{"id":1482,"date":"2022-06-30T17:05:00","date_gmt":"2022-06-30T10:05:00","guid":{"rendered":"https:\/\/dt-corp.com.vn\/?p=1482"},"modified":"2022-06-30T17:05:00","modified_gmt":"2022-06-30T10:05:00","slug":"behind-the-news-cyberattack-forces-iranian-state-owned-steel-plant-to-stop-production","status":"publish","type":"post","link":"https:\/\/dt-corp.com.vn\/?p=1482","title":{"rendered":"Behind the News: Cyberattack forces Iranian state-owned steel plant to stop production!"},"content":{"rendered":"<p>With the constant increase of cyber attacks on Industrial entities and Critical infrastructures, it\u2019s clear industry sectors around the world are susceptible to a variety of attacks, and last Monday (June 27, 2022) it happened in a steel plant in Iran- as part of the escalating cyber warfare tensions worldwide. Attacks on industrial infrastructure have been continuous in the Middle East.\u00a0 During the past year we witnessed cyber attacks on petrol stations, camera systems\u00a0 in Iran, and last week an attack on local \u201calert systems\u201d in Israel.<\/p>\n<p>One of Iran\u2019s major steel companies claimed it was forced to halt production after being hit by a cyberattack, making it one of the biggest assaults on the country\u2019s strategic industrial sector in recent years.<\/p>\n<p>The state-owned Khuzestan Steel Company, which is currently under U.S. sanctions, said experts had determined the plant had to stop work until further notice \u201cdue to technical problems\u201d following \u201ccyberattacks.\u201d\u00a0 So far the company has not blamed any specific group for the alleged attack.<\/p>\n<p>In Twitter, the hacking gang named Gonjeshke Darande, which has claimed responsibility for previous attacks on Iranian infrastructure has subsequently posted a video on Twitter, stating that it had hacked Khuzestan as well as two other steel plants. The gang continued and published not only a video of the machine explosion, but also pictures of the HMI (the user interface or dashboard that connects a person to a machine, system, or device), as well as a picture of the network<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-4159\" src=\"https:\/\/www.radiflow.com\/wp-content\/uploads\/Screenshot-167-300x240.png\" sizes=\"auto, (max-width: 691px) 100vw, 691px\" srcset=\"https:\/\/www.radiflow.com\/wp-content\/uploads\/Screenshot-167-300x240.png 300w, https:\/\/www.radiflow.com\/wp-content\/uploads\/Screenshot-167-1024x819.png 1024w, https:\/\/www.radiflow.com\/wp-content\/uploads\/Screenshot-167-768x615.png 768w, https:\/\/www.radiflow.com\/wp-content\/uploads\/Screenshot-167.png 1141w\" alt=\"\" width=\"691\" height=\"553\" \/><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-4161\" src=\"https:\/\/www.radiflow.com\/wp-content\/uploads\/Screenshot-168-1-300x146.png\" sizes=\"auto, (max-width: 781px) 100vw, 781px\" srcset=\"https:\/\/www.radiflow.com\/wp-content\/uploads\/Screenshot-168-1-300x146.png 300w, https:\/\/www.radiflow.com\/wp-content\/uploads\/Screenshot-168-1-1024x499.png 1024w, https:\/\/www.radiflow.com\/wp-content\/uploads\/Screenshot-168-1-768x375.png 768w, https:\/\/www.radiflow.com\/wp-content\/uploads\/Screenshot-168-1.png 1466w\" alt=\"\" width=\"781\" height=\"380\" \/><\/p>\n<p>[Twitter source \u2013 https:\/\/bit.ly\/3HYVInd].<\/p>\n<p>&nbsp;<\/p>\n<p>Our Radiflow experts and analysts shared a few insights about this incident.<\/p>\n<p>For one, the intrusion vector is still unknown so we don\u2019t know which vulnerability was exploited to gain access. It\u2019s important to mention (although we see this over and over again), most OT infrastructures are not well segmented, neither protected well enough from connected IT networks\/environments.\u00a0 In addition to that, outdated\/unpatched operating systems of OT servers and workstations of SCADA and DCS environments combined with the lack of IDS (intrusion detection systems) which can detect early signs of suspicious activity, contributes to easy adversarial lateral movement within the plant.<\/p>\n<p>Even in the event that the attackers do obtain access, it\u2019s still not an easy task to execute an attack. They need to have a domain expert, so they can create the desired effect, in the desired time and place (like was shown in the footage- assuming it is authentic).<\/p>\n<p>Another issue worth pointing out is the relation between the attack on the ICS and the attack on the plant CCTV systems. The breach and further full control over the CCTV cameras allowed hackers to achieve a number of goals \u2013 validate and control the physical effects, exfiltrate the footage and post it later as a proof for demonstration purposes and show the vulnerability not only of OT environments but of physical security systems as well.<\/p>\n<p>Lastly, and important to mention, is network visibility.\u00a0 This is critical for the attackers, as well as for the defender\/s. The network diagram posted by the hacking group shows that the knowledge of network connectivity and its vulnerabilities is playing a critical role for hacking activities and more than that for defensive operations.<\/p>\n<p>Radiflow is expecting for further exploitation of critical infrastructure and strategic manufacturing facilities worldwide by various hacking groups from various reasons therefore proper and correct implementation of various cyber security tools for industrial environments which include OT network visibility, intrusion detection, virtual breach-attack-simulation and in general risk management is a vital part of organizations\u2019 strategy in strengthening their cybersecurity posture.<\/p>\n<p>[source \u2013\u00a0<a role=\"link\" href=\"https:\/\/abcn.ws\/3ORbrqN\">https:\/\/abcn.ws\/3ORbrqN<\/a>]<\/p>\n","protected":false},"excerpt":{"rendered":"<p class=\"tx-excerpt\">With the constant increase of cyber attacks on Industrial entities and Critical infrastructures, it\u2019s clear industry sectors around the world are susceptible to a variety of attacks, and last Monday (June 27, 2022)","protected":false},"author":3,"featured_media":1483,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[13],"tags":[],"class_list":["post-1482","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/dt-corp.com.vn\/wp-content\/uploads\/2022\/06\/AP19129338484369-640x400-1.jpg","_links":{"self":[{"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/posts\/1482","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1482"}],"version-history":[{"count":1,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/posts\/1482\/revisions"}],"predecessor-version":[{"id":1484,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/posts\/1482\/revisions\/1484"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/media\/1483"}],"wp:attachment":[{"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1482"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1482"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1482"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}