Over the past few days we have witnessed an extraordinary increase in high-profile cyber attacks on multinational manufacturing corporations and critical infrastructure providers.
This time on the top of media headlines were Honda and the ENEL Group.
According to MalwareBytes‘ analysis, both incidents were targeted attacks using EKANS/SNAKE ransomware, which at least in Honda case caused various business disruptions including disruption to production line operations.
One of the interesting pieces of evidence found in this case was publicly exposed Remote Desktop Protocol (RDP) access, which revealed internal domains on both attacked organizations’ networks. The same domains were found in malware samples which were uploaded to Internet virus analytics services.
It should be noted that attacks by this ransomware family are becoming more and more frequent in manufacturing and other sectors.
[inject id=’code-47fd23f73a9caecab1e206306adae7f9′]
Behind the news
Although most enterprises are experiencing economic slowdown, hacking activity against industrial organizations is constantly increasing. Specifically, such attacks can be attributed to organizations’ efforts to open their networks to external access for remote working, which in many cases this was done without installing proper cybersecurity measures. This can dramatically increase the threats not only to IT, but also to OT networks.
In addition, multinational enterprises should install additional measures to:
Finally, cyber-risk management processes for core/critical industrial operations in ICS environments should be made an organic part of the CISO/Chief Risk Officer’s responsibility.
Harmonizing risk and consequence strategies across IT and OT environments for greater cyber resilience
Strengthening OT Resilience: Protecting Critical Systems in a Rapidly Evolving Threat Environment
Quarterly ICS Security Report 2024 Q3