Oil & Gas

Industry

Sasser Worm Infection in Process Control System.

January 1, 2004

WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.

read more

Worm attack on Drilling Control system

January 1, 2004

WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.

read more

Safety Instrumented System Disabled by Triton Malware

August 1, 2017

Triton, which has been called the Worlds 1st murderous malware was discovered in 2017. In December 2017, it was reported that the safety systems of an unidentified petrochemical plant in Saudi Arabia were compromised when the Triconex industrial safety technology made by Schneider Electric SE was targeted in what is believed to have been a state sponsored attack. The computer security company Symantec claimed that the malware, known as “Triton”, exploited a vulnerability in computers running the Microsoft Windows operating system. The intention of Triton was to disable the safety instrumented systems, thus earning the name of the 1st murderous malware.

read more

30,000 Hard drives wiped by virus

January 1, 2013

Saudi Arabia’s national oil company, Aramco, said that a cyber attack damaged approximately, 30,000 computers. The attack was aimed at stopping oil and gas production in Saudi Arabia. The company shut down its main internal network for more than a week. The computer virus, Shamoon, spread through Amarco’s network and wiped computers’ hard drives clean. Fortunately, the damage was limited to office computers and didn’t affect control systems software that would impact technical operations.

read more

Advantech Hit By Ransomware

November 19, 2020

Ransomware attack hit Taiwan-based Advantech Co. in November, 2020 and the hackers sought 750 bitcoin or $13.8 million in exchange for the decryption key.

read more

Natural Gas Compression Facility Spearfishing

February 18, 2020

CISA responded to a cyberattack affecting control and communication assets on the operational technology (OT) network of a natural gas compression facility. A cyber threat actor used a Spearphishing Link [T1192] to obtain initial access to the organization’s information technology (IT) network before pivoting to its OT network. The threat actor then deployed commodity ransomware to Encrypt Data for Impact [T1486] on both networks. Specific assets experiencing a Loss of Availability [T826] on the OT network included human machine interfaces (HMIs), data historians, and polling servers. Impacted assets were no longer able to read and aggregate real-time operational data reported from low-level OT devices, resulting in a partial Loss of View [T829] for human operators. The attack did not impact any programmable logic controllers (PLCs) and at no point did the victim lose control of operations. Although the victim’s emergency response plan did not specifically consider cyberattacks, the decision was made to implement a deliberate and controlled shutdown to operations. This lasted approximately two days, resulting in a Loss of Productivity and Revenue [T828], after which normal operations resumed. CISA is providing this Alert to help administrators and network defenders protect their organizations against this and similar ransomware attacks.

read more

INA Group Cyber Attack

February 14, 2020

A notice on the company website states: “The INA Group is under cyber-attack, which began around 10 pm on February 14, 2020, causing problems in the operation of certain IT systems, which can occasionally affect normal operation, such as issuing mobile phone vouchers, electronic vignettes, paying utility bills.”

read more