Kaspersky Lab Discovers Russian Hacker Infrastructure


russian hacking code

NFPA 70e Training

Our customized live online or in‑person group training can be delivered to your staff at your location.

  • Live Online
  • 6 hours Instructor-led
  • Group Training Available
Regular Price:
$199
Coupon Price:
$149
Reserve Your Seat Today

Crouching Yeti APT targets energy infrastructure with watering-hole attacks, compromising servers to steal credentials and stage intrusions; Kaspersky Lab links the Energetic Bear group to ICS threats across Russia, US, Europe, and Turkey.

 

Key Points

Crouching Yeti APT, aka Energetic Bear, is a threat group that targets energy firms using watering-hole attacks.

✅ Targets energy infrastructure via watering-hole compromises

✅ Uses open-source tools and backdoored sshd for persistence

✅ Scans global servers to stage intrusions and steal credentials

 

A hacker collective known for attacking industrial companies around the world have had some of their infrastructure identified by Russian security specialists.

Kaspersky Lab said that it has discovered a number of servers compromised by the group, belonging to different organisations based in Russia, the US, and Turkey, as well as European countries.

The Russian-speaking hackers, known as Crouching Yeti or Energetic Bear, mostly focus on energy facilities, as seen in reports of infiltration of the U.S. power grid targeting critical infrastructure, for the main purpose of stealing valuable data from victim systems.

 

Hacked servers

Crouching Yeti is described as an advanced persistent threat (APT) group that Kaspersky Lab has been tracking since 2010.

#google#

Kaspersky Lab said that the servers it has compromised are not just limited to industrial companies. The servers were hit in 2016 and 2017 with different intentions. Some were compromised to gain access to other resources or to be used as intermediaries to conduct attacks on other resources.

Others, including those hosting Russian websites, were used as watering holes.

It is a common tactic for Crouching Yeti to utilise watering hole attacks where the attackers inject websites with a link redirecting visitors to a malicious server.

“In the process of analysing infected servers, researchers identified numerous websites and servers used by organisations in Russia, US, Europe, Asia and Latin America that the attackers had scanned with various tools, possibly to find a server that could be used to establish a foothold for hosting the attackers’ tools and to subsequently develop an attack,” said the security specialists in a blog posting.

“The range of websites and servers that captured the attention of the intruders is extensive,” the firm said. “Kaspersky Lab researchers found that the attackers had scanned numerous websites of different types, including online stores and services, public organisations, NGOs, manufacturing, etc.

Kaspersky Lab said that the hackers used publicly available malicious tools, designed for analysing servers, and for seeking out and collecting information. The researchers also found a modified sshd file with a preinstalled backdoor. This was used to replace the original file and could be authorised with a ‘master password’.

“Crouching Yeti is a notorious Russian-speaking group that has been active for many years and is still successfully targeting industrial organisations through watering hole attacks, among other techniques,” explained Vladimir Dashchenko, head of vulnerability research group at Kaspersky Lab ICS CERT.

 

Russian government?

“Our findings show that the group compromised servers not only for establishing watering holes, but also for further scanning, and they actively used open-sourced tools that made it much harder to identify them afterwards,” he said.

“The group’s activities, such as initial data collection, the theft of authentication data, and the scanning of resources, are used to launch further attacks,” said Dashchenko. “The diversity of infected servers and scanned resources suggests the group may operate in the interests of the third parties.”

This may well tie into a similar conclusion from a rival security vendor.

In 2014 CrowdStrike claimed that the ‘Energetic Bear’ group was also tracked in Symantec's Dragonfly research and had been hacking foreign companies on behalf of the Russian state.

The security vendor had said the group had been carrying out attacks on foreign companies since 2012, with reports of breaches at U.S. power plants that underscored the campaign, and there was evidence that these operations were sanctioned by the Russian government.

Last month the United States for the first time publicly accused Russia in a condemnation of Russian grid hacking of attacks against the American power grid.

Symantec meanwhile warned last year of a resurgence in cyber attacks on European and US energy companies, including reports of access to U.S. utility control rooms that could result in widespread power outages.

And last July the UK’s National Cyber Security Centre (NCSC) acknowledged it was investigating a broad wave of attacks on companies in the British energy and manufacturing sectors.

