Kaspersky Lab Discovers Russian Hacker Infrastructure


russian hacking code

High Voltage Maintenance Training Online

Our customized live online or in‑person group training can be delivered to your staff at your location.

  • Live Online
  • 12 hours Instructor-led
  • Group Training Available
Regular Price:
$599
Coupon Price:
$499
Reserve Your Seat Today

Crouching Yeti APT targets energy infrastructure with watering-hole attacks, compromising servers to steal credentials and stage intrusions; Kaspersky Lab links the Energetic Bear group to ICS threats across Russia, US, Europe, and Turkey.

 

Key Points

Crouching Yeti APT, aka Energetic Bear, is a threat group that targets energy firms using watering-hole attacks.

✅ Targets energy infrastructure via watering-hole compromises

✅ Uses open-source tools and backdoored sshd for persistence

✅ Scans global servers to stage intrusions and steal credentials

 

A hacker collective known for attacking industrial companies around the world have had some of their infrastructure identified by Russian security specialists.

Kaspersky Lab said that it has discovered a number of servers compromised by the group, belonging to different organisations based in Russia, the US, and Turkey, as well as European countries.

The Russian-speaking hackers, known as Crouching Yeti or Energetic Bear, mostly focus on energy facilities, as seen in reports of infiltration of the U.S. power grid targeting critical infrastructure, for the main purpose of stealing valuable data from victim systems.

 

Hacked servers

Crouching Yeti is described as an advanced persistent threat (APT) group that Kaspersky Lab has been tracking since 2010.

#google#

Kaspersky Lab said that the servers it has compromised are not just limited to industrial companies. The servers were hit in 2016 and 2017 with different intentions. Some were compromised to gain access to other resources or to be used as intermediaries to conduct attacks on other resources.

Others, including those hosting Russian websites, were used as watering holes.

It is a common tactic for Crouching Yeti to utilise watering hole attacks where the attackers inject websites with a link redirecting visitors to a malicious server.

“In the process of analysing infected servers, researchers identified numerous websites and servers used by organisations in Russia, US, Europe, Asia and Latin America that the attackers had scanned with various tools, possibly to find a server that could be used to establish a foothold for hosting the attackers’ tools and to subsequently develop an attack,” said the security specialists in a blog posting.

“The range of websites and servers that captured the attention of the intruders is extensive,” the firm said. “Kaspersky Lab researchers found that the attackers had scanned numerous websites of different types, including online stores and services, public organisations, NGOs, manufacturing, etc.

Kaspersky Lab said that the hackers used publicly available malicious tools, designed for analysing servers, and for seeking out and collecting information. The researchers also found a modified sshd file with a preinstalled backdoor. This was used to replace the original file and could be authorised with a ‘master password’.

“Crouching Yeti is a notorious Russian-speaking group that has been active for many years and is still successfully targeting industrial organisations through watering hole attacks, among other techniques,” explained Vladimir Dashchenko, head of vulnerability research group at Kaspersky Lab ICS CERT.

 

Russian government?

“Our findings show that the group compromised servers not only for establishing watering holes, but also for further scanning, and they actively used open-sourced tools that made it much harder to identify them afterwards,” he said.

“The group’s activities, such as initial data collection, the theft of authentication data, and the scanning of resources, are used to launch further attacks,” said Dashchenko. “The diversity of infected servers and scanned resources suggests the group may operate in the interests of the third parties.”

This may well tie into a similar conclusion from a rival security vendor.

In 2014 CrowdStrike claimed that the ‘Energetic Bear’ group was also tracked in Symantec's Dragonfly research and had been hacking foreign companies on behalf of the Russian state.

The security vendor had said the group had been carrying out attacks on foreign companies since 2012, with reports of breaches at U.S. power plants that underscored the campaign, and there was evidence that these operations were sanctioned by the Russian government.

Last month the United States for the first time publicly accused Russia in a condemnation of Russian grid hacking of attacks against the American power grid.

Symantec meanwhile warned last year of a resurgence in cyber attacks on European and US energy companies, including reports of access to U.S. utility control rooms that could result in widespread power outages.

And last July the UK’s National Cyber Security Centre (NCSC) acknowledged it was investigating a broad wave of attacks on companies in the British energy and manufacturing sectors.

 

Related News

Related News

Illinois electric utility publishes online map of potential solar capacity

ComEd Hosting Capacity Map helps Illinois communities assess photovoltaic capacity, distributed energy resources, interconnection limits, and grid planning needs, guiding developers and policymakers on siting solar, net metering feasibility, and RPS-aligned deployment by circuit.

