Go back

Raphael Arakelian on Operation Grim Beeper

36m 42s

Raphael Arakelian on Operation Grim Beeper

Operation Grim Beeper, a two-day attack in 2024, involved the remote detonation of pagers and walkie-talkies favored by Hezbollah, causing mass casualties. Researcher Rafael Arkelyan, from Accenture, conducted in-depth analysis, focusing on the technical and supply chain dimensions. The operation was highly complex, requiring a sophisticated supply chain compromise that included creating dummy companies and embedding explosives (PETN) and non-metallic detonators into the devices during manufacturing. The firmware was modified to receive specific messages that triggered detonation, while circuitry changes ensured the electro-kinetic effect. Concealment was key, with materials chosen to bypass X-ray inspections. Arkelyan posits that remote triggering likely relied on an internal network, such as a compromised message gateway or insider, rather than external airborne platforms, due to Lebanon's mountainous terrain and the need for broad coverage. He categorizes this as a hardware Trojan with malicious firmware, emphasizing lessons for OT and supply chain security. The attack underscores the need for robust supply chain verification, firmware integrity checks, and defense-in-depth strategies to prevent similar cyber-physical threats. Arkelyan's research highlights how traditional security assumptions, especially around trusted hardware and software, can be exploited in modern warfare.

Transcription

4717 Words, 27247 Characters

English
[MUSIC] >> Welcome back to the Nexus podcast. Rafael Arkelyan joins me. Rafael is the OT and IOT cybersecurity manager at Accenture. And he has conducted in-depth research into Operation Grim Beeper. That's the name given to a two-day attack in 2024 in the Middle East where explosives were introduced into pagers and walkie-talkies favored by Hezbollah. The attack injured more than 1,500 and killed dozens and Rafael's research looks at several technical aspects of this attack. And he also shares some lessons and security gaps that can be applied across the OT and supply chain ecosystems. So I've been looking forward to getting Rafael on the show to talk about this. I'm glad we can make it work out. How are you? Rafael, good to see you. >> And nice to see you, Michael. Thanks for having me on the podcast. I've been following it for a few years now and I'm excited to talk to you more about it. >> Thank you. Thank you. I appreciate that. So tell me a little bit about yourself in your security background. I think people like to hear about kind of people's paths into this career. >> Sure. So actually, I don't really come from a cybersecurity background. My background is in chemical engineering. Both my bachelor's and master's were in chemical engineering. I specialized in wastewater treatment. So really not related to security whatsoever. Although, as we know, chemical engineering and engineering backgrounds have security and safety, an angle or lens that can be translated into cybersecurity, I would say most of my life, if not my entire life, I've been a computer geek. I loved computers. I loved solving technical problems, breaking them down. So while in university, I made a decision to shift from chemical engineering to this niche field that at the time was getting quite a bit of attention, which is OT cybersecurity. >> Right. >> And that's the first job that I landed who was in OT cybersecurity. >> I'm just curious from an OT cyber perspective, what do you think has been kind of the turning point? Because you're right, it's definitely one of the hot aspects of the cybersecurity industry. Have you noticed anything lately that's kind of turned the corner for OT cybersecurity and all the attention that it's getting? >> Well, I think there's a lot of historical events that happened as many different countries experiencing attacks that had a cyber physical impact. There's Stuxnet, that is the super famous one. But I would attribute my career beginning to the shift in industry or let's say the popularity in the industry of deploying technical controls that were now helping solve the challenges that OT environments were facing. And that's related to OT visibility. And it's not a recent technical control. And obviously there were a lot of attempts for understanding how to assess OT environments, whether it was through the NERC-SIP efforts or other efforts. But my personal, let's say journey started with, because of the market's attention on those OT visibility products, and that happened around, I guess, between 2016 and 2018 when the buildups started happening. >> Sure. >> So yeah, and those journeys will continue to evolve as events happen worldwide. Recently, the attack in Poland is another, let's say, important milestone that has garnered attention in ways will affect the landscape of OT cybersecurity. >> So let's jump into Operation Grim Beaper and the research that you conducted. Obviously, this is one of the most disturbing cyber physical attacks on record. So many elements to these incidents aside from the geopolitical aspects. What, I'm curious, what was the motivation? What motivated you to look so extensively into the technical aspects of these attacks and the supply chain part of it as well? >> Yeah, well, I would say, yeah, this attack definitely got a lot of attention worldwide and the reactions definitely fall in a range. Sometimes affected by the geopolitics, sometimes outside of that, right? More from a technology utilization standpoint. But I would say one of the key underlying themes or reactions was still one of all. A lot of people said, well, including myself, when I first heard and saw it, it's like, this could be straight from a James Bond movie. I haven't watched all the James Bond movies, but I don't know any personal ones