Categories: Technology

Hackers Gain Entry Into U.S., European Energy Sector, Symantec Warns

Advanced hackers have targeted U.S. and European energy companies, in a cyber-espionage campaign that has in some cases successfully broken into the core-systems that control the companies’ operations, according to researchers at the security firm Symantec.

Malicious email campaigns have been used to gain entry into organizations in the U.S., Turkey and Switzerland, and likely other countries well, Symantec said in a report published on Wednesday.

The cyber attacks, which began in late 2015 but increased in frequency in April this year, are probably the work of a foreign government.

The attacks bear the hallmarks of a hacking group known as Dragonfly, Eric Chien, a cyber security researcher at Symantec, said in an interview.

The research adds to concerns that industrial firms, including power providers and other utilities are susceptible to cyber attacks that could be leveraged for destructive purposes in the event of a major geo-political conflict.

In June, the U.S. Government warned industrial firms about a hacking campaign targeting the nuclear and energy sectors, saying in an alert that hackers sent phishing emails to harvest credentials in order to gain access to targeted networks.

Chien said he believed that the alert likely referenced the same campaign Symantec has been tracking.

He said dozens of companies had been targeted and that a handful of them, including in the U.S., had been compromised on the operational level.

“That level of access meant that motivation was “the only step left” preventing “sabotage of the power grid,” Chien said.

However, other researchers cast some doubt on the findings.

“While concerning, the attacks were “far from the level of being able to turn off the lights, so there’s no alarmism needed,” said Robert M. Lee.

Lee is founder of U.S. critical infrastructure security firm Dragos Inc, who read the report.

Lee called the connection to Dragonfly “loose.”

Dragonfly was previously active from around to 2011 to 2014, when it appeared to go dormant after several cyber firms published research exposing its attacks.

The group, also known as Energetic Bear or Koala, was widely believed by security experts to be tied to the Russian government.

Symantec did not name Russia in its report but noted that the attackers used code strings that were in Russian.

Other codes used French, Symantec said, suggesting the attackers may be attempting to make it more difficult to identify them.

 

 

 

Source: The Guardian

Recent Posts

Ajuri Ngelale’s Resignation: A Strategic Exit From A Struggling Government?

By Kayode Adesiyan In a surprising turn of events, Ajuri Ngelale, Special Adviser to President…

4 hours ago

Top 10 Trending Stories In Nigeria Today

In today's fast-paced world, staying informed is more important than ever. Osun Defender, a leading…

4 hours ago

Lookman, Osimhen Score As Nigeria Beats Benin 3-0 In AFCON Qualifiers Opener

Ademola Lookman scored once in each half as the Super Eagles of Nigeria defeated Benin…

6 hours ago

“Tinubu Na Thief”: Nigerians React As OPay, PalmPay Announce New Transaction Charges

Nigerians have taken to social media particularly on Twitter to express outrage following an announcement…

7 hours ago

Adeleke’s Deputy Accused Of Sabotaging Sports In Osun

The Osun State Government may face a massive protest in the coming days from the…

9 hours ago

Speculations Fly On Ngelale’s Leave Of Absence

Chief Ajuri Ngelale, the Special Adviser to President Bola Tinubu on Media & Publicity, has…

10 hours ago

This website uses cookies.