Lightwork

Malware updated 4 months ago (2024-05-05T01:18:20.439Z)
Download STIX
Preview STIX
Lightwork is a disruptive malware tool written in C++, designed to manipulate the state of Remote Terminal Units (RTUs) over TCP using the IEC-104 protocol. It operates alongside another component called Piehop, both of which are part of a new malware system known as CosmicEnergy. According to cybersecurity firm Mandiant, CosmicEnergy manipulates RTUs by leveraging these two derivative components. While the sample of Piehop obtained was riddled with programming logic errors that hinder its IEC-104 control capabilities, Mandiant believes these issues can be easily rectified. Lightwork, on the other hand, requires more development maturity before it becomes a full-fledged IEC104 attack capability. The malware system functions by having Piehop connect to a specified remote MSSQL server for uploading files and issuing remote commands to an RTU using Lightwork. Lightwork then implements the IEC-104 protocol to modify the RTU state to 'on' or 'off'. However, the operator likely needs to perform internal reconnaissance to obtain environmental information, such as MSSQL server IP addresses and credentials, as CosmicEnergy lacks discovery capabilities. Additionally, Lightwork was hard-coded to affect a specific IEC 104 network configuration, unlike Industroyer and Industroyer2, which had adaptable configuration formats. Despite these functionalities, cybersecurity firm Dragos does not see Lightwork as an immediate threat. This is due to the fact that Lightwork was compiled with symbol information, enabling researchers to decompile the function and argument names used in the malware code. Furthermore, Dragos concluded that Lightwork was not a variant of the other two tools, Industroyer and Industroyer2, as they used a custom IEC 104 library while Lightwork did not. Hence, while Lightwork has demonstrated potential for disruption, it still requires further development to pose a significant threat.
Description last updated: 2024-05-05T01:17:05.952Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Lightwork Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
8 months ago
Analysis of OT cyberattacks and malwares
CERT-EU
a year ago
CosmicEnergy ICS Malware Poses No Immediate Threat, but Should Not Be Ignored
CERT-EU
a year ago
CosmicEnergy’s threat to critical infrastructure in dispute
CERT-EU
a year ago
COSMICENERGY Malware May be Artifact of Russian Emergency Response Exercises