logo

Refinery raid

ID: 4bd7927c-4726-58cf-a3b9-24c22efb6090

STIX ID: report--4bd7927c-4726-58cf-a3b9-24c22efb6090

Feed Name: NVISO Labs

Date Published: 2025-07-29

Date Updated: 2026-04-28

Author: Nick Foulon

...
...

This blog post provides a step-by-step lab guide for setting up the Labshock virtual oil refinery environment and demonstrating OT attack techniques against PLC/SCADA systems, including discovering services, validating access to port 502, and using Modbus TCP with mbtget and a Python script to read and toggle pump states. It highlights common weaknesses such as default credentials and Modbus’s lack of authentication, briefly relates the exercise to real-world ICS incidents like FrostyGoop, and underscores the importance of monitoring and stronger defensive controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.