SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security

Siemens: Removing SCADA worm may harm plants

Siemens: Removing SCADA worm may harm plants

By:  Robert McMillan  On: 23 Jul 2010 For: IDG News Service (San Francisco Bureau) Creator

German manufacturer Siemens AG warned users that removing the Stuxnet worm discovered last week could affect industrial operations. The malicious software is written for supervisory control and data acquisition systems.

Removing a dangerous worm that targets industrial systems could disrupt plant operations, Siemens AG warned customers Thursday.

The warning came as Siemens released a new tool that finds and removes the malicious software along with a full-fledged security update for its SCADA (supervisory control and data acquisition) management products.

Siemens on Thursday released the update along with the tool, developed by security vendor Trend Micro. But in a note sent to customers, the company warned users to check with customer support before removing the software from an infected SCADA system. "As each plant is individually configured, we cannot rule out the possibility that removing the virus may affect your plant in some way," the note reads.

The worm was identified by security vendor VirusBlokAda last month. So far, it has been identified on only one system running Siemens' software -- an engineering computer used by an unnamed German organization. "A production plant has not been affected so far," Siemens said.

Called Stuxnet, the worm is the first publicly identified piece of malware to target SCADA computers, which are used to control things such as manufacturing plants and utility systems. The worm copies itself to other USB systems on the computer and scans for Siemens Simatic WinCC or PCS 7 software. If it finds one of these programs, it tries to upload data from the systems to the Internet.

Siemens doesn't know who built the worm, but is investigating and plans to pursue the matter to the "full extent of the law," the company said on its website.

Robert McMillan covers computer security and general technology breaking news for The IDG News Service. Follow Robert on Twitter at @bobmcmillan. Robert's e-mail address is robert_mcmillan@idg.com


Sign up for our Newsletters












Print |  Views: 947   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




robert mcmillan Robert McMillan is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

After worm, Siemens says don't change passwords
After worm, Siemens says don't change passwordsAlthough a newly discovered worm could allow criminals to break into Siemens AGs industrial automation systems using a default password, Siemens is telling customers to leave their passwords...
Worms spur new protection methods
Worms spur new protection methods In light of myriad malicious code crawling across the Web, security software vendors are devising new methods to protect PCs. But industry observers say the problem won’t be solved by technology alone.
Federal Government Secure Channel boondoggle finally being made visible
an article by kathryn may of the ottawa citizen exposes the "secure channel" boondoggle. this is the same project that was mentioned in the
blog comments powered by Disqus