 

Key Points

An online tool showing circuit-level DER capacity, PV limits, and interconnection readiness across ComEd.

✅ Circuit-level estimates of solar hosting capacity

✅ Guides siting, interconnection, and net metering

✅ Supports RPS goals with grid planning insights

 

As the Illinois solar market grows from the Future Energy Jobs Act, the largest utility in the state has posted a planning tool to identify potential PV capacity in their service territory. ComEd, a Northern Illinois subsidiary of Exelon, has a hosting capacity website for its communities indicating how much photovoltaic capacity can be sited in given areas, based on the existing electrical infrastructure, as utilities pilot virtual power plant programs that leverage distributed resources.

According to ComEd’s description, “Hosting Capacity is an estimate of the amount of DER [distributed energy resources] that may be accommodated under current configurations at the overall circuit level without significant system upgrades to address adverse impacts to power quality or reliability.” This website will enable developers and local decision makers to estimate how much solar could be installed by township, sections and fractions of sections as small as ½ mile by ½ mile and to gauge EV charging impacts with NREL's projection tool for distribution planning. The map sections indicate potential capacity by AC kilowatts with a link to to ComEd’s recently upgraded Interconnection and Net Metering homepage.

The Hosting Map can provide insight into how much solar can be installed in which locations in order to help solar reach a significant portion of the Illinois Renewable Portfolio Standard (RPS) of 25% electricity from renewable sources by 2025, and to plan for transportation electrification as EV charging infrastructure scales across utility territories. For example, the 18 sections of Oak Park Township capacity range from 612 to 909 kW, and total 13,260 kW of photovoltaic power. That could potentially generate around 20 million kWh, and policy actions such as the CPUC-approved PG&E EV program illustrate how electrification initiatives may influence future demand. Oak Park, according to the PlanItGreen Report Card, a joint project of the Oak Park River Forest Community Foundation and Seven Generations Ahead, uses about 325 million kWh.

Based on ComEd’s Hosting Capacity, Oak Park could generate about 6% of its electricity from solar power located within its borders. Going significantly beyond this amount would likely require a combination of upgrades by ComEd’s infrastructure, potentially higher interconnection costs and deployment of technologies like energy storage solutions. What this does indicate is that a densely populated community like Oak Park would most likely have to get the majority of its solar and renewable electricity from outside its boundaries to reach the statewide RPS goal of 25%. The Hosting Capacity Map shows a considerable disparity among communities in ½ mile by ½ mile sections with some able to host only 100-200 kWs to some with capacities of over 3,000 kW.

 

Related News

View more

PG&E Supports Local Communities as It Pays More Than $230 Million in Property Taxes to 50 California Counties

PG&E property tax payments bolster counties, education, public safety, and infrastructure across Northern and Central California, reflecting semi-annual levies tied to utility assets, capital investments, and economic development that serve 16 million customers.

 

Key Points

PG&E property tax payments are semi-annual county taxes funding public services and linked to utility infrastructure.

✅ $230M paid for Jul-Dec 2017 across 50 California counties

✅ Estimated $461M for FY 2017-2018, up 12% year over year

✅ Investments: $5.9B in grid, Gas Safety Academy, control center

 

Pacific Gas and Electric Company (PG&E) paid property taxes of more than $230 million this fall to the 50 counties where the energy company owns property and operates gas and electric infrastructure that serves 16 million Californians. The tax payments help support essential public services like education and public health and safety actions across the region.

The semi-annual property tax payments made today cover the period from July 1 to December 31, 2017.

Total payments for the full tax year of July 1, 2017 to June 30, 2018 are estimated to total more than $461 million—an increase of $50 million, or 12 percent, compared with the prior fiscal year, even as customer rates are expected to stabilize in the years ahead.

“Property tax payments provide crucial resources to the many communities where we live and work, supporting everything from education to public safety. By continuing to make local investments in gas and electric infrastructure, we are not only creating one of the safest and most reliable energy systems in the country, including wildfire risk reduction programs and related efforts, we’re investing in the local economy and helping our communities thrive,” said Jason Wells, senior vice president and chief financial officer for PG&E.

PG&E invested more than $5.7 billion last year and expects to invest $5.9 billion this year to enhance and upgrade its gas and electrical infrastructure amid power line fire risks across Northern and Central California.

Some recent investments include the construction of PG&E’s $75 millionGas Safety Academy in Winters in Yolo County, which opened in September. Last year, PG&E opened a $36 million, state-of-the-art electric distribution control center in Rocklin.

