The Russian hacking group Sandworm is likely responsible for the attack on the water system in Muleshoe, Texas, according to the report from the American cybersecurity firm, which is a subsidiary of Google.
It did not cause any service disruptions or serious damage, however.
According to Mandiant, the Sandworm group, which has reportedly been established since 2009 and also goes by the name “Frozen Barents” and “APT44” among others, is likely behind the attack.
The group is “sponsored by Russian military intelligence” and is a “dynamic and operationally mature threat actor that is actively engaged in the full spectrum of espionage, attack, and influence operations,” the cyber firm states.
Experts believe the group is likely connected to Russia’s largest foreign intelligence agency, the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GU), commonly known as the Main Intelligence Directorate (GRU).
Sandworm Can ‘Direct, Influence’ Hacking Groups
According to Mandiant, Sandworm has the ability to “direct and influence” the Cyber Army of Russia’s activities across multiple platforms.The group has also taken credit for various other attacks, including those on Polish and French water utilities, according to Mandiant.
At the time, officials said their hacking attacks were “intended to support Russian government efforts to undermine, retaliate against, or otherwise destabilize,” multiple nations including Ukraine, Georgia, and France,“ and that the hackers used ”some of the world’s most destructive malware to date.”
The six men were allegedly involved in incidents that included shutting down the power grid, the Ministry of Finance, and the State Treasury Service in Ukraine from December 2015 to December 2016. They were also accused of carrying out spearphishing campaigns and related hack-and-leak efforts targeting the political party of French President Emmanuel Macron in April and May 2017.
EPA Warns of Possible Attacks From China, Iran
Additionally, the group of men allegedly targeted worldwide businesses and critical infrastructure, Georgian companies and government entities, and the opening ceremony of the Pyeongchang Winter Olympics in 2017, according to the DOJ.The Justice Department also accused the men of creating a virus called NotPetya, which officials said caused $10 billion in damage to computers worldwide.
The latest report from Mandiant comes just one month after the Environmental Protection Agency and National Security Council warned state leaders of potential attacks on America’s water infrastructure.
Officials urged states to remain alert regarding possible attacks, particularly from Chinese or Iranian hackers, pointing to previous malicious cyberattacks against U.S. critical infrastructure entities, including drinking water systems.
“Drinking water and wastewater systems are an attractive target for cyberattacks because they are a lifeline critical infrastructure sector but often lack the resources and technical capacity to adopt rigorous cybersecurity practices,” they added.