US government agencies warn of new custom tools, created by several APT actors, that are capable of compromising IT equipment used in critical infrastructure
Several advanced persistent threat (APT) actors have created custom-made tools designed to breach IT equipment used … Source: CISA .
The RecordJonathan Greig
Context & Ripple Effects
Earlier CISA reporting linked China-associated groups to exploitation of F5, Citrix, Pulse Secure and Exchange flaws in US government networks, documented in CISA's warning on perimeter-product exploitation. The new advisory extends the concern from disclosed vulnerabilities to tailored tooling aimed at infrastructure-related IT.
Related coverage later connected China-backed exploitation of known flaws with network-traffic collection and identified Iran-linked interest in industrial control devices, linking network-traffic espionage through known vulnerabilities with a broader critical-infrastructure threat picture.
First-order effects
Critical-infrastructure owners now have a named threat category—custom APT tooling aimed at their IT equipment—to prioritize alongside commodity malware and disclosed vulnerabilities.
CISA and the other warning agencies gain a clearer basis for coordinating defensive guidance around infrastructure-facing IT systems rather than treating the risk solely as a government-network issue.
Second-order effects
Patching known flaws alone becomes a less complete response: the related reporting on exploitation for network-traffic access shows how bespoke tools add a separate detection and hardening burden.
Operators whose IT connects to operational environments face heightened pressure to segment and monitor that boundary, as later agency coverage identifies Iran-linked targeting of industrial control devices.
Third-order effects
If multiple APT groups continue developing tailored infrastructure tooling, critical-infrastructure cybersecurity will increasingly be organized around the IT-to-operational-technology boundary rather than isolated product vulnerabilities.
The sequence of agency advisories points toward threat intelligence being shared across government networks and infrastructure operators as the same actors and techniques span both domains.
The trend: Critical-infrastructure defense is shifting from vulnerability-by-vulnerability remediation toward countering persistent actors that tailor tools for connected IT and operational environments.
Today the US Government announced a new ICS malware that has been designed to disrupt industrial operations. CISA/FBI/NSA put out a great advisory; also I appreciate the callout/thanks to @DragosInc in the advisory - we call the malware PIPEDREAM https://www.cisa.gov/...
With @DOE_CESER, @FBI, & @NSACyber, we published a joint advisory on APT cyber tools targeting #ICS & #SCADA devices. Critical infrastructure organizations - especially in the energy sector - should review our recommended proactive mitigations and actions: https://www.cisa.gov/..…
This is the first time, I'm aware of, that an industrial cyber capability has been found *prior* to its deployment for intended effects. This capability was designed to be disruptive/destructive in nature - and we're actually a step ahead of the adversary.
Certain advanced persistent threat (APT) #cyber actors have shown the ability to gain full system access to multiple industrial control system (ICS)/supervisory control and data acquisition (SCADA) devices. Learn more via our joint Cybersecurity Advisory. https://www.cisa.gov/...…
I think there is some confusion about the ICS malware that @CISAgov and @NSAGov announced today. It has not been deployed nor has it targeted US critical infrastructure. The code was discovered before it was used in any attacks, per @DragosInc.
The module that was discovered is designed to target industrial controllers made by Schneider Electric, which are used in facilities around the world, not just the US and not just electric but there's no sign it was actually used in any attacks yet.
Here we go. New unnamed state 🤔 hackers are infecting U.S. critical infrastructure—like grid operators—with custom tools capable of worst-case scenario attacks. There's no soft peddling it. This is very serious. Read @CISAgov's advisory in full. And do everything they say. Now ht…
NATO has previously confirmed that cyberattacks are attacks that trigger the Article 5 joint defense provision. That seems to mean the US has been attacked in an act of war. As predicted Putin is drawing the US in and daring it to respond. It can only be stopped one way. https://…
Now that is quite an assessment: “INCONTROLLER poses the greatest threat to Ukraine, NATO member states, and other states actively responding to Russia's invasion of Ukraine.” https://www.mandiant.com/...
This is a very serious #cyber threat on our critical infrastructure. Read this advisory in its entirety - especially if you work for any of the targeted agencies. https://twitter.com/...
We've published a blog post on our analysis of the INCONTROLLER framework, covering how new state-sponsored cyber attack tools target multiple industrial control systems. Thanks to @SchneiderElec & our partners for their contribution. Full post 👇 #ICS https://www.mandiant.com/...