Vermont power company finds malware linked to Russian hackers

A malware signature linked to ‘Grizzly Steppe’ by the FBI and DHS was found on a single laptop.

Just a few days ago, the FBI and the Department of Homeland Security released a report detailing their assessment that Russian hackers were behind a series of attacks on US agencies and citizens. While the Obama administration issued sanctions, code linked to those hackers has been shared with other agencies, and on Friday, the Burlington Electric Department found malware with a matching signature on one of its laptops. The discovery raises more questions than it answers, but with recent reports of Russian hackers attacking the power grid in Ukraine, it obviously has raised alerts all over.

The Washington Post first reported the finding, suggesting that Russian hackers had gained access to the electrical grid via the Vermont utility, however the company’s statement says there’s no indication that happened. In a statement, it said the laptop in question was not connected to grid systems. Vermont Public Service Commissioner Christopher Recchia told the Burlington Free Press that the grid was not in danger.

Because it’s not clear exactly what matched, there’s a possibility that it could be the result of a false positive, or shared code. Also, it’s not clear when or how the malware got on the laptop. Based on those reasons, a number of security professionals on Twitter suggested waiting for more details before crediting this finding to Grizzly Steppe (a name attributed to the Russian attacks in Wednesday’s report).

So far, no other utilities or agencies have reported anything similar, but we will update this post if more information comes to light.

Leave a Reply

Your email address will not be published. Required fields are marked *