During the World Economic Forum’s Annual Meeting of the New Champions, taking place this week in Tianjin, China, about 1,500 policy makers and experts from more than 90 countries are gathering to discuss Industry 4.0.
William Saito, Vice Chairman, Japan, for Palo Alto Networks, explains in his latest column for the World Economic Forum that the potential for Industry 4.0 — specifically how technologies such as cloud computing and big data join with the Internet of Things and algorithms from machine learning to govern new processes — requires preventive security by design, not as an add-on.
“It’s worth remembering,” notes William, “that cloud services, big data, IoT, block chain, AI, fin tech and all the other buzzwords are possible not only because of the Internet, but because of security.”
A recent, well-publicized attack on a Japanese business involved two malware families, PlugX and Elirks, that were found during the investigation. PlugX has been used in a number of attacks since first being discovered in 2012, and we have published several articles related to its use, including an analysis of an attack campaign targeting Japanese companies.
Elirks, less widely known than PlugX, is a basic backdoor Trojan, first discovered in 2010, that is primarily used to steal information from compromised systems. We mostly observe attacks using Elirks occurring in East Asia. One of the unique features of the malware is that it retrieves its C2 address by accessing a pre-determined microblog service or SNS. Attackers create accounts on those services and post encoded IP addresses or the domain names of real C2 servers in advance of distributing the backdoor. We have seen multiple Elirks variants using Japanese blog services for the last couple of years. Figure 1 shows embedded URL in an Elirks sample found in early 2016.
Figure 1 Embedded URLs in Elirks variant
In another sample found in 2014, an attacker used a Japanese blog service. The relevant account still exists at the time of writing this article (Figure 2).
Figure 2 Blog account created by the attacker in 2014
Link to previous attack campaign
Unit 42 previously identified an Elirks variant during our analysis of the attack campaign calledScarlet Mimic. It is years-long campaign targeting minority rights activists and governments. The malware primarily used in this series of attacks was FakeM. Our researchers described the threat sharing infrastructure with Elirks in the report.
As of this writing, we can note similarities between previously seen Elirks attacks and this recent case in Japan.
Spear Phishing Email with PDF attachment
Figure 3 shows an email which was sent to a ministry of Taiwan in May 2012.
Figure 3 Spear Phishing Email sent to a ministry of Taiwan
The email characteristics were bit similar to the recent case (Table 1).
2012
2016
Email Sender
Masquerades as an existing bank in Taiwan
Masquerade as an existing aviation company in Japan
Email Recipient
Representative email address of a ministry of Taiwan, which is publicly available.
Representative email address of a subsidiary company, which is publicly available.
Subject
“Bank credit card statement” in Chinese
“Airline E-Ticket” in Japanese
Attachment
PDF file named “Electronic Billing1015” in Chinese
File named “E-TKT” in Japanese with PDF icon
Table 1 Email characteristics
When a user opened the attached PDF file, the following message is displayed. It exploits a vulnerability in Adobe Flash, CVE-2012-0611 embedded in the PDF and installs Elirks malware on the system.
Figure 4 opening malicious PDF attachment
Airline E-Ticket
Attackers choose a suitable file name to lure targeted individual or organization. In the recent case, the malicious attachment name in the email was reported as “E-TKT”. We found similar file name in the previous attack in Taiwan in August 2012 (Figure 5).
Figure 5 Elirks executable file masquerade as folder of E-Ticket
When opening the file, Elirks executes itself on the computer and creates ticket.doc to deceive users (Figure 6).
Figure 6 doc file created by Elirks
We’ve also seen another file name related to aviation at Taiwan in March 2012. Figure 7 shows PDF file named “Airline Reservation Numbers (updated version).pdf”. When opening the PDF file, it displays the exactly same message with the Figure4, exploits CVE-2011-0611 and installs Elirks.
Figure 7 PDF named “Airline Reservation Number”
Conclusion
Currently, we have found no reliable evidence to indicate the same adversary attacked a company in Japan in 2016 and multiple organizations in Taiwan in 2012. However, we can see some resemblances between the two attacks. In both cases, attackers used the same malware family, crafted spear phishing emails in a similar manner, and seem to be interested in some areas related to aviation. We have been seeing multiple Elirks variants targeting Japan in the last few years, potentially indicating an ongoing cyber espionage campaign. We will keep an eye on the threat actors.
Palo Alto Networks customers are protected from Elirks variant and can gather additional information using the following tools:
WildFire detects all known Elirks samples as malicious
All known C2s are classified as malicious in PAN-DB
In this Lightboard session, Martin Walter explains how the integration of Palo Alto Networks global URL Filtering service (PAN-DB) works with the single-pass architecture of our next- generation firewalls and our Threat Intelligence Cloud to allow you to safely enable web access while protecting against malware or phishing sites.
In our Reference Blueprint for Industrial Control and SCADA, we describe the need to isolate remote communication technologies into a separate zone. Devices like iNets, unlicensed and licensed microwave, satellite, AMI meters and other forms of longer-range, radio-based communications need to be looked at carefully before being implemented and extra consideration of these types of technology is essential to preventing unintentional access into enterprise and OT systems.
