A Tale of Two Industroyers: It was the Season of Darkness
Luis E. Salazar, Sebastián R. Castro, Juan Lozano, Keerthi Koneru, Emmanuele Zambon, Bing Huang, Ross Baldick, Marina Krotofil, Alonso Rojas, Alvaro A. Cárdenas
Abstract
In this paper, we study two pieces of malware that attempted to create blackouts in Ukraine. In particular, we design and develop a new sandbox that emulates different networks, devices, and other characteristics so that we can execute malware targeting substation equipment and understand in detail the specific sequence of actions the attackers could perform on substation equipment. We also study the effects that future similar malware can have. Our findings include new malware behavior not previously documented (such as the detailed algorithm for the MMS protocol payload) and an illustration of how attacking different targets will produce different effects.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 323556bf-2c84-495d-82f9-6c8eb02f9a45Cited by top-tier papers2
- SoK: Security of Programmable Logic ControllersEfrén López-Morales, Ulysse Planta, Carlos E. Rubio-Medrano, Ali Abbasi et al.USENIX Security 2024 · 10 citations
- Grid Trouble in Paradise: Uncovering Vulnerable Distributed Energy Resources and Their Grid-Level RisksAnna Raymaker, Samuel Talkington, Zeezoo Ryu, Richard Asiamah et al.CCS 2026
Builds on5
- Hey, My Malware Knows Physics! Attacking PLCs with Physical Model Aware RootkitLuis Garcia, Ferdinand Brasser, Mehmet Hazar Cintuglu, Ahmad-Reza Sadeghi et al.NDSS 2017 · 205 citations
- ICSREF: A Framework for Automated Reverse Engineering of Industrial Control Systems BinariesAnastasis Keliris, Michail ManiatakosNDSS 2019 · 90 citations
- Not Everything is Dark and Gloomy: Power Grid Protections Against IoT Demand AttacksBing Huang, Alvaro A. Cárdenas, Ross BaldickUSENIX Security 2019 · 87 citations
- Towards Automated Safety Vetting of PLC Code in Real-World PlantsMu Zhang, Chien-Ying Chen, Bin-Chou Kao, Yassine Qamsane et al.S&P 2019 · 64 citations
- MaDIoT 2.0: Modern High-Wattage IoT Botnet Attacks and DefensesTohid Shekari, Alvaro A. Cárdenas, Raheem BeyahUSENIX Security 2022
Related papers
- Shedding Light on Inconsistencies in Grid Cybersecurity: Disconnects and RecommendationsBrian Singer, Amritanshu Pandey, Shimiao Li, Lujo Bauer et al.S&P 2023
- BlackIoT: IoT Botnet of High Wattage Devices Can Disrupt the Power GridSaleh Soltan, Prateek Mittal, H. Vincent PoorUSENIX Security 2018 · 348 citations
- RFDIDS: Radio Frequency-based Distributed Intrusion Detection System for the Power GridTohid Shekari, Christian Bayens, Morris Cohen, Lukas Graber et al.NDSS 2019 · 25 citations
- SIMurai: Slicing Through the Complexity of SIM Card Security ResearchTomasz Piotr Lisowski, Merlin Chlosta, Jinjin Wang, Marius MuenchUSENIX Security 2024 · 10 citations
- Spotless Sandboxes: Evading Malware Analysis Systems Using Wear-and-Tear ArtifactsNajmeh Miramirkhani, Mahathi Priya Appini, Nick Nikiforakis, Michalis PolychronakisS&P 2017 · 134 citations
