Motives Behind Havex ICS Malware Campaign Remain a Mystery
Summary
Experts question whether the Havex malware campaign targeting three European industrial control system software vendors is merely a dry run for something bigger. Or are they just going around to prove this thing out?” Digital Bond last week published the names of two of the three victim companies targeted by Havex: MB Connect Line of Germany, a manufacturer of wind turbines and biogas, and eWON of Belgium, which provides VPN access for programmable logic controllers. In addition to Havex behaving like a traditional RAT in that it gathers system information and data stored on a compromised client or server using the Open Protocol Communications standard. It is used as the ‘glue’ to tie systems together and translate other protocols.” While Havex wasn’t targeting the protocol directly, it could have been gathering information for another stage of the campaign. K. Reid Wightman, also of Digital Bond, tweeted speculatively last week that Havex’s ultimate target could be data centers.