Benefits of Remote Communication Technologies
With the advent of the Industrial Internet of Things (IIoT), or Industry 4.0, new highly efficient, low-energy and low-cost wide-area communication devices are continually being produced, providing more bandwidth and flexibility in deployment items deemed essential in an ICS/SCADA environment.
Improvements in communication technology not only make the possibility of remote automation doable but also attractive, if not a necessity. These advancements in communication help with automation, and make it possible to place more intelligent devices further out, and they reduce labor costs, as an army of people would no longer be required to travel to remote destinations, retrieve information and bring it back. Improved communications would allow operators to gather this information back to a single location, cutting many of the expenses associated with vehicle maintenance, gas and hourly wages.
Remote automation is not only cost-effective, dependable, and safe, it enables owner/operators to be competitive in several ways:
It helps improve the efficiency of the system, allowing for real-time, or near real-time, information at regular intervals.
It produces data for analytics, which helps improve system performance, increase efficiencies and produce higher yields in a product.
It increases visibility into our systems, allowing us to adjust as necessary.
There is, however, a downside to these innovations in communications for ICS/SCADA, which is the need for greater enforcement of security at remote locations.
Challenges of Remote Communication Technologies
Putting high-speed, high-bandwidth connections in remote unmanned areas makes them ideal beachhead attack points, and some areas can take hours to reach due to the remoteness and terrain, serving as an excellent foothold for an adversary because of the access to both enterprise and OT systems. The remoteness of the asset provides attackers with ample time to come and go as needed.
At remote facilities, it is possible for someone to install micro-computing devices that can be left in place and go unnoticed for months, if not years, if the physical placement of equipment and site layout goes unaudited for a long period of time. On-premise equipment could be reloaded with weaponized or malicious code and leveraged against the owner/operator’s internal systems, giving the ability to cause major disruptions.
Placing more intelligent devices further out at remote locations – devices with far more computing power than those previously used – can give attackers better internal resources with which to attack our systems.
Today’s broadband technology, in most cases, is some form of shared medium, meaning people with the right skill set and tools are capable of eavesdropping on others, making for insecure communications on systems that run critical real-time production.
One other key element many fail to consider when deploying communication technologies, such as satellite or microwave, is that many of these technologies are easy to remove and relocate. It is not uncommon for satellite dishes to go missing. Just think about what happens when the outdoor unit, dish and block upconverter (BUC), and the indoor unit (IDU) satellite modem go missing, and the relocation still shows online.
Another nefarious scenario is using these remote access points as an attack vector against a competitor or generating denial of service (DoS) attacks against others routed through the owner/operator’s network.
With all of these advances in communication technologies, older forms like frame relay or dedicated leased lines are no longer in use. If they are, they are very expensive to maintain. But older technologies, being point-to-point in nature, do provide slightly more security at remote facilities, unlike most of today’s Internet-based communication technologies, which is why greater attention much be paid to the security, both physical and cyber, of remote communication technologies.
Securing Remote Communication Technologies
Physical security at these locations is difficult to maintain due to their remoteness, but cybersecurity and ensuring the traffic coming in from a field site is only that which is required – and nothing more – is an achievable, sustainable objective.
At Palo Alto Networks® we believe in and follow the best practices of Zero Trust networking. In the Zero Trust networking model, it is highly advised that access to and from remote assets be set in an entirely separate zone, and that communications be restricted to only the applications, ports, and protocols needed for the process.
By following this tactic, a company can minimize its attack surface and limit possible exposure caused by breaches with their communications link. By zoning remote connections into a separate isolated enclave restricted by application and user ID, the field of focus is narrowed, providing better visibility into attempts to use the sites’ communications.
Unauthorized attempts to access the OT/IT networks would be painfully obvious in the logs, which would be seen as failed or dropped attempts at communication, especially if contact attempts are made with resources that the zone has no need to communicate with. This would be a clear indicator of compromise (IoC) from that device or facility.
Palo Alto Networks recently bagged the Next-Generation Firewall award category at NetworkWorld Asia’s Information Management Awards in Singapore. We won the same category last year, and are pleased at the consistent growth and recognition of our platform in this fast-growing region.
NetworkWorld Asia is one of the leading publications in the region that provides CIOs, CTOs, Head of IT, IT Directors and IT Managers with updates, perspectives, tips and guides on how to leverage leading-edge technologies, tools and strategies to achieve performance, cost savings and business success.
This particular award recognizes Asia’s leaders in Information Security, Storage and Data Management for the huge advanced made in these fields over the last few years. It is an honor!
KP Unnikrishan, Senior Marketing Director, Asia Pacific & Japan for Palo Alto Networks (left) receiving the award from Tan Hoon Chiang, CIO, National Institute of Education (right)
Victor Ng, South East Asia Editor in Chief (left) and Khoo Boo Leong, Senior Editor (Right) at Questex Media Group with KP Unnikrishnan