where such an operation happens at such a scale and against an organization that has a lot of, let's say, they have their own security mechanisms and so on and also be so successful at the same time. So the complexity, the success, the nature of it is really what drove me to understand this attack and try to break it down from my standpoint and see how it applies to OT environments and the ICS ecosystem. >> And how would you characterize the complexity involved? Because I mean, we're talking about hundreds or thousands of these pages and walkie talkies. Again, the supply chain aspect of this. How do you characterize the complexity? >> I would say highly complex. If I were to quantify it, I would have to do more research. Some research I looked into many operations along the history of warfare, there were operations that were done in Vietnam, for instance, where there were booby traps in ammunition and so on. And there's other operations. Of course, we're not talking about cyber, but just historically part of my presentation at Asfor. I referenced the Greek slash Trojan horse and its importance in the history of warfare. Of course, that story is known as a myth or legend, but when I look at everything at this 10,000 foot view, it's Operation Green Beaper, highly complex, very sophisticated, supply chain, compromise was involved. It was crafted at the design phase, so it wasn't just a simple insertion somewhere in the supply chain. So all those elements together really put it in a, let's say, high percentile quarter, if we were to look at the history of warfare. As you enter a research project like this, are you, do you come into it having already identified some gaps in the story, for example, or some areas in the research that you particularly want to focus on? How do you, how do you jump into a research initiative like this? That's a great question. It's actually something I learned while at university during my masters, because I was working on a thesis and I had done that even before in undergrad. We had a specific course that actually taught this approach, and it's a fairly common approach, it's nothing novel. The course was titled Research Methods, and that's actually what I utilize as part of these projects. One of the first things you do is a literature review. So as part of my literature review, I was looking at all the news outlets. When this happened, I was reading articles, people dissecting the attacks, whether it was on Twitter or formerly known as Twitter on X, on Reddit, watching YouTube videos. And that was just in the beginning. So it was after the attack around October, September, 2024, and I was following the analysis. And there's a lot of learning that I do as part of this literature review, because you're basing your understanding on what others have. understood so far. And I kept following the updates and information because there were more investigations, more reports. There was a lot of investigative journalism that was happening in different countries. So I kept following that. But at some point, I made a conscious decision that this was clearly-- I had clearly had a cyber element to it. There were so many assumptions about how safe these products were. And in my head, I thought this would be a great angle to investigate from OT security standpoint. And that's when I got more into the formal, let's say, research methods where I sat down, watched hundreds of YouTube videos, media reports, even research papers. There weren't many that were published, but there are some very good ones in particular. There's one from University of Florida, which was great. So yeah, combined all that information to identify the gaps that I was seeing and also to create this holistic or comprehensive view of what were the most likely theories of what happened. And I mean, there was clearly some extensive planning in this, just the supply chain part of it, identifying the manufacturers, building dummy companies. And you mentioned your S4 presentation, which was really well done. Go through some of that aspect of this for the listener. I think that's really fascinating in addition to the technical part of this. Yeah. The supply chain part definitely very interesting. I referenced that in my presentation. I also referenced the article that had that visual. It showed the various entities that were identified, that were involved in the operation or suspected to be involved, or even without awareness of what the operation is going to be they had a role to play. That article, Crypto Museum, by the way, it references events in the past and basically has an archive function, is actually based on what other journalists had looked at in different countries. So there was investigative journalism happening in Taiwan, in Hungary, in Bulgaria, in Hong Kong. So the authors of that page had pieced everything together. And I found it very interesting because we could see the relationships between the organizations. You mentioned the dummy companies. So certainly, BAC Consulting was one. There was a North-A-Global, another one that played an intermediate role. There were also companies that were involved on the financial side. So Ellenburg Trading Company in Hong Kong. And it was supposed to have a company or a base in Switzerland. But when journalists who investigated that, they didn't actually identify any traces related to that company in Switzerland, for instance. So going to those references, looking at them was definitely very interesting. But one of the things that I actually mentioned in my presentation as well, I quote the Mossad agent actually from the CBS 60 Minutes interview. They talk about how they can develop scenarios. They can create a pretend world. And that's really true because what we know about these companies and these links can just be at the surface level. I