 

Related News

Related News

Despite delays, BC Hydro says crews responded well to 'atypical' storm

BC Hydro Ice Storm Response to Fraser Valley power outages highlights freezing rain impacts, round the clock crews, infrastructure challenges, and climate change risks across the Lower Mainland during winter weather and restoration efforts.

 

Key Points

A plan for freezing rain events that prioritizes safety, rapid repairs, and clear communication to restore power.

✅ Prioritizes hazards, critical loads, and public safety first

✅ Deploys crews, contractors, and equipment across affected areas

✅ Addresses climate risks without costly undergrounding expansion

 

Call it the straw that broke the llama's back.

The loss of power during recent Fraser Valley ice storms meant Jennifer Quick, who lives on a Mission farm, had no running water, couldn't cook with appliances and still had to tend to a daughter sick with stomach flu.

As if that wasn't enough, she had to endure the sight of her shivering llamas.

"I brought them outside at one point and when I brought them back in, they had icicles on their fur," she said, adding the animals stayed in the warmth of their barn from then on.

For three and a half days, Quick and her family were among more than 160,000 BC Hydro customers in the Fraser Valley left in the dark after ice storms whipped through the region.

BC Hydro expects to get all customers back online Tuesday, five days after the storm hit.

And with another storm possibly on the horizon, the utility is defending its response to the treacherous weather, noting that windstorm power outages can be widespread.

BC Hydro spokesperson Mora Scott said the utility has a "best in class" storm response system, similar to PG&E winter storm prep in the U.S.

"In a typical storm situation we normally have 95 per cent of our customers back up within 24 hours. Ice storms are different and obviously this was an atypical storm for us," she said.

Scott said that in this case, the utility got power back on for 75 per cent of customers within 24 hours. It took the work of 450 employees called in from around B.C., working around the clock, a mobilization echoed by Sudbury Hydro crews after a storm, she said.

The work was complicated by trees falling near crews, icy roads, low visibility and even substations so frozen over the ice had to be melted off with blowtorches.

She said that in the long term, BC Hydro has no plans to make changes to how it responds to extreme ice storms or how infrastructure is built.

"Seeing ice build up in the Lower Mainland like this is a rare event," she said. "So to build for extremes like that probably doesn't make a lot of sense."

 

Climate change will bring storms

But CBC meteorologist Johanna Wagstaffe said that might not always be the case as climate change continues to impact our planet.

"The less severe winter events, like light snowfall, will happen less often," she said. "But the disruptive events — like last week's storm — will actually happen more often and we are already seeing this shift happen."

Marc Eliesen, a former CEO of BC Hydro in the early 1990s, said the utility needs to keep that in mind when planning for worst-case scenarios.

"This [storm] is a condition characteristic of the weather in the east, particularly in Ontario and Quebec, where freezing rain outages in Quebec are more common, which is organized to deal with freezing rain and heavy snow on the lines," he said. "This is a new phenomenon for British Columbia."

Eliesen questions whether BC Hydro has adequate equipment and crew training to deal with ice storms if they become more frequent, pointing to Hydro One storm restoration in Ontario as a comparison.

 

'Always something we can learn'

Scott disagrees with some of Eliesen's points.

She said some of the crews called in to deal with the recent storm come from northern B.C. and the Interior and have plenty of experience with snow.

"There's always something we can learn in every major storm situation," she said.

The idea of putting power lines underground was raised by some CBC readers and listeners, but Scott said running underground lines is five to 10 times the cost of running lines on pole, so it is done sparingly. Besides, equipment like substations and transmission lines need to be kept aboveground.

Meanwhile, Wagstaffe said that beginning Thursday, wintry weather could return to the Lower Mainland.

 

Related News

View more

German Energy Demand Hits Historic Low Amid Economic Stagnation

Germany Energy Demand Decline reflects economic stagnation, IEA forecasts, and the Energiewende, as industrial output slips and efficiency gains, renewables growth, and cost-cutting reduce fossil fuel use while reshaping sustainability and energy security.

 

Key Points

A projected 7% drop in German energy use driven by industrial slowdown, efficiency gains, and renewables expansion.

