From Exploits to Forensics: Unraveling the Unitronics Attack
ID: 4897ddbe-7b83-52fe-8f1d-77ee8cd83988
STIX ID: report--4897ddbe-7b83-52fe-8f1d-77ee8cd83988
Feed Name: Claroty Team82
Threat Score
Team82 documents their reverse-engineering of Unitronics’ proprietary PCOM protocol and the development of two forensic tools (PCOM2TCP and PCOMClient) to extract evidence from Vision/Samba PLCs; their research uncovered two CVEs and detailed how an Iran-linked group (CyberAv3ngers) exploited weak authentication to deface water-treatment facility devices, while the report also enumerates PCOM opcodes and PLC-resident forensic artifacts (VisiLogic project file and signature log).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
