Honda Hackers May Have Used Tools Favored by Countries

A computer virus hit the Japanese automaker Honda this week, disrupting its internal computer networks, forcing it to shut factories across the globe and leaving employees cut off from email or internal servers.

While Honda has declined to name the attackers or the tools they used, cybersecurity analysts said that the attack appears to have been carried out by software designed to attack the control systems for a wide variety of industrial facilities like factories and power plants. Such cyberweapons previously were only known to have been used by state agents.

In the hands of criminals, the tools could be used not just to steal data or disrupt business operations but to bring factories to a grinding halt or switch off power grids.

Previous assaults on Japanese corporations have been aimed at disrupting communications, or stealing or holding data hostage, according to Masahiro Shimomura, head of the Japan Network Security Association.

“This is a real advancement,” he said. “The ability to infect process controls, in other words, the production line, that means it’s quite advanced.”

In a statement, Honda said it canceled production at most North American plants on Monday, resumed production at some on Tuesday and had all back running by Thursday. The virus also halted work at Honda factories in Brazil, India and Turkey. The company said it had so far found no evidence of a loss of personally identifiable information.

Emails sent by Honda to American auto dealers said that the virus had affected the American Honda Finance Corporation, which was unable to “answer calls, fund contracts, provide payoff quotes or service customer accounts.” A system that automatically orders parts for dealers was also suspended, and dealers were unable to submit new warranty claims, the emails said.

On Friday, Misako Saka, a spokeswoman for Honda, said that the company had “almost entirely recovered.”

Production at the company’s factories “was temporarily paused to ensure safety,” she said, adding that the company reopened the last factory, located in Ohio, on Thursday morning.

The attack was identified Monday morning in Japan, when employees could not open their email or files, she said, adding that the virus had “penetrated an internal sever and then spread.”

The company ordered employees not to turn on corporate computers and temporarily shut factories to assess the extent of the damage.

The cybersecurity firm Malwarebytes and other analysts said that the tool used in the attack was most likely a relatively new variety of ransomware meant to disrupt industrial systems, in addition to the standard practice of encrypting files.

The most famous example of a virus that targets industrial controls is Stuxnet, which was jointly developed by Israel and the United States and used to destroy over 1,000 centrifuges used in Iran’s uranium enrichment program.

  • Updated June 12, 2020

    • Does asymptomatic transmission of Covid-19 happen?

      So far, the evidence seems to show it does. A widely cited paper published in April suggests that people are most infectious about two days before the onset of coronavirus symptoms and estimated that 44 percent of new infections were a result of transmission from people who were not yet showing symptoms. Recently, a top expert at the World Health Organization stated that transmission of the coronavirus by people who did not have symptoms was “very rare,” but she later walked back that statement.

    • How does blood type influence coronavirus?

      A study by European scientists is the first to document a strong statistical link between genetic variations and Covid-19, the illness caused by the coronavirus. Having Type A blood was linked to a 50 percent increase in the likelihood that a patient would need to get oxygen or to go on a ventilator, according to the new study.

    • How many people have lost their jobs due to coronavirus in the U.S.?

      The unemployment rate fell to 13.3 percent in May, the Labor Department said on June 5, an unexpected improvement in the nation’s job market as hiring rebounded faster than economists expected. Economists had forecast the unemployment rate to increase to as much as 20 percent, after it hit 14.7 percent in April, which was the highest since the government began keeping official statistics after World War II. But the unemployment rate dipped instead, with employers adding 2.5 million jobs, after more than 20 million jobs were lost in April.

    • Will protests set off a second viral wave of coronavirus?

      Mass protests against police brutality that have brought thousands of people onto the streets in cities across America are raising the specter of new coronavirus outbreaks, prompting political leaders, physicians and public health experts to warn that the crowds could cause a surge in cases. While many political leaders affirmed the right of protesters to express themselves, they urged the demonstrators to wear face masks and maintain social distancing, both to protect themselves and to prevent further community spread of the virus. Some infectious disease experts were reassured by the fact that the protests were held outdoors, saying the open air settings could mitigate the risk of transmission.

