SCADA Hacking: Inside Russian SCADA/ICS Facilities, Part 2
Welcome back, aspiring cyberwarriors!
We’re continuing our series on SCADA hacking. Today, we’re going to walk through a compromised SCADA system controlling several water towers belonging to a company in Russia. The company was compromised by Cyber Cossacks. The group was trained by OccupyTheWeb to defend Ukraine digitally. Along with the water towers, they gained access to a range of SCADA systems within the organization, from refrigerators to pasteurization systems.
System administrators rarely segment SCADA systems from Active Directory and that helps hackers move laterally once they compromise a vulnerable host. Even though this particular company didn’t have a properly configured AD, the group still managed to compromise all the hosts through password reuse. This example should be useful for both blue and red teams. Let’s take a closer look.
Initial Access
It began with access to a database system. The IT team had made some effort to isolate the machine and none of the local credentials were useful anywhere else. There were no cleartext credentials in the registry, PowerShell history or local files. The host was used for development and maintenance of the company’s database, which was outsourced to a third party provider.
The team used Inveigh to capture NTLMv2 hashes when users tried to connect to nonexistent shares. This tool is similar to Responder, but it works on Windows.

Windows automatically tries to authenticate with the host it thinks is hosting the share, sending NTLMv2 credentials along the way. Once captured, these can be cracked offline later. The image above was pulled from the internet to show what this looks like.
Cracking Hashes
After collecting hashes, they ran hashcat against rockyou.txt. A few passwords cracked, giving them access to an accountant’s machine. That became their pivot. The accountant had local admin rights and after dumping local SAM hashes, the group got the Administrator hashed password, which turned out to be reused across multiple machines and SCADA servers running on Windows 7.
Windows 7 Vulnerabilities
Windows 7 is outdated and lacks the security measures newer systems have, yet it’s still common in SCADA environments. Without LSASS memory dump prevention (LSASS PPL), pulling credentials from it is easy. Using NetExec they dumped LSASS and got the Administrator’s actual password.

Inside the SCADA Server
They used RDP to connect to the SCADA server. It had dashboards showing refrigerators and milk pasteurization systems with visual representations of the system status.




They also found schematics built by the engineering team, like the one below with visual layouts of the system operations.

MasterSCADA
MasterSCADA is a common SCADA management application used across different Russian companies. It often has a default “sa” user and a blank password. This system was no different.

Water Tower Access
The water towers were the most interesting find in this operation. They were part of the same SCADA system. The executives had pictures of the physical towers and their drainage pond. The SCADA interface showed pressure and temperature stats.



As mentioned in Part 1, hacking SCADA isn’t always about destroying the Windows machine it’s hosted on. Hackers need to understand how the system actually works. Research is key here. When you’re dealing with water towers and pipe networks, pushing pressure to the maximum is rarely safe. Most water systems are designed to run between 2 to 4 bar (30 to 60 psi). Spiking the pressure to 5 bar can cause serious damage. Weak pipes might burst, fittings and joints can start leaking and plastic components will just fail under this stress.
At night the risks get even higher, because the demand is low. A pressure increase followed by a valve closing or a pump shutting off can create a water hammer. That pressure wave travels through the system and damages valves at the very least.


That’s what happened here. The group raised the pressure to its maximum and left it there. By the time the facility resumed work in the morning, the pressure had been sitting at critical levels for several hours. This kept happening for several days, causing significant damage before the group wiped everything.
Conclusion
SCADA systems aren’t always secured. Often they aren’t segmented and don’t have unique credentials. From a single foothold, the group moved laterally and compromised the entire organization. Ironically, the vulnerable SCADA server helped the hackers do it without any resistance. SCADA is more than just software, as it connects the physical and digital worlds. Mishandling it can bring real and visible consequences.
If you want to learn how to hack and secure SCADA systems, we invite you to our training led by OccupyTheWeb. It’s available for both beginners and advanced students.
The post SCADA Hacking: Inside Russian SCADA/ICS Facilities, Part 2 first appeared on Hackers Arise.