Facts matter: Sign up for the free Mother Jones Daily newsletter. Support our nonprofit reporting. Subscribe to our print magazine.

I honestly don’t know if this is something to take seriously or just the latest in cyberwar hype, but….

Anti-virus specialists report that a new trojan is spreading via USB flash drives, apparently exploiting a previously unknown hole in Windows.

….An investigation by malware analyst Frank Boldewin has shown that this is not just any old trojan designed to harvest passwords from unsuspecting users….During his investigation, Boldewin came across some database queries the trojan made that point towards the WinCC SCADA system by Siemens. As Boldewin explained in an email to The H’s associates at heise Security, a “normal” malware programmer wouldn’t have managed to do that. Boldewin continued “As this Siemens SCADA system is used by many industrial enterprises worldwide, we must assume that the attackers’ intention was industrial espionage or even espionage in the government area”.

Stewart Baker explains what he thinks this means:

This particular exploit is remarkably sophisticated and singleminded….Most troubling is what the malware goes looking for once it starts up. The entire attack seems designed to exploit holes in the Siemens SCADA software that runs electric grids around the world.

As far as I can tell, there’s no reason to compromise a SCADA system other than to take it down. The SCADA system doesn’t contain credit card numbers or other financial data, and I doubt that compromising it is a cost-effective way to steal power for free….There are no obvious secrets to steal from a SCADA system — other than the secret of how to bring the system down. So the logical goal of the malware is not so much espionage as sabotage.

Let me repeat that for emphasis. This elaborate, previously unseen piece of malware, which surely could have been a big moneymaker if used to create a botnet or to send spam, has instead been put to use for a purpose that has no obvious economic payoff — compromising the power grid.

The comment thread on Baker’s post is lively and, needless to say, not everyone agrees with him that this is as big a deal as he thinks. And since I don’t have the chops to have an independent opinion, don’t take this post as an endorsement of what Baker says. But it seemed interesting and potentially ugly. Just thought I’d pass it along.

And while I’m on the subject, if you didn’t read Mark Bowden’s Atlantic piece about the Conficker worm, “The Enemy Within,” when it came out a few weeks ago, it’s well worth your time. It’s pretty riveting stuff if you have even a little touch of nerd in you.

THE TRUTH...

is the first thing despots go after. An unwavering commitment to it is probably what draws you to Mother Jones' journalism. And as we're seeing in the US and the world around, authoritarians seek to poison the discourse and the way we relate to each other because they can't stand people coming together around a shared sense of the truth—it's a huge threat to them.

Which is also a pretty great way to describe Mother Jones' mission: People coming together around the truth to hold power accountable.

And right now, we need to raise about $400,000 from our online readers over the next two months to hit our annual goal and make good on that mission. Read more about the information war we find ourselves in and how people-powered, independent reporting can and must rise to the challenge—and please support our team's truth-telling journalism with a donation if you can right now.

payment methods

THE TRUTH...

is the first thing despots go after. An unwavering commitment to it is probably what draws you to Mother Jones' journalism. And as we're seeing in the US and the world around, authoritarians seek to poison the discourse and the way we relate to each other because they can't stand people coming together around a shared sense of the truth—it's a huge threat to them.

Which is also a pretty great way to describe Mother Jones' mission: People coming together around the truth to hold power accountable.

And right now, we need to raise about $400,000 from our online readers over the next two months to hit our annual goal and make good on that mission. Read more about the information war we find ourselves in and how people-powered, independent reporting can and must rise to the challenge—and please support our team's truth-telling journalism with a donation if you can right now.

payment methods

We Recommend

Latest

Sign up for our free newsletter

Subscribe to the Mother Jones Daily to have our top stories delivered directly to your inbox.

Get our award-winning magazine

Save big on a full year of investigations, ideas, and insights.

Subscribe

Support our journalism

Help Mother Jones' reporters dig deep with a tax-deductible donation.

Donate