ICS/SCADA Toolkit Targeting Industrial Control Systems
Advanced Persistent Threat (APT) actors are utilizing a sophisticated, custom-made toolkit designed specifically to infiltrate and manipulate Operational Technology (OT) networks. Once initial access is established, this toolkit allows attackers to scan, compromise, and exert control over critical Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) devices.
Key Facts
- Targets include Schneider Electric PLCs, OMRON Sysmac NEX PLCs, and OPC UA servers.
- Features a modular architecture that enables highly automated exploits.
- Includes a virtual console that mirrors the interface of targeted devices.
- Allows lower-skilled actors to perform complex operations typically reserved for high-skill experts.
- Utilizes a vulnerable ASRock motherboard driver (CVE-2020-15368) for Windows kernel execution.
Modular Architecture and Capabilities
The toolkit is built with a modular design, which allows cyber actors to execute automated attacks against specific industrial hardware. A standout feature is the virtual console; this command interface mimics the actual interface of the targeted ICS/SCADA device, simplifying the process of manipulation.
By using these modules, APT actors can bridge the skill gap, enabling less experienced operators to emulate the capabilities of highly skilled attackers. The primary operational capabilities include:
- Scanning for targeted devices within the network.
- Conducting detailed reconnaissance on device specifications.
- Uploading malicious code or configurations to the hardware.
- Backing up or restoring device contents.
- Modifying critical device parameters.
Targeted Hardware and Protocols
The toolkit specifically targets high-value industrial components. This includes Programmable Logic Controllers (PLCs)—the ruggedized computers used to automate industrial processes—from Schneider Electric and OMRON Sysmac NEX. Additionally, it targets Open Platform Communications Unified Architecture (OPC UA) servers, which are standard frameworks used for data exchange in industrial automation.
| Target Category | Specific Target / Vulnerability | Impact |
|---|---|---|
| PLCs | Schneider Electric & OMRON Sysmac NEX | Compromise and control of industrial logic |
| Communication Servers | OPC UA Servers | Interruption or manipulation of data exchange |
| System Drivers | AsrDrv103.sys (CVE-2020-15368) | Windows kernel code execution |
Kernel Exploitation and Lateral Movement
Beyond targeting industrial hardware, the toolkit includes a tool designed to exploit a known vulnerability in a signed ASRock motherboard driver, specifically AsrDrv103.sys. By leveraging CVE-2020-15368, attackers can execute malicious code directly within the Windows kernel.
This kernel-level access is critical for APT actors as it facilitates lateral movement—the process of moving deeper into an IT or OT environment. Once they have escalated their privileges via the kernel, they can more easily disrupt critical functions or access other sensitive devices across the network.
Frequently Asked Questions
Which specific industrial devices are targeted by this toolkit?
The toolkit targets Schneider Electric PLCs, OMRON Sysmac NEX PLCs, and Open Platform Communications Unified Architecture (OPC UA) servers.
How does the toolkit help lower-skilled attackers?
The toolkit uses a modular architecture and a virtual console that mirrors the target device's interface, allowing lower-skilled actors to perform complex exploits that usually require high-level expertise.
What can an attacker do once they compromise a device using this toolkit?
Attackers can scan for devices, perform reconnaissance, upload malicious configurations or code, modify device parameters, and back up or restore device contents.
What is the role of CVE-2020-15368 in these attacks?
This vulnerability exists in the ASRock-signed motherboard driver AsrDrv103.sys. Attackers use it to execute malicious code in the Windows kernel, enabling them to move laterally through IT and OT environments to disrupt critical functions.