Elektrine lite

← Feed

@reverseics@infosec.exchange

Post #4325588

2026-07-31 19:14 UTC

If your PLC had its password set by a hacktivist, you might be tempted to get your hands on some sketchy password reset/password retrieval software for it. We looked at one of those a bit ago and while it did what it said (retrieved the password using an undisclosed bug in the plc comms protocol) it also came with some C2 software. You wanted malware with your PLC password retrieval, right? I mention this as a piece of software that I've been hunting for, which claims to retrieve passwords from PLCs recently impacted in these water treatment breaches, just showed up on VT for the first time this morning. It is protected with vmprotect and looks fairly sketchy. Still trying to analyze it but stay frosty. You don't want to be a double victim in all this...

Replies (4)

  • @reverseics@infosec.exchange @Viss@mastodon.social At least *somebody* will be managing it.

    Open ##4342942

  • @ajn142@infosec.exchange 2026-07-31 19:31

    @reverseics@infosec.exchange @h2onolan@infosec.exchange we can have a second incident, as a treat?

    Open ##4342944

  • @reverseics@infosec.exchange "Out of the frying pan and into the fire"

    Open ##4342945

  • @reverseics@infosec.exchange Would PLC 'password retrieval' be something people want as a convenience feature(just reset the password without having to wipe the unit or otherwise disrupt things); or are at least some PLCs intended to take credentials seriously enough that even someone with physical access can lock themselves out beyond the ability of a factory reset and reload to get them back in?

    Open ##4342946