On October 20th, 2019, authorities in India confirmed that one of its nuclear power plants had been hacked. The malware attack on the Kudankulam Nuclear Power Plant (KKNPP), first noticed on September 4th, has since been attributed to the North Korean state-sponsored threat group known as Lazarus.
While the malware did not target critical control systems--instead infecting a network used for administrative purposes--the attack highlights the potential for a catastrophic attack.
Malware variant that opens doors to future cyber-attacks
The malware used in the KKNPP attack, Dtrack (which was also used to propagate the WannaCry ransomware attacks in 2017), is a monitoring and intelligence gathering tool that scans networks and systems for potential vulnerabilities that can be exploited. In this way, Lazarus was able to open a doorway into the KKNPP network. This could make an attack easier going forward by establishing a “persistent presence on the nuclear power plant’s networks”.
Once embedded, Dtrack can quickly take advantage of the slightest gap or blind spot in security defenses, such as non-secure ports; unpatched or out-of-date systems; or new, unmanaged IoT devices. All of these pose significant cybersecurity risks in the utilities sector.
It’s little wonder that a former analyst who initially discovered and flagged the attack to India’s National Cyber Security Coordinator called the attack a “casus belli”--an “act of war”.
Limitations of regulated security controls in utilities sector exposed
Critical National Infrastructures, such as nuclear power plants, are required to comply with stringent cybersecurity requirements to protect against cyber-attacks. Yet, their controls typically encompass critical systems and networks associated with safety-related functions and secondary functions considered “important-to-safety”.