Summary

In April 2024, a group calling itself Blackjack, believed to be affiliated with Ukrainian intelligence services, claimed an attack on Moscollector. Moscollector is a Moscow company that monitors underground water, sewage and communications infrastructure through networks of sensors. Claroty Team82 published an analysis on 12 April 2024 (updated 15 April) of the malware involved, Fuxnet. Its destructive routines:

  • corrupt the filesystem and disable remote-access services on the sensor gateways;
  • perform bit-flip operations on NAND memory chips to cause hardware failure;
  • flood the Meter-Bus (M-Bus) serial channel with random and structured data to overwhelm the connected sensors.

The impact claims shrank under scrutiny. Blackjack first claimed 87,000 sensors destroyed, then revised to 2,659 gateways targeted and about 1,700 “successfully attacked”. Claroty’s review of the leaked data suggests “a little more than 500 sensor gateways were bricked”, with the remote sensors themselves likely intact.

Apa maksudnya untuk Malaysia? 🇲🇾

Fuxnet targets the distributed edge of utilities: cheap, numerous gateways spread across a city, often managed remotely and rarely monitored like a control room. As Malaysian utilities expand smart metering and remote monitoring, that edge grows.

  • Inventory remote gateways and their management interfaces, and make sure they are not reachable from the internet or from the corporate network.
  • Plan for physical replacement at scale. Firmware-bricked devices need truck rolls, so hold spares and a rapid-replacement process.
  • Read claims critically. Hacktivist and state-linked personas routinely overstate impact. Compare claims against telemetry before briefing management, as Claroty did here. The same discipline applies to the claims in Rectifyq’s Breach Watch.

Details / TTPs (ATT&CK for ICS)

TechniqueNameObserved behavior
T0822External Remote ServicesRemote access used to reach the sensor gateways
T0809Data DestructionFilesystem corruption on gateways
T0814Denial of ServiceM-Bus flooding of connected sensors
T0879Damage to PropertyNAND bit-flipping to destroy hardware
T0829Loss of ViewSensor data from the monitored networks lost

Detection guidance

  • Monitor gateway heartbeat/telemetry gaps across the fleet; a sudden mass drop-off is the signature of this attack.
  • Alert on firmware or configuration pushes to field gateways that aren’t from your management platform.
  • Restrict SSH/Telnet and other management services on field gateways to a dedicated management network.

IoCs

See the Claroty Team82 analysis for sample details.

References