✅ IEA projects up to 7% demand drop in the next year

✅ Industrial slowdown and efficiency programs cut consumption

✅ Energiewende shifts mix to wind, solar, and less fossil fuel

 

Germany is on the verge of experiencing a significant decline in energy demand, with forecasts suggesting that usage could hit a record low as the country grapples with economic stagnation. This shift highlights not only the immediate impacts of sluggish economic growth but also broader trends in energy consumption, Europe's electricity markets, sustainability, and the transition to renewable resources.

Recent data indicate that Germany's economy is facing substantial challenges, including high inflation and reduced industrial output. As companies struggle to maintain profitability amid nearly doubled power prices and rising costs, many have begun to cut back on energy consumption. This retrenchment is particularly pronounced in energy-intensive sectors such as manufacturing and chemical production, which are crucial to Germany's export-driven economy.

The International Energy Agency (IEA) has projected that German energy demand could decline by as much as 7% in the coming year, a stark contrast to the trends seen in previous decades. This decline is primarily driven by a combination of factors, including reduced industrial activity, increased energy efficiency measures, and a shift toward alternative energy sources, as well as mounting pressures on local utilities to stay solvent. The current economic landscape has led businesses to prioritize cost-cutting measures, including energy efficiency initiatives aimed at reducing consumption.

In the context of these developments, Germany’s energy transition—known as the "Energiewende"—is becoming increasingly significant. The country has made substantial investments in renewable energy sources such as wind, solar, and biomass in recent years. As energy efficiency improves and the share of renewables in the energy mix rises, traditional fossil fuel consumption has begun to wane. This transition is seen as both a response to climate change and a strategy for energy independence, particularly in light of geopolitical tensions and Europe's wake-up call to ditch fossil fuels across the continent.

However, the current stagnation presents a paradox for the German energy sector. While lower energy demand may ease some pressures on supply and prices, it also raises concerns about the long-term viability of investments in renewable energy infrastructure, even as debates continue over electricity subsidies for industry to support competitiveness. The economic slowdown has the potential to derail progress made in reducing carbon emissions and achieving energy targets, particularly if it leads to decreased investment in green technologies.

Another layer to this issue is the potential impact on employment within the energy sector. As energy demand decreases, there may be a ripple effect on jobs tied to traditional energy production and even in renewable energy sectors if investment slows. Policymakers are now tasked with balancing the immediate need for economic recovery, illustrated by the 200 billion-euro energy price shield, with the longer-term goal of achieving sustainability and energy security.

The effects of the stagnation are also being felt in the residential sector. As households face increased living costs and rising heating and electricity costs, many are becoming more conscious of their energy consumption. Initiatives to improve home energy efficiency, such as better insulation and energy-efficient appliances, are gaining traction among consumers looking to reduce their utility bills. This shift toward energy conservation aligns with broader national goals of reducing overall energy consumption and carbon emissions.

Despite the challenges, there is a silver lining. The current situation offers an opportunity for Germany to reassess its energy strategies and invest in technologies that promote sustainability while also addressing economic concerns. This could include increasing support for research and development in green technologies, enhancing energy efficiency programs, and incentivizing businesses to adopt cleaner energy practices.

Furthermore, Germany’s experience may serve as a case study for other nations grappling with similar issues. As economies around the world face the dual pressures of recovery and sustainability, the lessons learned from Germany’s current energy landscape could inform strategies for balancing these often conflicting priorities.

In conclusion, Germany is poised to witness a historic decline in energy demand as economic stagnation takes hold. While this trend poses challenges for the energy sector and economic growth, it also highlights the importance of sustainability and energy efficiency in shaping the future. As the nation navigates this complex landscape, the focus will need to be on fostering innovation and investment that aligns with both immediate economic needs and long-term environmental goals. The path forward will require a careful balancing act, but with the right strategies, Germany can emerge as a leader in sustainable energy practices even in challenging times.

 

Related News

View more

Electricity sales in the U.S. actually dropped over the past 7 years

US Electricity Sales Decline amid population growth and GDP gains, as DOE links reduced per capita consumption to energy efficiency, warmer winters, appliances, and bulbs, while hotter summers and rising AC demand may offset savings.

 

Key Points

US electricity sales fell 3% since 2010 despite population and GDP growth, driven by efficiency gains and warmer winters.

✅ DOE links drops to efficiency and warmer winters

✅ Per capita residential use fell about 7% since 2010

✅ Rising AC demand may offset winter heating savings

 

Since 2010, the United States has grown by 17 million people, and the gross domestic product (GDP) has increased by $3.6 trillion. Yet in that same time span, electricity sales in the United States actually declined by 3%, according to data released by the U.S. Department of Energy (DOE), even as electricity prices rose at a 41-year pace nationwide.

The U.S. decline in electricity sales is remarkable given that the U.S. population increased by 5.8% in that same time span. This means that per capita electricity use fell even more than that; indeed, the Department of Energy pegs residential electricity sales per capita as having declined by 7%, even as inflation-adjusted residential bills rose 5% in 2022 nationwide.

There are likely multiple reasons for this decline in electricity sales. Department of Energy analysts suggest that, at least in part, it is due to increased adoption of energy-efficient appliances and bulbs, like compact fluorescents. Indeed, the DOE notes that there is a correlation between consumer spending on “energy efficiency” and a reduction in per capita electricity sales, while utilities invest more in delivery infrastructure to modernize the grid.

Yet the DOE also notes that states with a greater increase in warm weather days had a corresponding decrease in electricity sales, as milder weather can reduce power demand across years. In southern states, the effect was most dramatic: for instance, from 2010 to 2016, Florida had a 56% decrease in cold weather days that would require heating and as a result, saw a 9% decrease in per capita electricity sales.

The moral is that warm winters save on electricity. But if global temperatures continue to rise, and summers become hotter, too, this decrease in winter heating spending may be offset by the increased need to run air conditioning in the summer, and given how electricity and natural gas prices interact, overall energy costs could shift. Indeed, it takes far more energy to cool a room than it does to heat it, for reasons related to the basic laws of thermodynamics. 

 

Related News

View more

Why Is Georgia Importing So Much Electricity?

Georgia Electricity Imports October 2017 surged as hydropower output fell and thermal power plants underperformed; ESCO balanced demand via low-cost imports, mainly from Azerbaijan, amid rising tariffs, kWh consumption growth, and a widening generation-consumption gap.

 

Key Points

They mark a record import surge due to costly local generation, lower hydropower, ESCO balancing costs, and rising demand.

✅ Imports rose 832% YoY to 157 mln kWh, mainly from Azerbaijan

✅ TPP output fell despite capacity; only low-tariff plants ran

✅ Balancing price 13.8 tetri/kWh signaled costly domestic PPAs

 

In October 2017, Georgian power plants generated 828 mln. KWh of electricity, marginally up (+0.79%) compared to September. Following the traditional seasonal pattern and amid European concerns over dispatchable power shortages affecting markets, the share of electricity produced by renewable sources declined to 71% of total generation (87% in September), while thermal power generation’s share increased, accounting for 29% of total generation (compared to 13% in September). When we compare last October’s total generation with the total generation of October 2016, however, we observe an 8.7% decrease in total generation (in October 2016, total generation was 907 mln. kWh). The overall decline in generation with respect to the previous year is due to a simultaneous decline in both thermal power and hydro power generation. 

Consumption of electricity on the local market in the same period was 949 mln. kWh (+7% compared to October 2016, and +3% with respect to September 2017), and reflected global trends such as India's electricity growth in recent years. The gap between consumption and generation increased to 121 mln. kWh (15% of the amount generated in October), up from 100 mln. kWh in September. Even more importantly, the situation was radically different with respect to the prior year, when generation exceeded consumption.

The import figure for October was by far the highest from the last 12 years (since ESCO was established), occurring as Ukraine electricity exports resumed regionally, highlighting wider cross-border dynamics. In October 2017, Georgia imported 157 mln. kWh of electricity (for 5.2 ¢/kWh – 13 tetri/kWh). This constituted an 832% increase compared to October 2016, and is about 50% larger than the second largest import figure (104.2 mln. kWh in October 2014). Most of the October 2017 imports (99.6%) came from Azerbaijan, with the remaining 0.04% coming from Russia.

