider range of PLCs with different protocol languages. Because these controllers are prevalent in many other critical infrastructure sectors, the potential threat from PIPEDREAM goes far beyond energy suppliers.

“Future malware with the extensive capabilities shown in the PIPEDREAM toolkit poses a risk to all critical industries, including power grids, factories, utilities, and oil,” says Ankura.

Source of information: scmagazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS