Alert - Exploitation of Unitronics programmable logic controllers

Number: AL23-018
Date: December 1, 2023

Audience

This Alert is intended for IT professionals and managers of notified organizations.

Purpose

An Alert is used to raise awareness of a recently identified cyber threat Cyber threatA threat actor, using the internet, who takes advantage of a known vulnerability in a product for the purposes of exploiting a network and the information the network carries. that may impact cyber information assets, and to provide additional detection DetectionThe monitoring and analyzing of system events in order to identify unauthorized attempts to access system resources. and mitigation advice to recipients. The Canadian Centre for Cyber Security Cyber securityThe protection of digital information, as well as the integrity of the infrastructure housing and transmitting digital information. More specifically, cyber security includes the body of technologies, processes, practices and response and mitigation measures designed to protect networks, computers, programs and data from attack, damage or unauthorized access so as to ensure confidentiality, integrity and availability. ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.

Details

The Canadian Centre for Cyber Security (Cyber Centre) is aware of reported exploitation of Unitronics programmable logic controllers (PLCs) used in the water and wastewater systems sector. The Cyber Centre recommends organizations review the guidance published by the Cybersecurity and Infrastructure Security Agency (CISA) about this activity and follow the recommended mitigationsootnote 1.

The risk to industrial control systems accessible from the Internet is not limited to Unitronics devices or the water and wastewater systems sector. The Cyber Centre recommends that organizations using industrial control systems review and implement the security guidance in the Cyber Centre's "Security considerations for industrial control systems"otnote 2.

Suggested actions

The Cyber Centre recommends organizations:

  • Review and implement the guidance published by CISA on the activity targeting Unitronics programmable logic controllersFootnote 1.
  • Review and implement the security mitigations in the Cyber Centre's "Security considerations for industrial control systems" guidanceFootnote 2.

Should activity matching the content of this alert be discovered, recipients are encouraged to report via the My Cyber Portal, or email contact@cyber.gc.ca.

Date modified: