Microsoft has highlighted the need for security of operational technology (OT) devices exposed to the internet, following a series of cyberattacks targeting such environments since late 2023 .

“Repeated attacks against OT devices highlight the imperative need to strengthen the security of these devices to avoid turning critical systems into easy targets,” said the Microsoft Threat Intelligence team.
See more: Microsoft Office: Pirated versions distribute malware
The company said that a cyberattack on an OT system could allow malicious actors to tamper with critical parameters used in industrial processes. This could happen either through the programming of the programmable logic controller (PLC) or through the use of the graphical controls of the human-machine interface (HMI). The result would be system malfunctions and outages.
It was also reported that OT systems often lack adequate security mechanisms, making them vulnerable to adversary attacks that are “relatively easy to execute.” The situation is further exacerbated by the additional risks posed by directly connecting OT devices to the internet.
This not only makes devices detectable by hackers through online scanning tools, but also turns them into weapons to gain initial access, exploiting weak passwords or outdated software with known vulnerabilities.
Just last week, Rockwell Automation issued an advisory urging its customers to disconnect all industrial control systems (ICS) that are not intended to connect to the public internet, due to heightened geopolitical tensions and heightened cyber activity worldwide.
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory warning of pro-Russian hacktivists targeting vulnerable industrial control systems in North America and Europe.
“Specifically, these hacktivists manipulated the HMIs, leading to an overshoot of normal operating parameters for the water pumps,” the agency said. “In each case, the hacktivists maximized setpoints, modified other parameters, disabled alarm mechanisms, and changed administrative passwords, thereby locking out WWS operators.”.
Microsoft reported that the start of the Israel-Hamas war in October 2023 caused a surge in cyberattacks on incorrectly insured OT assets of Israeli companies that were exposed online. Many of these attacks were carried out by groups such as Cyber Av3ngers, Soldiers of Solomon, and Abnaa Al-Saada, which are linked to Iran.
According to Redmond, the attacks targeted OT equipment deployed in various sectors in Israel, manufactured by both international suppliers and local manufacturers with facilities in other countries.
Read more: Russian Cyber Army claims cyberattack on Bulgarian port infrastructure company
These OT devices are mostly internet-exposed systems with inadequate security. They often come with weak passwords and known vulnerabilities, the tech giant said.
To mitigate the risks from such threats, organizations should ensure the security of their OT systems. This includes reducing the attack surface and implementing zero-trust practices to prevent hackers from moving laterally within a compromised network.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The development came after security firm OT Claroty uncovered a devastating strain of malware, Fuxnet. The Blackjack hacking group, allegedly backed by Ukraine, reportedly used it against Moscollector, a Russian company that operates an extensive sensor network to monitor Moscow’s groundwater and sewage systems, as well as emergency detection and response systems.
BlackJack, which shared details of the attack early last month, described Fuxnet as “Stuxnet on steroids.” Claroty noted that the malware was likely deployed remotely to target sensor gateways, using protocols such as SSH or the Sensor Blocking Protocol (SBK) over port 4321.
Fuxnet has the ability to irreversibly destroy the file system, prevent access to the device, and destroy NAND memory chips by continuously writing to the memory, rendering it unusable.
Furthermore, it is designed to rewrite the UBI volume to prevent sensor reboots and eventually destroy the sensors themselves by sending a flood of false Meter-Bus (M-Bus) messages.
“ Hackers developed malware that targeted the gateways, deleting file systems and directories, disabling remote access and routing services for each device, rewriting flash memory, destroying chips and UBI volumes, and causing other actions that further disrupted the operation of these gateways,” Clarotti noted.
According to data published by Russian cybersecurity firm Kaspersky earlier this week, the internet, email clients, and removable storage devices emerged as the top sources of threats to computers in an organization's OT infrastructure in the first quarter of 2024.

See also: Microsoft: North Korean hackers Moonstone Sleet linked to new ransomware FakePenny
“Malicious actors use scripts for a variety of purposes: gathering information, monitoring, redirecting browsers to malicious websites, and uploading various types of malware (spyware and/or silent cryptocurrency mining tools) to the user’s system or browser,” he said. “These are spread via the internet and emails.”
Source: thehackernews