The main question that comes to mind when observing these statistics is: why did Georgia import so much? One might argue that this is just the result of a bad year for hydropower generation and increased demand. This argument, however, is not fully convincing. While it is true that hydropower generation declined and demand increased, the country’s excess demand could have been easily satisfied by its existing thermal power plants, even as imported coal volumes rose in regional markets. Instead of increasing, however, the electricity coming from thermal power plants declined as well. Therefore, that cannot be the reason, and another must be found. The first that comes to mind is that importing electricity may have been cheaper than buying it from local TPPs, or from other generators selling electricity to ESCO under power purchase agreements (PPAs). We can test the first part of this hypothesis by comparing the average price of imported electricity to the price ceiling on the tariff that TPPs can charge for the electricity they sell. Looking at the trade statistics from Geostat, the average price for imported electricity in October 2017 remained stable with respect to the same month of the previous year, at 5.2 ¢ (13 tetri) per kWh. Only two thermal power plants (Gardabani and Mtkvari) had a price ceiling below 13 tetri per kWh. Observing the electricity balance of Georgia, we see that indeed more than 98% of the electricity generated by TPPs in October 2017 was generated by those two power plants.

What about other potential sources of electricity amid Central Asia's power shortages at the time? To answer this question, we can use the information derived from the weighted average price of balancing electricity. Why balancing electricity? Because it allows us to reconstruct the costs the market operator (ESCO) faced during the month of October to make sure demand and supply were balanced, and it allows us to gain an insight about the price of electricity sold through PPAs.

ESCO reports that the weighted average price of balancing electricity in October 2017 was 13.8 tetri/kWh, (25% higher than in October 2016, when it was below the average weighted cost of imports – 11 vs. 13 – and when the quantity of imported electricity was substantially smaller). Knowing that in October 2017, 61% of balancing electricity came from imports, while 39% came from hydropower and wind power plants selling electricity to ESCO under their PPAs, we can deduce that in this case, internal generation was (on average) also substantially more expensive than imports. Therefore, the high cost of internally generated electricity, rather than the technical impossibility of generating enough electricity to satisfy electricity demand, indeed appears to be one the main reasons why electricity imports spiked in October 2017.

 

Related News

View more

Four Major Types of Substation Integration Service Providers Account for More than $1 Billion in Annual Revenues

Substation Automation Services help electric utilities modernize through integration, EPC engineering, protective relaying, communications and security, with CAPEX and OPEX insights and a growing global market for third-party providers worldwide rapidly.

 

Key Points

Engineering, integration, and EPC support modernizing utility substations with protection, control, and secure communications

✅ Third-party engineering, EPC, and OEM services for utilities

✅ Integration of multi-vendor devices and platforms

✅ Focus on relays, communications, security, CAPEX-OPEX

 

The Newton-Evans Research Company has released additional findings from its newly published four volume research series entitled: The World Market for Substation Automation and Integration Programs in Electric Utilities: 2017-2020.

This report series has observed four major types of professional third-party service providers that assist electric utilities with substation modernization. These firms range from (1) smaller local or regional engineering consultancies with substation engineering resources to (2) major global participants in EPC work, to (3) the engineering services units of manufacturers of substation devices and platforms, to (4) substation integration specialist firms that source and integrate devices from multiple manufacturers for utility and industrial clients, and often provide substation automation training to support implementation.

2016 Global Share Estimates for Professional Services Providers of Electric Power Substation Integration and Automation Activities

The North American market report (Volume One) includes survey participation from 65 large and midsize US and Canadian electric utilities while the international market report (Volume Two) includes survey participation from 32 unique utilities in 20 countries around the world. In addition to the baseline survey questions, the report includes 2017 substation survey findings on four additional specific topics: communications issues; protective relaying trends; security topics and the CAPEX/OPEX outlook for substation modernization.

Volume Three is the detailed market synopsis and global outlook for substation automation and integration:

Section One of the report provides top-level views of substation modernization, automation & integration and the emerging digital grid landscape, and a narrative market synopsis.

Section Two provides mid-year 2017 estimates of population, electric power generation capacity, transmission substations, including the 2 GW UK substation commissioning as a benchmark, and primary MV distribution substations for more than 120 countries in eight world regions. Information on substation related expenditures and spending for protection and control for each major world region and several major countries is also provided.

Section Three provides information on NGO funding resources for substation modernization among developing nations.

Section Four of this report volume includes North American market share estimates for 2016 shipments of many substation automation-related devices and equipment, such as trends in the digital relay market for utilities.