    • How do we start exercising again without hurting ourselves after months of lockdown?

      Exercise researchers and physicians have some blunt advice for those of us aiming to return to regular exercise now: Start slowly and then rev up your workouts, also slowly. American adults tended to be about 12 percent less active after the stay-at-home mandates began in March than they were in January. But there are steps you can take to ease your way back into regular exercise safely. First, “start at no more than 50 percent of the exercise you were doing before Covid,” says Dr. Monica Rho, the chief of musculoskeletal medicine at the Shirley Ryan AbilityLab in Chicago. Thread in some preparatory squats, too, she advises. “When you haven’t been exercising, you lose muscle mass.” Expect some muscle twinges after these preliminary, post-lockdown sessions, especially a day or two later. But sudden or increasing pain during exercise is a clarion call to stop and return home.

    • My state is reopening. Is it safe to go out?

      States are reopening bit by bit. This means that more public spaces are available for use and more and more businesses are being allowed to open again. The federal government is largely leaving the decision up to states, and some state leaders are leaving the decision up to local authorities. Even if you aren’t being told to stay at home, it’s still a good idea to limit trips outside and your interaction with other people.

    • What are the symptoms of coronavirus?

      Common symptoms include fever, a dry cough, fatigue and difficulty breathing or shortness of breath. Some of these symptoms overlap with those of the flu, making detection difficult, but runny noses and stuffy sinuses are less common. The C.D.C. has also added chills, muscle pain, sore throat, headache and a new loss of the sense of taste or smell as symptoms to look out for. Most people fall ill five to seven days after exposure, but symptoms may appear in as few as two days or as many as 14 days.

    • How can I protect myself while flying?

      If air travel is unavoidable, there are some steps you can take to protect yourself. Most important: Wash your hands often, and stop touching your face. If possible, choose a window seat. A study from Emory University found that during flu season, the safest place to sit on a plane is by a window, as people sitting in window seats had less contact with potentially sick people. Disinfect hard surfaces. When you get to your seat and your hands are clean, use disinfecting wipes to clean the hard surfaces at your seat like the head and arm rest, the seatbelt buckle, the remote, screen, seat back pocket and the tray table. If the seat is hard and nonporous or leather or pleather, you can wipe that down, too. (Using wipes on upholstered seats could lead to a wet seat and spreading of germs rather than killing them.)

    • Should I wear a mask?

      The C.D.C. has recommended that all Americans wear cloth masks if they go out in public. This is a shift in federal guidance reflecting new concerns that the coronavirus is being spread by infected people who have no symptoms. Until now, the C.D.C., like the W.H.O., has advised that ordinary people don’t need to wear masks unless they are sick and coughing. Part of the reason was to preserve medical-grade masks for health care workers who desperately need them at a time when they are in continuously short supply. Masks don’t replace hand washing and social distancing.

    • What should I do if I feel sick?

      If you’ve been exposed to the coronavirus or think you have, and have a fever or symptoms like a cough or difficulty breathing, call a doctor. They should give you advice on whether you should be tested, how to get tested, and how to seek medical treatment without potentially infecting or exposing others.

The attack on Honda, Malwarebytes wrote in a recent blog post, was probably carried out using a variation on a group of programs called Snake — also known as Ekans, or snake spelled backward — which was identified in December.

The company based its assessment on information posted to an online repository. Attempts to run the code in the company’s lab showed that it was specifically aimed at Honda’s internal networks, Malwarebytes wrote.

Although Honda has declined to specify how the virus entered its networks, speculation has centered around a possible breach related to remote working policies put in place after the beginning of the coronavirus pandemic.

A system that gives employees remote access to internal networks may have opened an opportunity for hackers to introduce the virus, Malwarebytes wrote.

Neal E. Boudette contributed reporting.

Source Article