Password Recovery Tool Infects Industrial Systems With Malware

July 18, 2022

Security researchers at Dragos have uncovered the activities of a threat actor that uses password recovery tools to infect industrial control systems (ICS).

After analyzing an incident involving Automation Direct’s DirectLogic PLCs, the researchers discovered that the cracking software exploited a known vulnerability in the device to extract the password.

The software also dropped a malware known as Sality during the recovery process. Sality is a malware that creates a peer-to-peer botnet for various tasks that require the power of distributed computing to complete faster actions such as password cracking or cryptocurrency mining.

Sality can also inject itself into running processes and abuse the Windows autorun function to copy itself into network shares, external drives, and removable storage devices that could transfer it to other systems.

The malicious software and vulnerability identified have been reported to Automation Direct and the manufacturer has released fixes to address them.

Administrators of PLC from other providers should be aware of the risk of using password cracking in ICS environments. Operational technology engineers are also advised to avoid password cracking tools, especially if the source is unknown.

The sources for this piece include an article in BleepingComputer.

Top Stories

Related Articles

December 30, 2025 A fast-moving cyberattack has compromised more than 59,000 internet-facing Next.js servers in less than two days after more...

December 29, 2025 The U.S. National Institute of Standards and Technology (NIST) has warned that several of its Internet Time more...

December 29, 2025 A critical security flaw has been found in LangChain, one of the most widely used frameworks for more...

December 23, 2025 Editor's Notes: This is the first of two articles reflecting on the year but Yogi Schulz. Schulz' more...

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn