Kaspersky Lab Discovers Russian Hacker Infrastructure


russian hacking code

CSA Z462 Arc Flash Training - Electrical Safety Essentials

Our customized live online or in‑person group training can be delivered to your staff at your location.

  • Live Online
  • 6 hours Instructor-led
  • Group Training Available
Regular Price:
$249
Coupon Price:
$199
Reserve Your Seat Today

Crouching Yeti APT targets energy infrastructure with watering-hole attacks, compromising servers to steal credentials and stage intrusions; Kaspersky Lab links the Energetic Bear group to ICS threats across Russia, US, Europe, and Turkey.

 

Key Points

Crouching Yeti APT, aka Energetic Bear, is a threat group that targets energy firms using watering-hole attacks.

✅ Targets energy infrastructure via watering-hole compromises

✅ Uses open-source tools and backdoored sshd for persistence

✅ Scans global servers to stage intrusions and steal credentials

 

A hacker collective known for attacking industrial companies around the world have had some of their infrastructure identified by Russian security specialists.

Kaspersky Lab said that it has discovered a number of servers compromised by the group, belonging to different organisations based in Russia, the US, and Turkey, as well as European countries.

The Russian-speaking hackers, known as Crouching Yeti or Energetic Bear, mostly focus on energy facilities, as seen in reports of infiltration of the U.S. power grid targeting critical infrastructure, for the main purpose of stealing valuable data from victim systems.

 

Hacked servers

Crouching Yeti is described as an advanced persistent threat (APT) group that Kaspersky Lab has been tracking since 2010.

#google#

Kaspersky Lab said that the servers it has compromised are not just limited to industrial companies. The servers were hit in 2016 and 2017 with different intentions. Some were compromised to gain access to other resources or to be used as intermediaries to conduct attacks on other resources.

Others, including those hosting Russian websites, were used as watering holes.

It is a common tactic for Crouching Yeti to utilise watering hole attacks where the attackers inject websites with a link redirecting visitors to a malicious server.

“In the process of analysing infected servers, researchers identified numerous websites and servers used by organisations in Russia, US, Europe, Asia and Latin America that the attackers had scanned with various tools, possibly to find a server that could be used to establish a foothold for hosting the attackers’ tools and to subsequently develop an attack,” said the security specialists in a blog posting.

“The range of websites and servers that captured the attention of the intruders is extensive,” the firm said. “Kaspersky Lab researchers found that the attackers had scanned numerous websites of different types, including online stores and services, public organisations, NGOs, manufacturing, etc.

Kaspersky Lab said that the hackers used publicly available malicious tools, designed for analysing servers, and for seeking out and collecting information. The researchers also found a modified sshd file with a preinstalled backdoor. This was used to replace the original file and could be authorised with a ‘master password’.

“Crouching Yeti is a notorious Russian-speaking group that has been active for many years and is still successfully targeting industrial organisations through watering hole attacks, among other techniques,” explained Vladimir Dashchenko, head of vulnerability research group at Kaspersky Lab ICS CERT.

 

Russian government?

“Our findings show that the group compromised servers not only for establishing watering holes, but also for further scanning, and they actively used open-sourced tools that made it much harder to identify them afterwards,” he said.

“The group’s activities, such as initial data collection, the theft of authentication data, and the scanning of resources, are used to launch further attacks,” said Dashchenko. “The diversity of infected servers and scanned resources suggests the group may operate in the interests of the third parties.”

This may well tie into a similar conclusion from a rival security vendor.

In 2014 CrowdStrike claimed that the ‘Energetic Bear’ group was also tracked in Symantec's Dragonfly research and had been hacking foreign companies on behalf of the Russian state.

The security vendor had said the group had been carrying out attacks on foreign companies since 2012, with reports of breaches at U.S. power plants that underscored the campaign, and there was evidence that these operations were sanctioned by the Russian government.

Last month the United States for the first time publicly accused Russia in a condemnation of Russian grid hacking of attacks against the American power grid.

Symantec meanwhile warned last year of a resurgence in cyber attacks on European and US energy companies, including reports of access to U.S. utility control rooms that could result in widespread power outages.

And last July the UK’s National Cyber Security Centre (NCSC) acknowledged it was investigating a broad wave of attacks on companies in the British energy and manufacturing sectors.

 

Related News

Related News

UK Energy Industry Divided Over Free Electricity Debate

UK Free Electricity Debate weighs soaring energy prices against market regulation, renewables, and social equity, examining price caps, funding via windfall taxes, grid investment, and consumer protection in the UK's evolving energy policy landscape.

 

Key Points

A policy dispute over free power, balancing consumer relief with market stability, renewables, and investment.

✅ Pros: relief for households; boosts efficiency and green adoption.

✅ Cons: risks to market signals, quality, and grid investment.

✅ Policy options: price caps, windfall taxes, targeted subsidies.

 

In recent months, the debate over free electricity in the UK has intensified, revealing a divide within the energy sector. With soaring energy prices and economic pressures impacting consumers, the discussion around providing free electricity has gained traction. However, the idea has sparked significant controversy among industry stakeholders, each with their own perspectives on the feasibility and implications of such a move.

The Context of Rising Energy Costs

The push for free electricity is rooted in the UK’s ongoing energy crisis, exacerbated by geopolitical tensions, supply chain disruptions, and the lingering effects of the COVID-19 pandemic. As energy prices reached unprecedented levels, households faced the harsh reality of skyrocketing bills, prompting calls for government intervention to alleviate financial burdens.

Supporters of free electricity argue that it could serve as a vital lifeline for struggling families and businesses. The proposal suggests that by providing a certain amount of electricity for free, the government could help mitigate the effects of rising costs while encouraging energy conservation and efficiency.

Industry Perspectives

However, the notion of free electricity has not been universally embraced within the energy sector. Some industry leaders express concerns about the financial viability of such a scheme. They argue that providing free electricity could undermine the market dynamics that incentivize investment in infrastructure and renewable energy, in a market already exposed to natural gas price volatility today. Critics warn that if energy companies are forced to absorb costs, it could lead to diminished service quality and investment in necessary advancements.

Additionally, there are worries about how free electricity could be funded. Proponents suggest that a tax on energy companies could generate the necessary revenue, but opponents question whether this would stifle innovation and competition. The fear is that placing additional financial burdens on energy providers could ultimately lead to higher prices in the long run.

Renewable Energy and Sustainability

Another aspect of the debate centers around the UK’s commitment to transitioning to renewable energy sources. Supporters of free electricity emphasize that such a policy could encourage more widespread adoption of green technologies by making energy more accessible. They argue that by removing the financial barriers associated with energy costs, households would be more inclined to invest in solar panels, heat pumps, and other sustainable solutions.

On the other hand, skeptics contend that the focus should remain on ensuring a stable and reliable energy supply as the UK moves toward its climate goals. They caution against implementing policies that might disrupt the balance of the energy market, potentially hindering the necessary investments in renewable infrastructure.

Government's Role

As discussions unfold, the government’s role in this debate is crucial. Policymakers must navigate the complex landscape of energy regulation, market dynamics, and consumer needs. The government has already introduced measures aimed at assisting vulnerable households, such as energy price caps and direct financial support. However, the question remains whether these initiatives go far enough in addressing the root causes of the energy crisis.

In this context, the government faces pressure from both consumers demanding relief and industry leaders advocating for market stability, including proposals to end the link between gas and electricity prices to curb price volatility. The challenge lies in finding a middle ground that balances immediate support for households with long-term sustainability and investment in the energy sector.

Future Implications

The ongoing debate about free electricity in the UK underscores broader themes related to energy policy, market regulation, and social equity, with rising electricity prices abroad offering context for comparison. As the country navigates its energy transition, the decisions made today will have far-reaching implications for both consumers and the industry.

If the government chooses to pursue a model that includes free electricity, it will need to carefully consider how to implement such a system without jeopardizing the market. Transparency, stakeholder engagement, and thorough impact assessments will be essential to ensure that any new policies are sustainable and equitable.

Conversely, if the concept of free electricity is ultimately rejected, the focus will likely shift back to addressing energy costs through other means, such as enhancing energy efficiency programs or increasing support for vulnerable populations.

The divide within the UK’s energy industry regarding free electricity highlights the complexities of balancing consumer needs with market stability. As the energy crisis continues to unfold, the conversations surrounding this issue will remain at the forefront of public discourse. Ultimately, finding a solution that addresses the immediate challenges while promoting a sustainable energy future will be key to navigating this critical juncture in the UK’s energy landscape.

 

Related News

View more

Federal government spends $11.8M for smart grid technology in Sault Ste. Marie

Sault Ste. Marie Smart Grid Investment upgrades PUC Distribution infrastructure with federal funding, clean energy tech, outage reduction, customer insights, and reliability gains, creating 140 jobs and attracting industry to a resilient, efficient grid.

 

Key Points

A federally funded PUC Distribution project to modernize the citywide grid, cut outages, boost efficiency, and create jobs.

✅ $11.8M federal funding to PUC Distribution

✅ Citywide smart grid cuts outages and energy loss

✅ 140 jobs; attracts clean tech and industry

 

PUC Distribution Inc. in Sault Ste. Marie is receiving $11.8 million from the federal government to invest in infrastructure, as utilities nationwide have faced pandemic-related losses that underscore the need for resilient systems.

The MP for the riding, Terry Sheehan, made the announcement on Monday.

The money will go to the utility's smart grid project, where technologies like a centralized SCADA system can enhance situational awareness and control.

"This smart grid project offers a glimpse into our clean energy future and represents a new wave of economic activity for the region," Sheehan said.

"Along with job creation, new industries will be attracted to a modern grid, supported by stable electricity pricing that helps competitiveness, all while helping the environment."

His office says the investment will allow the utility to reduce outages, provide more information to customers to help make smarter electricity use choices, aligned with Ontario's energy-efficiency programs that encourage conservation, and offer more services.

"This is an innovative project that makes Sault Ste. Marie a leader," mayor Christian Provenzano said.

"We will be the first city in our country to implement a community-wide smart grid. Once it is complete, the smart grid will make our energy infrastructure more reliable, reduce energy loss and lead to a more innovative economy for our community."

The project will also create 140 new jobs.

"As a community-focused utility, we are always looking for innovative ways to help our customers save money amid concerns about hydro disconnections during winter, and reduce their carbon footprint," Rob Brewster, president and CEO of PUC Distribution said.

"The investment the government has made in our community will not only help modernize our city's electrical distribution system [as] once the project is complete, Sault Ste. Marie will have access to an electricity grid that can handle the growing demands of a city in the 21st century."

 

Related News

View more

After alert on Russian hacking, a renewed focus on protecting U.S. power grid

U.S. Power Grid Cybersecurity combats DHS-FBI flagged threats to energy infrastructure, with PJM Interconnection using ICS/SCADA segmentation, phishing defenses, incident response, and resilience exercises against Russia-linked attacks and pipeline intrusions.

 

Key Points

Strategies, controls, and training that protect U.S. electric infrastructure from cyber threats and disruptions.

✅ ICS/SCADA network segmentation and zero-trust architecture

✅ Employee phishing drills and incident response playbooks

✅ DOE-led grid exercises and threat intelligence sharing

 

The joint alert from the FBI and Department of Homeland Security last month warning that Russia was hacking into critical U.S. energy infrastructure, as outlined in six essential reads on Russian hacks from recent coverage, came as no surprise to the nation’s largest grid operator, PJM Interconnection.

“You will never stop people from trying to get into your systems. That isn’t even something we try to do.” said PJM Chief Information Officer, Tom O’Brien. “People will always try to get into your systems. The question is, what controls do you have to not allow them to penetrate? And how do you respond in the event they actually do get into your system?”

PJM is the regional transmission organization for 65 million people, covering 13 states, including Pennsylvania, and Washington D.C.

On a rainy day in early April, about 10 people were working inside PJM’s main control center, outside Philadelphia, closely monitoring floor-to-ceiling digital displays showing real-time information from the electric power sector throughout PJM’s territory in the mid-Atlantic and parts of the midwest, amid reports that hackers accessed control rooms at U.S. utilities.

#google#

Donnie Bielak, a reliability engineering manager, was overseeing things from his office, perched one floor up.

“This is a very large, orchestrated effort that goes unnoticed most of the time,” Bielak said. “That’s a good thing.”

But the industry certainly did take notice in late 2015 and early 2016, when hackers successfully disrupted power to the Ukrainian grid. The outages lasted a few hours and affected about 225,000 customers. It was the first publicly-known case of a cyber attack causing major disruptions to a power grid. It was widely blamed on Russia.

One of the many lessons of the Ukraine attacks was a reminder to people who work on critical infrastructure to keep an eye out for odd communications.

“A very large percentage of entry points to attacks are coming through emails,” O’Brien said. “That’s why PJM, as well as many others, have aggressive phishing campaigns. We’re training our employees.”

O’Brien doesn’t want to get into specifics about how PJM deals with cyber threats. But one common way to limit exposure is by having separate systems: For example, industrial controls in a power plant are not connected to corporate business networks, a separation underscored after breaches at U.S. power plants prompted reviews across the sector.

Since 2011, North American grid operators and government agencies have also done large, security exercises every two years. Thousands of people practice how they’d respond to a coordinated physical or cyber event, including rising substation attacks that highlight resilience gaps.

So far, nothing like that has happened in the U.S. It’s possible, but not likely, according to Robert M. Lee, a former military intelligence analyst, who runs the industrial cybersecurity firm Dragos.

“The more complex the system, the harder it is to have a scalable attack,” said Lee, who co-authored a report analyzing the Ukraine attacks. “If you wanted to take out a power generation station– that isn’t the most complex thing. Let’s say you cause an hour of outage. But now you want to cause two months of outages? That’s an exponential increase in effort required.”

For example, he said, it would very difficult for hackers to knock out power to the entire east coast for a long time. But briefly disrupting a major city is easier. That’s the sort of thing that keeps him up at night.

“I worry about an adversary getting into, maybe, Washington D.C.’s portion of the grid, taking down power for 30 minutes,” he said.

The Department of Energy is creating a new office focused on cybersecurity and emergency response, following the U.S. government’s condemnation of power grid hacking by Russia.

Deterrence may be one reason why there has not yet been a major attack on the U.S. grid, said John MacWilliams, a former senior DOE official who’s now a fellow at Columbia University’s Center on Global Energy Policy.

“That’s obviously an act of war,” he said. “We have the capability of responding either through cyber mechanisms or kinetic military.”

In the meantime, small-scale incidents keep happening.

This spring, another cyber attack targeted natural gas pipelines. Four companies shut down their computer systems, just in case, but they say no service was disrupted.

 

Related News

View more

Russian hackers had 'hundreds of victims' as they infiltrated U.S. power grid

Russian cyberattacks on U.S. power grid exposed DHS warnings: Dragonfly/Energetic Bear breached control rooms, ICS networks, and could trigger blackouts via switch manipulation, phishing, and malware, threatening critical infrastructure and utility operations nationwide.

 

Key Points

State-backed breaches of utility ICS and control rooms enabled potential switch manipulation and blackouts.

✅ DHS: Dragonfly/Energetic Bear breached utility networks

✅ Access reached control rooms and ICS for switch control

✅ Ongoing campaign via phishing, malware, lateral movement

 

Russian hackers for a state-sponsored organization invaded hundreds of control rooms of U.S. electric utilities that could have led to blackouts, a new report says.

The group, known as Dragonfly or Energetic Bear, infiltrated networks of U.S. utilities as part of an effort that is likely ongoing, Department of Homeland Security officials told the Wall Street Journal.

Jonathan Home, chief of industrial-control-system analysis for DHS, said the hackers “got to the point where they could have thrown switches” and upset power flows.

Although the agency did not disclose which companies were impacted, the officials at a briefing Monday said that there were “hundreds of victims” including breaches at power plants across the U.S., and that some companies may not be aware that hackers infiltrated their networks yet.

According to experts, Russia has been preparing for such attacks for some time now, prompting a renewed focus on protecting the grid among utilities and policymakers.

“They’ve been intruding into our networks and are positioning themselves for a limited or widespread attack,” said former Deputy Assistant Defense Secretary Michael Carpenter, now senior director at the Penn Biden Center at the University of Pennsylvania, per the Wall Street Journal. “They are waging a covert war on the West.”

Earlier this year, the Trump administration claimed Russia had staged a power grid hacking campaign against the U.S. energy grid and other U.S. infrastructure.

The report comes after President Trump told reporters last week during a joint press conference in Helsinki alongside Russian President Vladimir Putin that he had no reason not to believe the Russian leader's assurances to him that the Kremlin was not to blame for interference in the election.

Trump later admitted that he misspoke when he said he didn’t “see any reason why” Russia would have meddled in the 2016 election, and said he believes the U.S. intelligence community assessment that found that the Russian government did interfere in the electoral process.

 

Related News

View more

China, Cambodia agree to nuclear energy cooperation

Cambodia-CNNC Nuclear Energy MoU advances peaceful nuclear cooperation, human resources development, and Belt and Road ties, targeting energy security and applications in medicine, agriculture, and industry across ASEAN under IAEA-guided frameworks.

 

Key Points

A pact to expand peaceful nuclear tech and skills, boosting Cambodia's energy, healthcare under ASEAN and Belt and Road.

✅ Human resources development and training pipelines

✅ Peaceful nuclear applications in medicine, agriculture, industry

✅ Aligns with IAEA guidance, ASEAN links, Belt and Road goals

 

Cambodia has signed a memorandum of understanding with China National Nuclear Corporation (CNNC) on cooperation in the peaceful use of nuclear energy. The agreement calls for cooperation on human resources development.

The agreement was signed yesterday by CNNC chief accountant Li Jize and Tekreth Samrach, Cambodia's secretary of state of the Office of the Council of Ministers and vice chairman of the Cambodian Commission on Sustainable Development. It was signed during the 14th China-ASEAN Expo and China-ASEAN Business and Investment Summit, being held in Nanning, the capital of China's Guangxi province.

The signing was witnessed by Cambodia's minister of commerce and other government officials, CNNC said.

"This is another important initiative of China National Nuclear Corporation in implementing the 'One Belt, One Road' strategy as China's nuclear program continues to advance and strengthening cooperation with ASEAN countries in international production capacity, laying a solid foundation for follow-up cooperation between the two countries," CNNC said.

One Belt, One Road is China's project to link trade in about 60 Asian and European countries along a new Silk Road, even as Romania ended talks with a Chinese partner in a separate nuclear project.

CNNC noted that Cambodia's current power supply cannot meet its basic electricity needs, while sectors including medicine, agriculture and industry require a "comprehensive upgrade". It said Cambodia has great market potential for nuclear power and nuclear technology applications.

On 14 August, CNNC vice president Wang Jinfeng met with Tin Ponlok, secretary general of Cambodia's National Council for Sustainable Development, to consult on the draft MOU. Cambodia's Ministry of Environment said these discussions focused on human resources in nuclear power for industrial development and environmental protection.

In late August, CNNC president Qian Zhimin visited Cambodia and met Say Chhum, president of the Senate of Cambodia. Qian noted that CNNC will support Cambodia in applying nuclear technologies in industry, agriculture and medical science, thus developing its economy and improving the welfare of the population. Cambodia can start training workers, promoting new energy exploitation as India's nuclear revival progresses in Asia, and infrastructure construction, and increasing its capabilities in scientific research and industrial manufacturing, he said. This will help the country achieve its long-term goal of the peaceful use of nuclear energy, he added.

In November 2015, Russian state nuclear corporation Rosatom signed a nuclear cooperation agreement with Cambodia, focused on a possible research reactor, but with consideration of nuclear power, while KHNP in Bulgaria illustrates parallel developments in Europe. A further cooperation agreement was signed in March 2016, and in May Rosatom and the National Council for Sustainable Development signed memoranda to establish a nuclear energy information centre in Cambodia and set up a joint working group on the peaceful uses of atomic energy.

In mid-2016, Cambodia's Ministry of Industry, Mines and Energy held discussions with CNNC on building a nuclear power plant and establishing the regulatory and legal infrastructure for that, in collaboration with the International Atomic Energy Agency, mirroring IAEA assistance in Bangladesh on nuclear development.

 

Related News

View more

Power Outage Affects 13,000 in North Seattle

North Seattle Power Outage disrupts 13,000 in Ballard, Northgate, and Lake City as Seattle City Light crews repair equipment failures. Aging infrastructure, smart grid upgrades, microgrids, and emergency preparedness highlight resilience and reliability challenges.

 

Key Points

A major outage affecting 13,000 in North Seattle from equipment failures and aging grid, prompting repairs and planning.

✅ 13,000 customers in Ballard, Northgate, Lake City affected

✅ Cause: equipment failures and aging infrastructure

✅ Crews, smart grid upgrades, and preparedness improve resilience

 

On a recent Wednesday morning, a significant power outage struck a large area of North Seattle, affecting approximately 13,000 residents and businesses. This incident not only disrupted daily routines, as seen in a recent London outage, but also raised questions about infrastructure reliability and emergency preparedness in urban settings.

Overview of the Outage

The outage began around 9 a.m., with initial reports indicating that neighborhoods including Ballard, Northgate, and parts of Lake City were impacted. Utility company Seattle City Light quickly dispatched crews to identify the cause of the outage and restore power as soon as possible. By noon, the utility reported that repairs were underway, with crews working diligently to restore service to those affected.

Such outages can occur for various reasons, including severe weather, such as windstorm-related failures, equipment failure, or accidents involving utility poles. In this instance, the utility confirmed that a series of equipment failures contributed to the widespread disruption. The situation was exacerbated by the age of some infrastructure in the area, highlighting ongoing concerns about the need for modernization and upgrades.

Community Impact

The power outage caused significant disruptions for residents and local businesses. Many households faced challenges as their morning routines were interrupted—everything from preparing breakfast to working from home became more complicated without electricity. Schools in the affected areas also faced challenges, as some had to adjust their schedules and operations.

Local businesses, particularly those dependent on refrigeration and electronic payment systems, felt the immediate impact. Restaurants struggled to serve customers without power, while grocery stores dealt with potential food spoilage, leading to concerns about lost inventory and revenue. The outage underscored the vulnerability of businesses to infrastructure failures, as recent Toronto outages have shown, prompting discussions about contingency plans and backup systems.

Emergency Response

Seattle City Light’s swift response was crucial in minimizing the outage's impact. Utility crews worked through the day to restore power, and the company provided regular updates to the community, keeping residents informed about progress and estimated restoration times. This transparent communication was essential in alleviating some of the frustration among those affected, and contrasts with extended outages in Houston that heightened public concern.

Furthermore, the outage served as a reminder of the importance of emergency preparedness for both individuals and local governments, and of utility disaster planning that supports resilience. Many residents were left unprepared for an extended outage, prompting discussions about personal emergency kits, alternative power sources, and community resources available during such incidents. Local officials encouraged residents to stay informed about power outages and to have a plan in place for emergencies.

Broader Implications for Infrastructure

This incident highlights the broader challenges facing urban infrastructure. Many cities, including Seattle, are grappling with aging power grids that struggle to keep up with modern demands, and power failures can disrupt transit systems like the London Underground during peak hours. Experts suggest that regular assessments and updates to infrastructure are critical to ensuring reliability and resilience against both natural and human-made disruptions.

In response to increasing frequency and severity of power outages, including widespread windstorm outages in Quebec, there is a growing call for investment in modern technologies and infrastructure. Smart grid technology, for instance, can enhance monitoring and maintenance, allowing utilities to respond more effectively to outages. Additionally, renewable energy sources and microgrid systems could offer more resilience and reduce reliance on centralized power sources.

The recent power outage in North Seattle was a significant event that affected thousands of residents and businesses. While the immediate response by Seattle City Light was commendable, the incident raised important questions about infrastructure reliability and emergency preparedness. As cities continue to grow and evolve, the need for modernized power systems and improved contingency planning will be crucial to ensuring that communities can withstand future disruptions.

As residents reflect on this experience, it serves as a reminder of the interconnectedness of urban living and the critical importance of reliable infrastructure in maintaining daily life. With proactive measures, cities can work towards minimizing the impact of such outages and building a more resilient future for their communities.

 

Related News

View more

Sign Up for Electricity Forum’s Newsletter

Stay informed with our FREE Newsletter — get the latest news, breakthrough technologies, and expert insights, delivered straight to your inbox.

Electricity Today T&D Magazine Subscribe for FREE

Stay informed with the latest T&D policies and technologies.
  • Timely insights from industry experts
  • Practical solutions T&D engineers
  • Free access to every issue

Live Online & In-person Group Training

Advantages To Instructor-Led Training – Instructor-Led Course, Customized Training, Multiple Locations, Economical, CEU Credits, Course Discounts.

Request For Quotation

Whether you would prefer Live Online or In-Person instruction, our electrical training courses can be tailored to meet your company's specific requirements and delivered to your employees in one location or at various locations.