Drovorub malware allows taking control of Trio radio stations

French power engineering company Schneider Electric has warned its customers about the Drovorub malware, which allows taking control of Trio radio.

Drovorub is malware developed for Linux by the Russian cybercriminal group APT28 (also known as Fancy Bear, Pawn Storm, Sednit and Strontium).

The malware contains an implant, a kernel module rootkit, file transfer and port forwarding tools, and a C&C server.

“Once installed on a device, the malware allows operators to upload and download files, execute commands with superuser privileges, and perform port forwarding. The malware also has mechanisms to ensure persistence and evade detection”, – said representatives of Schneider Electric.

Drovorub runs on systems with Linux 3.7 and later kernels (due to lack of proper kernel signature enforcement) and cannot provide persistence on systems where UEFI Secure Boot is enabled in Full or Thorough mode.

Schneider Electric has recommended that customers use comprehensive protection guidelines to keep Trio Q Data Radio and Trio J Data Radio devices safe from malware.

These products are radios designed to provide long-range wireless transmission for SCADA and remote telemetry applications.

“Installing malware allows an attacker to interact directly with the C&C server, execute arbitrary commands, redirect network traffic through a port, and use special techniques to evade detection”, – information security specialists report.

By default, Trio radios are not vulnerable to malware and it cannot be downloaded to devices without modification. Radios can only be potentially vulnerable if the user uses insecure protocols and refuses to implement role-based access control.

Schneider Electric strongly recommend following industry cybersecurity best practices such as:

Let me also remind you that the US Cyber Command uploaded to VirusTotal new versions of the ComRAT and Zebrocy malware, the authorship of which are attributed to Russian government hackers.

Exit mobile version