PULSE NAME
Proactive OT security: Lessons on supply chain risk management from a rogue Raspberry Pi
WHITE PetrP.73 2025-06-16 Modified: 2025-07-16
108
IOCs
HIGH VOLUME
A recent insider threat was identified when a vendor left a rogue Raspberry Pi device on a customer's Industrial Control Systems (ICS) network, highlighting supply chain vulnerabilities. Historical incidents, including the 2014 Havex attack and the 2018 semiconductor breach, exemplify the risks associated with compromised software within ICS environments. Darktrace's analysis pointed out unusual metadata linked to the device's encrypted connections, indicating potential risks despite lacking overt malicious signs. Additionally, advanced techniques like ClickFix baiting have been employed by threat actors such as APT28 and MuddyWater, utilizing social engineering to execute malicious commands and allowing for lateral movement within networks, thereby increasing the potential for sensitive data exfiltration.
Indicators of Compromise (8 / 108 total)
All FileHash-SHA1 FileHash-SHA256 domain hostname URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 34ff2f72c191434ce5f20ebc1a7e823794ac69bba9df70721829d66e7196b044 2025-06-16
FileHash-SHA256 10bab67df6d1c2489cb96a5e0d737c7216750a1d89449839a98394c9257b0e0f 2025-06-16
FileHash-SHA256 289b7314679947367e7fcd009eb6512eaf8002dc42f70ba892df197dcfa41971 2025-06-16
FileHash-SHA256 4639fbec6841b850049706fa0d46e4c1c400ec059cbae724fcd757b1c02cbffa 2025-06-16
FileHash-SHA256 a8bf49f8bd853a77f88ff58d3b8af65900a83b7253b23a439abd1413a9130d6c 2025-06-16
FileHash-SHA256 c131495e6da85ad210c564ee45870f3965e5a24b3a1418cd2da7debcb7b64a9a 2025-06-16
FileHash-SHA256 fbcc4571846d521eb6f4adfdf44fb0e7050b295ca7bedf8230c6a7f3fc3fc18d 2025-06-16
FileHash-SHA256 dabc552e18e8f4bd460e609b51196c781ce99c721a47d5024a5469b77be05b71 2025-06-16