In September 2019, the Kuwait transportation and shipping industry reported two major cybersecurity breaches on their IT Systems that occurred between May-June 2019. The company reportedly was hit by a malware attack by xHunt group (Hive0081), resulting in the company's IT System being infiltrated. It is how many computers were infected. The attack was part of the xHunt campaign targeting Kuwait government and shipping/transportation organizations.
May, 2019The Diamond 8 is a vessel that is suspected of involvement in DPRK sanction evasion. The vessel is believed to have performed in multiple ship-to-ship transfers on different occasions in throughout the years and delivering of sanctioned oil in for example in the port of Nampo. The vessel has been investigated for years and has changed its name multiple times. The vessel also is confirmed to be guilty of going dark on multiple occasions.
Apr, 2019GPS spoofing impacting shipping has been detected in over 20 Chinese coastal sites during 2019, including the port of Qingdao, possibly as a reaction to increased scrutiny of Iranian crude imports by the U.S. A ring of false AIS positions marks an apparent GPS interference device deployed in an office building identified as the Qingdao tax administration office. A total of three office buildings in Qingdao were affected by the incident.
Feb, 2019In February 2019, UK based Shipping Company Crew and Concierge Ltd. felt victim to a data breach. This case seems to be an example of hackers taking advantage of COVID-19 pandemic, especially targeting employees working from home through e-mail phishing scams. As a result, hackers gained access to personal data of 17,000+ people working in the yacht industry worldwide. The company faces a possible hefty fine. Reportedly, a company's server containing 90,000+ files of people related to the company, was found to be accessible for anyone without password protection.
Feb, 2019In February 2019, a deep draft merchant vessel bound for the port of New York and New Jersey was hit by a malware (Emotet Trojan) attack, disabling its onboard Computer System. It is possible that the ship may not have been targeted specifically, although this has not been confirmed. After the vessels radio contacted the coast guard, an incident-response team was send out and entered the ship to assess the possible damage. Eventually, the coast guard alerted the FBI.
In 2019, a tanker near the port of Naantali in Finland was hit by a ransomware attack. As a result, its administration server was infected and the back up disk was wiped. Reportedly, the method of intrusion remains unclear but a Remote Desktop Protocol (RDP), a USB device or an email attachment are identified as probable attack vectors. The same vessel was infected again 4 months later near the same port. The threat actor and motives behind the attack remain a mystery.
Nov, 2018In November 2018, key Ukrainian government and military targets got hit by a malware attack in Ukraine. The malware entered through a Backdoor entry called Pterodo. This Backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. The latest version activates only on Windo+X105:AA105ws systems with language localization for Ukrainian, Belarusian, Russian, Armenian, Azerbaijani, Uzbek, Tatar, and other languages associated with former Soviet states; this makes it more difficult to perform automated analysis of the malware with certain tools. According to the CERT-UA bulletin, the new version of Pterodo generates a unique URL for command and control based on the serial number of the hard drive of the infected system. Data about the infected system is uploaded to that URL, allowing the attackers to analyse which tools to remotely install and run. The domains associated with the attack so far include updates-spreadwork.pw, dataoffice.zapto.org, and bitsadmin.ddns.net. Behind this attack was the Russian Gameradon Group which is tied to the Russian FSB. The attack is a Spyware war and disinformation campaign. The attacks were aimed at gathering intelligence that could be used for the ships. Due to this attack Russia seized Ukrainian vessels and imprisoned Ukrainian sailors. The attackers gained information that would have been very relevant in planning.
Nov, 2018In November 2018, a vessel got hit by a GPS interference near the Port of Haifa in Israel. The vessel experienced erratic signals. GPS-guided autonomous cranes were unable to operate, meaning the ports had to revert to manual methods of loading and unloading cargo. It is who is behind these GPS interferences.
Nov, 2018When the Yuk Tung vessel transmitted under a Panamanian flag in November 2018, using the vessel name Maika, it completely faked its AIS and changed its path and destination, following a questionable ship-to-ship transfer between the Yuk Tung and the Ocean Explorer in October. The vessel officially approved and registered a Comoros-flagged vessel, the Hika, at the time of the spoofing. The Hika and the Maika had the same International Maritime Organization (IMO) number. The two ships were sisters, built in the same year by the same constructor and with identical specs and profiles. The Hika, on the other hand, was over 7,000 kilometres away at the time. Meanwhile, the Maika (aka Yuk Tung) was impersonating the Hika to deceive authorities. Bad actors had clearly lifted the bar with this AIS spoofing scenario.
Oct, 2018In October 2018, Austal shipbuilder in Australia got hit by a hacking/ransomware attack. Hackers located in the Middle East used login credentials purchased on a dark web forum to get into the system. The criminals walked around the ‘virtual rooms’ in the company's systems, and collected things as they went. The attackers also triggered an alarm as they stockpiled data for exfiltration. They also made an attempt to extortion by demanding ransom. The attack led to data theft, including some staff email addresses, mobile phone numbers and ship drawings. The attackers threatened to offer certain materials for sale on the internet and tried to extort the company. IT had to shut down all external ports to contain the attack. It appeared the stolen credentials were also relatively weak, being either ‘Password123’ or ‘Austal123’. The stolen ship drawings were designs for customers and sub-contractors, but the company insists neither commercially-sensitive nor details that affect national security were compromised. Austal has confirmed "some staff email addresses and mobile phone numbers" were accessed in the hack. The company was keen to point out the breach had no impact on its ongoing operations. The government will continue to actively deter and respond to malicious cyber activity.