Learn about an example of a supply chain attack through a third party software provider, where a legitimate industrial control system is 'trojanised'.
Since 2011, the cyber-espionage group known as Dragonfly (also known as Energetic Bear, Havex, and Crouching Yeti) has allegedly been targeting companies across Europe and North America, mainly in the energy sector. This group has a history of targeting companies through their supply chains.
In their latest campaign, Dragonfly successfully “trojanised” legitimate industrial control system (ICS) software. To do so, they first compromised the websites of the ICS software suppliers and replaced legitimate files in their repositories with their own malware infected versions.
Subsequently, when the ICS software was downloaded from the suppliers’ websites it would install malware alongside legitimate ICS software. The malware included additional remote access functionalities that could be used to take control of the systems on which it was installed.
Compromised software is very difficult to detect if it has been altered at the source, since there is no reason for the target company to suspect it was not legitimate. This places great reliance on the supplier, as it's not feasible to inspect every piece of hardware or software in the depth required to discover this type of attack.