NSA and CISA Recommend Immediate Actions

NJCCIC Alert

Original Release Date: 7/23/2020

Summary

On July 23, 2020, the National Security Agency (NSA) and Cybersecurity and Infrastructure Security Agency (CISA) released Activity Alert AA20-205A , which highlights the recent offensive malicious cyber activity perpetrated against critical infrastructure (CI) by exploiting internet-accessible operational technology (OT) assets. Due to the increase in adversary capabilities and activity, the criticality to U.S. national security and way of life, and the vulnerability of OT systems, the NSA and CISA recommend that all Department of Defense (DoD), National Security Systems (NSS), Defense Industrial Base (DIB), and U.S. critical infrastructure facilities take immediate actions to secure their OT assets.

Recently observed Tactics, Techniques and Procedures (TTPs) targeting OT are:

  • Spearphishing to obtain initial access to the organization’s information technology (IT) network before pivoting to the OT network.
  • Deployment of commodity ransomware to encrypt data for impact on both networks.
  • Connecting to internet accessible Programmable Logic Controllers (PLCs) requiring no authentication for initial access.
  • Utilizing commonly used ports and standard application layer protocols to communicate with controllers and download modified control logic.
  • User of vendor engineering software and program downloads
  • Modifying control logic and parameters on PLCs.

Reporting

The NJCCIC encourages recipients who discover signs of malicious cyber activity to contact the NJCCIC via the cyber incident report form by clicking here.

Please do not hesitate to contact us at njccic@cyber.nj.gov with any questions.

New Jersey Cybersecurity & Communications Integration Cell

2 Schwarzkopf Dr, Ewing Township, NJ 08628

njccic@cyber.nj.gov

OUR COMMITMENT

The NJCCIC is a component organization within the New Jersey Office of Homeland Security and Preparedness. We are the State's one-stop-shop for cyber threat analysis, incident reporting, and information sharing and are committed to making New Jersey more resilient to cyber threats by spreading awareness and promoting the adoption of best practices.

Agency Seals of State of NJ, NJOHSP and NJCCIC

STAY CONNECTED:

View our Privacy Policy here.

View our Site Index here.