In a timespan of multiple years, about 260 vessels of the Chinese fishing fleet have turn off their AIS system so they could enter the EEZ territory around the Galapagos Islands. This area is an international no-fishing zone, but by turning off their AIS, the vessels could enter the waters without being traced. That way they could illegally undergo fishing activities in de EEZ. These illegal fishing activities have resulted in multiple arrests.
Jun, 2014Between 2014 and 2015, trawler fishing vessels 'Releixo' and 'Egaluze' go dark in Senegal and Gambia in order to conduct illegal fishing activities. The ships were transmitting AIS signals for some of the time, and algorithms were then used to identify when the signal ceased for longer than 24 or 48 hours. Relaxio appeared to go dark to public tracking systems, around 21 times during a 19-month period between 2014 and 2015. Each incident lasted an average of 16 days, resulting in over 8,000 hours of unaccounted activity. Egaluze vanished from public AIS systems for 190 days when operating around the coasts of five African countries.
Apr, 2014In the first quarter of 2014, the Norwegian industrial conglomerate Ulstein Group experienced a cyber espionage attack just before Easter. Unauthorized individuals had access to the company's data files for at least one week. The attack was advanced and targeted, carried out by actors with significant resources. Stolen data files were collected, encrypted, and then sent out, making it difficult to determine what information was actually extracted. This incident is one of 16 serious attacks on private and public companies in Norway during this period. Ulstein Group has reported the incident to the police and has chosen to be open about it to raise awareness about industrial espionage.
Mar, 2014In March 2014, the port of Haifa and Ashdod, Israel got hit by a cyberattack. It concerns a hacking incident where it is not exactly clear what the attack pattern is. The aim of the attackers was the shadow war, this cyberattack was response to a major cyberattack on an Iranian port. The consequence of the attack was a leaked video footage that showed images from cameras recording access gates and even workers sitting at their desks in offices. In addition, the video includes personal details about workers and even their identification papers. The hackers also published a file that contained details of hundreds of workers from the ports. The threat actors of this cyberincident were Iranian hackers 'Iranian Saviours / Tunnel Vision' (IRGC). It is not exactly clear what measures they took during and after the incident.
Jan, 2014In January 2014, the ship MT Kerala was going dark in the countries Angola and Nigeria. Allegedly, pirates disabled the vessel’s AIS and other communication equipment so that the vessel could not be tracked from shore or satellite and painted over the identifying features of the vessel, including stack, name and IMO number. the aim of the pirates was fuel theft. The consequence of the attack was that $10 million of Cargo (oil) was stolen via ship-to-ship transfer. They undertook three separate ship-to-ship transfers of cargo amounting to the theft of approximately 12,271.5 tonnes of cargo. The hijacking of the Dynacom Tanker in an area where a known suspect vessel was operating was an embarrassment for the Angolan Navy, which floated the idea that the hijacking had been faked by the Kerala’s crew. During the hijacking, one crew member was stabbed by the pirates and others were beaten. After the incident they initiated an investigation towards the incident and gathered evidence.
From the year 2014 to 2018, the U.S. Engineering & Maritime industry got hit by malware attack orchestrated by Leviathan, TEMP.Periscope (China) in order to steal data for strategic use. The attackers used tools like backdoors, reconnaissance tools, file stealers, and web shells. The first of the backdoors is Airbreak, a JavaScript-based tool that retrieves commands from hidden strings in compromised webpages and actor controlled profiles on legitimate services. A second backdoor is Badflick, which can modify the file system, generate a reverse shell, and modify its command and control (C&C) configuration. Another similar piece of malware is Photo, a DLL backdoor that gets directory, file, and drive listing; creates a reverse shell; records the screen, video, and audio; lists, terminates, and creates processes; creates and modifies registry keys and values; logs keystrokes, returns usernames and passwords from protected storage; and can read, create, and modify files. The group also used Homefry, a 64-bit Windows password dumper/cracker previously used along with the first two backdoors. Based on received commands, it can either display cleartext credentials for each login session, or can display cleartext credentials, NTLM hashes, and malware version for each login session. Other tools employed by the hackers include Lunchmoney (which can exfiltrate files to Dropbox) and Murkytop, a command-line reconnaissance tool (which can execute files; move and delete files; schedule remote AT jobs; perform host discovery; scan for open ports in a connected network; and retrieve information about the operating system, users, groups, and shares on remote hosts). In recent attacks, the group was also observed employing the China Chopper code injection web shell capable of executing Microsoft .NET code within HTTP POST commands (thus, it can upload and download files, execute applications, list directory contents, access Active Directory, access databases, and more). Previously, the group used the Beacon backdoor (commercially available as part of the Cobalt Strike software platform), and the Blackcoffee backdoor that hides C&C communication as traffic to legitimate websites such as GitHub and Microsoft's TechNet portal. The group has been also observed using spear phishing emails; lure documents attempting to exploit CVE-2017-11882 to drop malware; stolen code signing certificates to sign their malware; bitsadmin.exe and PowerShell to download additional tools; and Windows Management Instrumentation (WMI) and Windows Shortcut files (.lnk) for persistence. The actor sometimes utilizes access at one compromised organization to attack the next. For example, compromised email accounts at one organization were used to send the next wave of malicious attachments to potential victims in the same industry. Similarly the actor attempts to compromise servers within victim organizations and use them for command and control (C&C) for their malware.
In 2013, oil platforms in Houston, TX and Gulf of Mexico got hit by a malware attack. The malware seems to be originating from pirated videos and music that has been downloaded through the satellite connections used by the rigs, as well as pirated material that were already existing on the workers' computers. The malware disabled operating systems and computers on several oil rigs. Due to this malware, one rig incapacitated from the communication and Navigation System. After that, she lost manoeuvrability skills and started to drift due to the crippleness of thrusters resulting in environmental damage and delay of operations. Many of these malware attacks could have been prevented with anti-virus systems and updated system software. However, it seems that many of the infected oil rigs opted against investing into cyber-security systems, which is why an outbreak of malware like this was able to occur. The infected oil rigs are going to take cyber threats seriously in the future in order to prevent an incident like this from occurring in the future.
In 2013, the port of Long Beach got hit by a DDoS attack. Very little is known about this incident. However, in response of this attack, the facility is developing the virtual port system, a computer network that integrates secure data from federal agencies and private terminal operators. It has also banned commercial internet traffic from its network; invested nearly $1m in commercial applications to monitor network activity, intrusions and firewalls; mapped its networked systems and access points; designated controlled access areas for its servers and backed up and replicated key data off-site.
Oct, 2012In October 2012, the Iranian off-shore oil and gas platform got hit by cyberattack. The exact location where the cyberattack took place was the Persian Gulf. For a few weeks, Iranian sources suspect Israel and a few other countries have been targeting the communication networks with the aim of having a cyber warfare with Iran. The consequence of the cyberattack was obstruction of the oil production. Tehran is heavily invested in cyber defense and capability.
Jun, 2012In June 2012, the United States Navy got hit by a hacking attack. The attackers employed a common hacking technique called a SQL injection, in which attackers probe a database to understand and (ultimately) exploit it. They did it because of boredom. The hackers found they were 'somewhat politically inclined to release the things [they had]'. Also because it was 'fun and we can'. The impact of hacking the Navy-SWM was theft of confidential information of approximately 220,000 Navy servicepeople who were being transferred. They posted the information, with social security numbers redacted, and crowed about it on Twitter. As a result Navy-SWM was shut down and never resumed operation. Over 700 deployed overseas Service Members could not access logistical support for transfers for more than 10 weeks. Caused loss to the Navy of approximately 514,000 dollars. The threat actor was TeamDigi7al (Nicholas Paul Knight, while on USS Harry S. Truman and Daniel Trenton Krueger). It is not exactly clear what measures the company took during and after the incident.