NSBM Green University
Faculty of Computing
Computer science
(CS002.2 ) Network and Cyber Security
Module Lecturer: Madusanka Mithrananda
Assignment / Case Study
Student Name: kumarathunge v d s
Student ID: 34701
Acknowledgement
I would like to express my sincere gratitude to my lecturer, Madusanka
Mithrananda, for their guidance and support in completing this
assignment. I also appreciate the available online resources that provided
valuable information.
Table of Contents
1 Introduction
2 Cyberattack Case Studies
2.1 Stuxnet (2010)
2.2 WannaCry(2017)
2.3 SolarWinds Hack(2020)
2.4 Colonial Pipeline Ransomware (2021)
2.5 Equifax Data Breach(2017)
3 Conclusion .
4 References
Introduction
In the modern era of the internet, cyberattacks have risen to
become a serious menace. They usually inflict massive injury on
individuals, organizations, and even governments. In order to
ascertain who was hit, who did it, what the attackers'
motivations were, what vulnerabilities were leveraged, and
which CIA (Confidentiality, Integrity, Availability) principles
were breached, this research looks at five notable attacks. These
attacks are analyzed to strengthen cybersecurity practices and
sensitize awareness.
Cyberattack Details
1. Stuxnet (2010)
• Targeted Entity: supervisory control and data
acquisition (SCADA) systems and is believed to be
responsible for causing substantial damage to the Iran
nuclear program
• Attacker: no-one of cially claimed responsibility for
Stuxnet, it is widely accepted that it was a joint creation
between the intelligence agencies of the US and Israel
• Motivation: to secretly destroy Iran's nuclear program by
damaging the centrifuges used to enrich uranium.
• Vulnerabilities Exploited:
fi
◦ Windows Shortcut Vulnerability
(CVE-2010-2568)Siemens PLCs with default
passwords.
◦ Privilege Escalation Vulnerabilities
◦ WinCC/SCADA Exploits (Siemens)
• CIA Violations: Integrity & Availability
[Link](2017)
• Targeted Entity: Global, more than 150 countries including
UK NHS hospitals. And more than 200,000 computer
catched to it
• Attacker: North Korea’s Lazarus Group.
• Motivation: Financial extortion.
• Vulnerabilities Exploited: Used EternalBlue exploit (NSA
leak) targeting a vulnerability in SMBv1 on Windows.
•
• CIA Violations: Availability & Con dentiality
3. SolarWinds Supply Chain Attack (2020)
fi
• Targeted Entity: SolarWinds clients , mainly U.S.
Government Agencies like DHS,DOD,NIH,DOE,NNSA
• Attacker: Russian APT29 (Cozy Bear)
• Motivation: Espionage.
• Vulnerabilities Exploited: used a method known as
a supply chain attack to insert malicious code into the Orion
system.
• CIA Violations: Con dentiality & Integrity
4. Colonial Pipeline Ransomware (2021)
• Targeted Entity: Colonial Pipeline Company.
• Attacker: DarkSide (ransomware-as-a-service group).
• Motivation: Financial gain.(asking for 75btc or 4.4million
usd)
• Vulnerabilities Exploited: The attackers gained access to
the system using a compromised password for an
inactive virtual private network (VPN) account, which did not
have multi-factor authentication enabled
• CIA Violations: Availability
fi
5. Equifax Data Breach (2017)
• Targeted Entity: Equifax Inc, effected 147 million people, or
over 40% of the U.S. adult population
• Attacker: Chinese state-sponsored actors.
• Motivation: personal data thief birth year, social security
number, names, password …etc
• Vulnerabilities Exploited: Unpatched Apache Struts
(CVE-2017-5638).
• CIA Violations: Con dentiality
References
1. Zetter, K. (2014). Countdown to Zero Day: Stuxnet and the
Launch of the World’s First Digital Weapon. Crown
Publishing.
2. Greenberg, A. (2019). Sandworm: A New Era of Cyberwar
and the Hunt for the Kremlin’s Most Dangerous Hackers.
Doubleday.
3. U.S. Department of Justice. (2020). SolarWinds Cyber
Attack Indictment. Retrieved from DOJ Website
fi
4. FBI. (2021). DarkSide Ransomware and Colonial Pipeline
Disruption. Retrieved from [Link]
5. Krebs, B. (2017). Equifax Breach Fallout. Krebs on Security.
Retrieved from [Link]
6. [Link]