PG&E supports the communities it serves in a variety of ways. In 2016, PG&E provided more than $28 million in charitable contributions to enrich local educational opportunities, preserve the environment, and support economic vitality and emergency preparedness and safety, including its Wildfire Assistance Program for impacted residents. PG&E employees provide thousands of hours of volunteer service in their local communities. The company also offers a broad spectrum of economic development services to help local businesses grow.

 

Related News

View more

Dutch produce more green electricity but target still a long way off

Netherlands renewable energy progress highlights rising wind energy and solar power output, delivering 17 billion kWh of green electricity from sustainable sources, yet trailing EU targets, with wind providing 60% and solar 34%.

 

Key Points

It is the country's growth in green electricity, led by wind and solar, yet short of EU targets at 13.8% of generation.

✅ 17 billion kWh green output; 13.8% of total generation

✅ Wind energy up 16% to 9.6 billion kWh; 60% of green power

✅ Solar power up about 13%; 34% of renewable production

 

The Netherlands is generating more electricity from sustainable sources as US renewable record 28% in April underscores broader momentum but is still far from reaching its targets, the national statistics office CBS said on Friday.

In total, the Netherlands produced 17 billion kilowatts of green energy last year, a rise of 10% on 2016. Sustainable sources now account for 13.8 per cent of energy generation, even as solar reshapes prices in Northern Europe across the region.

The biggest growth was in wind energy – up 16 per cent to 9.6 billion kWh – or the equivalent of energy for three million households. Wind energy now accounts for 60 per cent of green Dutch power. The amount of solar power, which accounts for 34% of green energy production, rose almost 13 per cent, and Dutch solar outpaces Canada according to recent reports.

In January, European statistics agency Eurostat said the Netherlands is near the bottom of a new table on renewable energy use in Europe. The EU has a target of a fifth of all energy use from green sources by 2020 and – while some countries have reached their own targets, including Germany's 50% clean power milestones – the Dutch, French and Irish need to increase their rates by at least 6%, Eurostat said, and Ireland has set green electricity goals for the next four years to close the gap.

 

Related News

View more

Coal CEO blasts federal agency's decision on power grid

FERC Rejects Trump Coal Plan, denying subsidies for coal-fired and nuclear plants as energy policy shifts toward natural gas and renewables, citing no grid reliability threat and warning about electricity prices and market impacts.

 

Key Points

FERC unanimously rejected subsidies for coal and nuclear plants, finding no grid reliability risk from retirements.

✅ Unanimous FERC vote rejects coal and nuclear compensation

✅ Cites no threat to grid reliability from plant retirements

✅ Opponents warned subsidies would distort power markets and prices

 

A decision by an independent energy agency to reject the Trump administration’s electricity pricing plan to bolster the coal industry could lead to more closures of coal-fired power plants and the loss of thousands of jobs, a top coal executive said Tuesday.

Robert Murray, CEO of Ohio-based Murray Energy Corp., called the action by the Federal Energy Regulatory Commission “a bureaucratic cop-out” that will raise the cost of electricity and jeopardize the reliability and security of the nation’s electric grid.

“While FERC commissioners sit on their hands and refuse to take the action directed by Energy Secretary Rick Perry and President Donald Trump, the decommissioning of more coal-fired and nuclear plants could result, further jeopardizing the reliability, resiliency and security of America’s electric power grids,” Murray said. “It will also raise the cost of electricity for all Americans.”

The five-member energy commission voted unanimously Monday to reject Trump’s plan to reward nuclear and coal-fired power plants for adding reliability to the nation’s power grid. The plan would have made the plants eligible for billions of dollars in government subsidies and help reverse a tide of bankruptcies and loss of market share suffered by the once-dominant coal industry as utilities' shift to natural gas and renewable energy continues.

The Republican-controlled commission said there’s no evidence that any past or planned retirements of coal-fired power plants pose a threat to reliability of the nation’s electric grid.

Murray disputed that and said the recent cold snap that hit the East Coast showed coal’s value, as power users in the Southeast were asked to cut back on electricity usage because of a shortage of natural gas. “If it were not for the electricity generated by our nation’s coal-fired and nuclear power plants, we would be experiencing massive brownouts risk and blackouts in this country,” he said.

Murray Energy is the largest privately owned coal company in the United States, with mining operations in Ohio, Illinois, Kentucky, Utah and West Virginia. Robert Murray, a Trump friend and political supporter, has been pushing hard for federal assistance for his industry. The Associated Press reported last year that Murray asked the Trump administration to issue an emergency order protecting coal-fired power plants from closing. Murray warned that failure to act could cause thousands of coal miners to be laid off and force his largest customer, Ohio-based FirstEnergy Solutions, into bankruptcy.

