Three Ukrainian power companies came under attack by the Sandworm tool set after employees downloaded BlackEnergy3 malware packages. According to an investigation by Robert M. Lee, former U.S. Air Force cyber warfare operations officer and co-founder of Dragos Security, the infections started in spring of 2015.
Attackers engaged in a spear-phishing campaign using infected Word documents aimed at system administrators and IT staff at the facilities. The targets who opened the Word document saw a prompt asking them to click to “enable macros,” which installed the BlackEnergy3 malware. It is notable that macros had been in decline until the time of this attack, but were now on the rise.40 After the malware successfully installed, it began to scan around for paths to the supervisory control and data acquisition networks, SCADA, which would allow them to take control of the plant’s control systems.41 All of this would be exceptionally risky at many power plants, but it turned out the Ukrainian security was above average and even outclassed many U.S. facilities. The networks were all very well segregated via firewalls but the CYBER BEARS stole in anyway.42
One of the plant operators stated he saw the attackers control one of the computer terminals and successfully search for the panel that would control circuit breakers. The attacker began to take down the power grid in front of his eyes. Though he tried to take control of the computer it was too late. The attackers locked him out and continued its task of shutting down around thirty electrical substations.
After the breach, the attackers used an eraser program called “KillDisk,” which wiped out major sectors of files, corrupted master boot records, and essentially rendered the systems useless without taking them offline and replacing them. The attackers reconfigured the backup generators in a manner that disabled them so the repair crew had to tough it out in the dark.
To top this off, they didn’t do this just once, the attackers hit three power stations simultaneously belonging to the Ukrainian power company Kyivoblenergo in the Ivano-Frankivsk Region.43 They also struck Prykarpatyaoblenergo with an outage that affected 80,000, as well as the Chernivtsioblenergo station.44 In total, an estimated 225,000 people were affected for nearly six hours. The companies restored power by going back to manual control. Power had to be restored manually since many systems were fried by the “KillDisk” deletions.
To make all of this more complicated, a Telephone Denial-of-Service (TDoS) attack on the telephone system flooded the circuits with bogus calls, which prevented citizens from alerting the power companies about outages.
The Warsaw Stock Exchange aka The Cyber Caliphate False Flag Attack #1: October 24, 2014
After the website for the Warsaw Stock Exchange went offline for two hours, a Pastebin message screamed to the world, “Today, we HACKED Warsaw Stock Exchange!” and “To be continued! Allahu Akbar!” Authorities initially credited the Cyber Caliphate, a hacker group that claims its allegiance to ISIS and works in association with the United Cyber Caliphate groups. The message posted on Pastbin, an online bulletin board said the hack was in retaliation for Polish bombing of the “Islamic State.”45
Initially, many accepted that ISIS-affiliated hackers were responsible, but the techniques, tools, and more importantly digital footprints suggested the attackers came from Russia. This is old spycraft technique called a False Flag operation: A deception where one entity is blamed for the actions of another. The false flag cover didn’t last, as forensic analysts demonstrated that Russian hackers had posed as ISIS and let them take the blame.46 It was later revealed that the hackers stole details on investors and the stock exchange’s network, including credentials for authorization to access customer accounts.47
The TV5 Monde Attack, aka The Cyber Caliphate False Flag #2
On the evening of April 9, 2015 at 10:00 pm the French TV channel TV5 Monde experienced a cyberattack that resulted in the suspension of their broadcast, as hackers infiltrated their internal systems and social media profiles. First, the website crashed, then emails went down.48 Helene Zemmour, digital director for the station said it all went down in a “synchronized manner.” CNN reported, “Shortly after the beginning of the attack our internal computer system fell and other programs followed.”