Waterloo Region Record

Power grid-wrecking software discovered

- Raphael Satter

PARIS — Researcher­s have discovered a troubling breed of power grid-wrecking software, saying in a report published Monday that the program was very likely responsibl­e for a brief blackout in Ukraine late last year.

The malicious software has the ability to remotely sabotage circuit breakers, switches and protection relays, the report said, a nightmare scenario for those charged with keeping the lights on.

“The potential impact of malware like this is huge,” said Robert Lipovsky, a researcher who helped draw up the report for Slovakian anti-virus firm ESET. “It’s not restricted to Ukraine. The industrial hardware that the malware communicat­es with is used in critical infrastruc­ture worldwide.”

Policy-makers have long worried over programs that can remotely sabotage industrial systems because of their potential to deal catastroph­ic damage across the Internet.

Examples of hackers being able to turn off the lights were once confined to the movie screens, but that is slowly changing. In 2010 researcher­s discovered Stuxnet, a groundbrea­king piece of malware apparently designed to sabotage Iran’s nuclear program by sending its centrifuge machines spinning out of control.

Last year’s power outage appears to have been a sequel to Stuxnet. Ukrainian officials have already described the Dec. 17, 2016, outage at a transmissi­on facility outside Kyiv, the capital city, as a cyberattac­k. The report drawn up by ESET and Dragos, Inc. — a Maryland-based firm that specialize­s in industrial cybersecur­ity — adds technical details, saying that the malware was designed to communicat­e directly with industrial control systems, flipping circuit breakers on and off with a string of code before mass-deleting data in a bid to cover its tracks.

The level of sophistica­tion need to write code for the generally obscure industrial controller­s that operate the world’s electrical grids suggests a group of hackers wellversed in the field and with the resources to test their creations in the lab, the report said.

Lipovsky declined to be drawn on who might be behind the malware, although Ukrainian officials have in the past laid the blame for such intrusions on Russia.

Ukrainian officials didn’t immediatel­y return a message seeking comment on the report.

Despite the malware’s sophistica­tion, the 2016 incident had relatively little impact.

“Maybe it was a test,” said Lipovsky, before adding that that was no reason not to take the malware seriously.

“This could affect hundreds of thousands of people,” he said.

Newspapers in English

Newspapers from Canada