Perry ultimately rejected Murray’s request, but later asked energy regulators to boost coal and nuclear plants as the administration moved to replace the Clean Power Plan with a more limited approach.

The plan drew widespread opposition from business and environmental groups that frequently disagree with each other, even as some coal and business interests backed the EPA's Affordable Clean Energy rule in court.

Jack Gerard, president and CEO of the American Petroleum Institute, said Tuesday that the Trump plan was “far too narrow” in its focus on power sources that maintain a 90-day fuel supply.

API, the largest lobbying group for oil and gas industry, supports coal and other energy sources, Gerard said, “but we should not put our eggs in an individual basket defined as a 90-day fuel supply (while) unnecessarily intervening in private markets.”

 

Related News

View more

China, Cambodia agree to nuclear energy cooperation

Cambodia-CNNC Nuclear Energy MoU advances peaceful nuclear cooperation, human resources development, and Belt and Road ties, targeting energy security and applications in medicine, agriculture, and industry across ASEAN under IAEA-guided frameworks.

 

Key Points

A pact to expand peaceful nuclear tech and skills, boosting Cambodia's energy, healthcare under ASEAN and Belt and Road.

✅ Human resources development and training pipelines

✅ Peaceful nuclear applications in medicine, agriculture, industry

✅ Aligns with IAEA guidance, ASEAN links, Belt and Road goals

 

Cambodia has signed a memorandum of understanding with China National Nuclear Corporation (CNNC) on cooperation in the peaceful use of nuclear energy. The agreement calls for cooperation on human resources development.

The agreement was signed yesterday by CNNC chief accountant Li Jize and Tekreth Samrach, Cambodia's secretary of state of the Office of the Council of Ministers and vice chairman of the Cambodian Commission on Sustainable Development. It was signed during the 14th China-ASEAN Expo and China-ASEAN Business and Investment Summit, being held in Nanning, the capital of China's Guangxi province.

The signing was witnessed by Cambodia's minister of commerce and other government officials, CNNC said.

"This is another important initiative of China National Nuclear Corporation in implementing the 'One Belt, One Road' strategy as China's nuclear program continues to advance and strengthening cooperation with ASEAN countries in international production capacity, laying a solid foundation for follow-up cooperation between the two countries," CNNC said.

One Belt, One Road is China's project to link trade in about 60 Asian and European countries along a new Silk Road, even as Romania ended talks with a Chinese partner in a separate nuclear project.

CNNC noted that Cambodia's current power supply cannot meet its basic electricity needs, while sectors including medicine, agriculture and industry require a "comprehensive upgrade". It said Cambodia has great market potential for nuclear power and nuclear technology applications.

On 14 August, CNNC vice president Wang Jinfeng met with Tin Ponlok, secretary general of Cambodia's National Council for Sustainable Development, to consult on the draft MOU. Cambodia's Ministry of Environment said these discussions focused on human resources in nuclear power for industrial development and environmental protection.

In late August, CNNC president Qian Zhimin visited Cambodia and met Say Chhum, president of the Senate of Cambodia. Qian noted that CNNC will support Cambodia in applying nuclear technologies in industry, agriculture and medical science, thus developing its economy and improving the welfare of the population. Cambodia can start training workers, promoting new energy exploitation as India's nuclear revival progresses in Asia, and infrastructure construction, and increasing its capabilities in scientific research and industrial manufacturing, he said. This will help the country achieve its long-term goal of the peaceful use of nuclear energy, he added.

In November 2015, Russian state nuclear corporation Rosatom signed a nuclear cooperation agreement with Cambodia, focused on a possible research reactor, but with consideration of nuclear power, while KHNP in Bulgaria illustrates parallel developments in Europe. A further cooperation agreement was signed in March 2016, and in May Rosatom and the National Council for Sustainable Development signed memoranda to establish a nuclear energy information centre in Cambodia and set up a joint working group on the peaceful uses of atomic energy.

In mid-2016, Cambodia's Ministry of Industry, Mines and Energy held discussions with CNNC on building a nuclear power plant and establishing the regulatory and legal infrastructure for that, in collaboration with the International Atomic Energy Agency, mirroring IAEA assistance in Bangladesh on nuclear development.

 

Related News

View more

Electricity distributors warn excess solar power in network could cause blackouts, damage infrastructure

Australian Rooftop Solar Grid Constraints are driving debates over voltage rise, export limits, inverter curtailment, DER integration, and network reliability, amid concerns about localized blackouts, infrastructure protection, tariff reform, and battery storage adoption.

 

Key Points

Limits on solar exports to curb voltage rise, protect equipment, and keep the distribution grid reliable.

