x

Society

US States Want Russian Malware Blockers

January 1, 2017

BURLINGTON, Vt. — Several states around the country have asked cybersecurity experts to re-examine state and utility networks after a Vermont utility’s laptop was found to contain malware U.S. officials say is linked to Russian hackers.

The Burlington Electric Department, one of Vermont’s two largest electric utilities, confirmed it had found on one of its laptops the malware code used in Grizzly Steppe, the name the U.S. government has given to malicious cyber activity by Russian civilian and military intelligence services.

A Burlington Electric Department spokesman said federal officials have told company officials the threat was not unique to them.

The Department of Homeland Security said it had no information indicating the power grid was penetrated in the cyber operation.

A spokesman wouldn’t say whether any other utilities, organizations or entities had reported similar malware on their systems but said any such information would be confidential.

Officials in New York, Rhode Island, Massachusetts and Connecticut said they’re more closely monitoring state and utility networks for anything suspicious.

“We have not detected any activity matching the reported malware at this time,” Connecticut governor’s office spokesman Chris Collibee said.

New Jersey’s Homeland Security Director said the state had no reports of malicious activity associated with Grizzly Steppe at major utility systems.

In New York, Democratic Gov. Andrew Cuomo directed all state agencies to re-examine their computer systems for security breaches. Nothing had been found.

An attack on a U.S. power grid has long been a nightmare scenario for top U.S. officials. The National Security Agency and U.S. Cyber Command chief Adm. Michael Rogers have previously warned it’s not a matter of if but when attackers target U.S. power systems.

On Dec. 23, 2015, a highly sophisticated cyberattack on the power grid in Ukraine hit three regional electronic power distribution companies, blacking out more than 225,000 customers.

Democratic Vermont Gov. Peter Shumlin said his administration has been in touch with the federal government and the state’s utilities. He said people should be “alarmed and outraged” that Russia “has been attempting to hack our electric grid, which we rely upon to support our quality-of-life, economy, health and safety.”

Burlington Electric noted it wasn’t connected to the grid system and didn’t explain how the malware got onto the computer.

The company said U.S. government authorities alerted American utilities about the malware code Dec. 29 in a report released when Democratic President Barack Obama announced the U.S. response to election hacking.

Obama ordered sanctions on Russian intelligence agencies, closed two Russian compounds and expelled 35 diplomats the U.S. said were spies.

A Russian state television channel on Dec. 31 sought to discredit reports linking the malware to the Kremlin.

If Russia is found to be connected to widespread hacking of U.S. utilities, it will make it more difficult for Republican President-elect Donald Trump to soften anti-Russian sentiment on Capitol Hill, where hearings on hacking are scheduled next week.

Rep. Peter Welch, a Democrat from Vermont, said the incident proves Obama’s response was warranted.

“This attack shows how rampant Russian hacking is. It’s systemic, relentless, predatory,” Welch said in a statement. “They will hack everywhere, even Vermont, in pursuit of opportunities to disrupt our country.”

The Washington Post first reported on the Vermont utility’s malware discovery.

The Rossiya state television channel said the Post provided no confirmation Russia was involved.

It said the Post report spoke only about the identification of malicious software code that Washington previously concluded had been used by the Russian intelligence services in the cyber attack on U.S. political institutions.

In a report released Dec. 29, Homeland Security and the FBI provided technical details about the tools and infrastructure they say Russian civilian and military intelligence services have used to compromise and exploit networks “associated with the U.S. election as well as a range of U.S. government, political and private sector entities.”

“This activity by the Russian civilian and military intelligence services is part of an ongoing campaign of cyber-enabled operations directed at the U.S. government and its citizens,” the report said.

___

Associated Press writers Deb Riechmann in Washington, Jacob Pearson in New York, Jennifer McDermott in Providence, Rhode Island, Holly Ramer in Concord, New Hampshire, and Christina Paciolla in Philadelphia contributed to this report.

RELATED

CALIFORNIA - The University of Southern California canceled its main graduation ceremony and dozens more college students were arrested at other campuses nationwide Thursday as protests against the Israel-Hamas war continued to spread.

Top Stories

Columnists

A pregnant woman was driving in the HOV lane near Dallas.

General News

NEW YORK – Meropi Kyriacou, the new Principal of The Cathedral School in Manhattan, was honored as The National Herald’s Educator of the Year.

Video

Over 100 Pilot Whales Beached on Western Australian Coast Have Been Rescued, Officials Say

MELBOURNE, Australia (AP) — More than 100 long-finned pilot whales that beached on the western Australian coast Thursday have returned to sea, while 29 died on the shore, officials said.

CALIFORNIA - The University of Southern California canceled its main graduation ceremony and dozens more college students were arrested at other campuses nationwide Thursday as protests against the Israel-Hamas war continued to spread.

NEW YORK  — The third day of witness testimony in Donald Trump's hush money trial concluded Thursday after Trump's lawyers got their first chance to question a witness on the stand.

ATLANTA — As Donald Trump seeks a return to the White House, criminal charges are piling up for the people who tried to help him stay there in 2020 by promoting false theories of voter fraud.

ATHENS - Voters should see the whole picture when they go to cast their ballot in the European Parliament elections on June 9, Prime Minister Kyriakos Mitsotakis said in an interview on Thursday.

Enter your email address to subscribe

Provide your email address to subscribe. For e.g. [email protected]

You may unsubscribe at any time using the link in our newsletter.