The Supplier Profiles report (Volume Four) provides descriptive information on the substation modernization offerings of more than 90 product and services companies, covering leading players in the transformer market as well.

 

Related News

View more

China, Cambodia agree to nuclear energy cooperation

Cambodia-CNNC Nuclear Energy MoU advances peaceful nuclear cooperation, human resources development, and Belt and Road ties, targeting energy security and applications in medicine, agriculture, and industry across ASEAN under IAEA-guided frameworks.

 

Key Points

A pact to expand peaceful nuclear tech and skills, boosting Cambodia's energy, healthcare under ASEAN and Belt and Road.

✅ Human resources development and training pipelines

✅ Peaceful nuclear applications in medicine, agriculture, industry

✅ Aligns with IAEA guidance, ASEAN links, Belt and Road goals

 

Cambodia has signed a memorandum of understanding with China National Nuclear Corporation (CNNC) on cooperation in the peaceful use of nuclear energy. The agreement calls for cooperation on human resources development.

The agreement was signed yesterday by CNNC chief accountant Li Jize and Tekreth Samrach, Cambodia's secretary of state of the Office of the Council of Ministers and vice chairman of the Cambodian Commission on Sustainable Development. It was signed during the 14th China-ASEAN Expo and China-ASEAN Business and Investment Summit, being held in Nanning, the capital of China's Guangxi province.

The signing was witnessed by Cambodia's minister of commerce and other government officials, CNNC said.

"This is another important initiative of China National Nuclear Corporation in implementing the 'One Belt, One Road' strategy as China's nuclear program continues to advance and strengthening cooperation with ASEAN countries in international production capacity, laying a solid foundation for follow-up cooperation between the two countries," CNNC said.

One Belt, One Road is China's project to link trade in about 60 Asian and European countries along a new Silk Road, even as Romania ended talks with a Chinese partner in a separate nuclear project.

CNNC noted that Cambodia's current power supply cannot meet its basic electricity needs, while sectors including medicine, agriculture and industry require a "comprehensive upgrade". It said Cambodia has great market potential for nuclear power and nuclear technology applications.

On 14 August, CNNC vice president Wang Jinfeng met with Tin Ponlok, secretary general of Cambodia's National Council for Sustainable Development, to consult on the draft MOU. Cambodia's Ministry of Environment said these discussions focused on human resources in nuclear power for industrial development and environmental protection.

In late August, CNNC president Qian Zhimin visited Cambodia and met Say Chhum, president of the Senate of Cambodia. Qian noted that CNNC will support Cambodia in applying nuclear technologies in industry, agriculture and medical science, thus developing its economy and improving the welfare of the population. Cambodia can start training workers, promoting new energy exploitation as India's nuclear revival progresses in Asia, and infrastructure construction, and increasing its capabilities in scientific research and industrial manufacturing, he said. This will help the country achieve its long-term goal of the peaceful use of nuclear energy, he added.

In November 2015, Russian state nuclear corporation Rosatom signed a nuclear cooperation agreement with Cambodia, focused on a possible research reactor, but with consideration of nuclear power, while KHNP in Bulgaria illustrates parallel developments in Europe. A further cooperation agreement was signed in March 2016, and in May Rosatom and the National Council for Sustainable Development signed memoranda to establish a nuclear energy information centre in Cambodia and set up a joint working group on the peaceful uses of atomic energy.

In mid-2016, Cambodia's Ministry of Industry, Mines and Energy held discussions with CNNC on building a nuclear power plant and establishing the regulatory and legal infrastructure for that, in collaboration with the International Atomic Energy Agency, mirroring IAEA assistance in Bangladesh on nuclear development.

 

Related News

View more

Sign Up for Electricity Forum’s Newsletter

Stay informed with our FREE Newsletter — get the latest news, breakthrough technologies, and expert insights, delivered straight to your inbox.

Electricity Today T&D Magazine Subscribe for FREE

Stay informed with the latest T&D policies and technologies.
  • Timely insights from industry experts
  • Practical solutions T&D engineers
  • Free access to every issue

Download the 2025 Electrical Training Catalog

Explore 50+ live, expert-led electrical training courses –

  • Interactive
  • Flexible
  • CEU-cerified