✅ Voltage rise triggers transformer protection and local outages.

✅ Export limits and smart inverter curtailment manage midday backfeed.

✅ Tariff reform and DER orchestration defer costly network upgrades.

 

With almost 1.8 million Australian homes and businesses relying on power from rooftop solar panels, there is a fight brewing over the impact of solar energy on the national electricity grid.

Electricity distributors are warning that as solar uptake continues to increase, there is a risk excess solar power could flow into the network, elevating power outage risks, causing blackouts and damaging infrastructure.

But is it the network businesses that are actually at risk, as customers turn away from centrally produced electricity?

This is what three different parties have to say:

Andrew Dillon of the network industry peak body, Energy Networks Australia (ENA), told 7.30 the way customers are charged for electricity has to change, or expensive grid upgrades to poles and wires will be needed to keep solar customers on the grid.

"The engineering reality is once we get too much solar in a certain space it does start to cause technical issues," he said.

"If there is too much energy coming back up the system in the middle of the day, it can cause frequency voltage disturbances in the system, which can lead to transformers tripping off to protect themselves from being damaged and that will cause localised blackouts.

"There are pockets of the grid already where we have significant penetration and we are starting to see technical issues."

However, he acknowledges that excess solar power has yet to cause any blackouts, or damage electricity infrastructure.

"I don't buy that at all," he said.

"It can be that in some suburbs or parts of suburbs a high penetration of solar on the point of use can raise voltage, these issues generally can be dealt with quickly.

"The critical issue is think where you are getting that perspective from. It is from an industry whose underlying market is threatened by customers doing it for themselves through peer-to-peer energy models. So, think with some critical insight to these claims."

He said when too many people rely on solar it threatens the very business model of the companies that own Australia's poles and wires.

"When the customers use the network less to buy centrally produced electricity, they ship less product," he said.

"When they ship less product, their underlying business is undermined, they need to charge more to the customers left and that leads to what has been called a death spiral.

"We are seeing rapid reductions in consumption at the point of use per household."

But Mr Dillon denies the distributors are acting out of self-interest.

"I absolutely reject that claim," he said.

"[What] we, as networks, have an interest in is running a safe network, running a reliable network, enabling the transition to a low carbon future and doing all that while keeping costs down as much as possible."

Solar installers say the networks are holding back business

Around Australia the poles and wires companies can decide which solar systems can connect to the grid.

Small systems can connect automatically, but in some areas, those wanting a larger system can find themselves caught up in red tape.

The vice-president of the Australian Solar Council, Glen Morris, said these limitations were holding back solar installation businesses and preventing the take-up of new battery storage technology.

"If you've already got a five kilowatt system, your house is full as far as the network is concerned," Mr Morris said.

"You go to add a battery, that's another five kilowatts and so they say no you're already full … so you can't add storage to your solar system."

The powers that be are stumbling in the dark to prevent a looming energy crisis, as the grid seeks to balance renewables' hidden challenges and competing demands.

Mr Morris also said the networks had the capacity to solve the problem of any excess solar flows into the grid, and infrastructure upgrades were not necessary.

"They already have the capability to turn off your solar invertor whenever they feel like it," he said.

"If they choose to connect that functionality, it's there in the inverter. The customer already has it."

ENA has acknowledged there is frustration with rooftop system size limits in the solar industry.

"What we are seeing is solar installers and others slightly frustrated at different requirements for different networks and sometimes they are unclear on the reasons for that," Mr Dillon said.

"Limitations are in place across the country to keep the lights on and make sure the network stays safe and we don't have sudden rushes of people connecting to the grid that causes outage issues."

But Mr Mountain is unconvinced, calling the limitations "somewhat spurious".

"The published, documented, critically reviewed analyses are few and far between, so it is very easy for engineers to make these arguments and those in policy circles only have so much tolerance for the detail," he said.

 

Related News

View more

Sign Up for Electricity Forum’s Newsletter

Stay informed with our FREE Newsletter — get the latest news, breakthrough technologies, and expert insights, delivered straight to your inbox.

Electricity Today T&D Magazine Subscribe for FREE

Stay informed with the latest T&D policies and technologies.
  • Timely insights from industry experts
  • Practical solutions T&D engineers
  • Free access to every issue

Live Online & In-person Group Training

Advantages To Instructor-Led Training – Instructor-Led Course, Customized Training, Multiple Locations, Economical, CEU Credits, Course Discounts.

Request For Quotation

Whether you would prefer Live Online or In-Person instruction, our electrical training courses can be tailored to meet your company's specific requirements and delivered to your employees in one location or at various locations.