don't know how many levels of other companies were also involved. So it's definitely very complex and very neat to gather those pieces and put them together. Right. But obviously, they had to have some intelligence. Either someone on the inside or just some form of intelligence had told them just from a base level, they preferred these types of pages and walkie talkies, for example. This wasn't just a random event. Yeah, so yeah, that's a good point. So there's two sides to that. First, whether it was an individual or multiple individuals that are responsible for the armed supply for Hezbollah, I can't say if they're compromised in the sense that they were playing the role of an insider. It seems highly unlikely because there could also be multiple chains of that role, not just a single point of contact that is doing the arms supplying. But whether those were compromised, it's hard for me to say directly. But there were reports of targeting ads in terms of the pages themselves. So that's, I guess, after the ideation phase or the design phase. But before all of that, I would say it was like a transition period that the threat actors were aware of that they had prepared for. And I am quite certain that it wasn't just a single scenario that they were prepared for. They had multiple, multiple scenarios based on evolution of events that they had prepared for. They were aware that Hezbollah is moving away from the use of cell phones or smartphones, things that were basically helping tracking them down. Even their leader at some point in early 2024, if I'm not mistaken, had publicly disclosed that they should stop using smartphones because of how it's impacting them. So I'm sure intelligence was preparing for all of that in advance as part of one of many scenarios. And we can know that many scenarios were prepared because in fact, there were two attack vectors. There were the pages themselves and the walkie talkies. Who knows what other attack vectors were involved in ideation or in other operations. But yes, all that information that was collected and all the targeting that was done helped facilitate deliver this attack. So can you explain from a high level, of course, what they did to the pages, what was done to the pages. It's such a small form factor to, you know, and what was done to them to get them to detonate. Because I know during your talk, you described how you built a couple of proof of concepts of the page of architecture, the batteries, et cetera. So before I talk about that piece, you know, improvised explosive devices or IEDs, the five key elements that they need is a power source, a switch, explosives, or the main charge, a detonator to basically play the role of the initiator. And then you need a container or a casing. Those are the five key elements. The pages by nature and actually also the walkie talkies have three out of those five key elements. They have a power source, the battery. They have a switch in there to switch between certain functions at a hardware level. And they also have the container or the casing. And that's because of the form factor itself. So the threat actors had to introduce two things, the main explosives and the detonators. So I mentioned this in the presentation, based on forensic analysis, reports suggest that the main explosive that was used was penta-erithritol tetranitrate or peta. And the reason they would have used that is because it's actually an organic compound. And why are organic compounds, you know, the right candidate because they're much more difficult to detect with, you know, using X-rays. And if the intelligence was already there about what type of X-ray machines and what configurations are being used at the Lebanese International Airport, because there's only one main international airport, then that could have also informed the decision making on, you know, how to design things and what substances to select. And the reason I mentioned that, because there were reports from Lebanese authorities that indicated that, yes, you know, Hizbullah had done some sort of a check using the X-ray systems that they have on these pages. but they hadn't detect anything. How reliable is that? claim, I don't know, it's kind of difficult when you're relying just on those type of reports. And then the last element that they would have added is the detonator itself. And again, there's reports suggesting that they would have used a non-metallic substance or strip to play that detonator role. And again, for the same reason of minimizing the likelihood of detection if those pages were to be detected. So at a high level, those two elements were introduced. But on top of that, it's important for me to mention that the firmware was also designed in a way that it receives, you know, when it receives a specific message, it helps generate some sort of a trigger that, you know, has an electric effect and then a kinetic effect. So at a high level, adding components was an important step. Having a firmware that, you know, feeds this use case of detonation was another step. The circuitry was also an important step or modification that the threat actors had to do. In other words, how would the detonator slash explosives interface with the firmware so that the trigger could then cause that electro kinetic impact? So yeah, I would say those were at at the high level. And of course, the underlying theme of all of those would be concealment, you know, identifying components, compartments that would minimize the likelihood of detection, whether it's using visual inspection, you know, just examining under the eye or using the X-ray equipment. And then the key is obviously to trigger them remotely somehow. Can you explain how that was carried out? Because there was some question during your presentation about, you know, the network that was used, whether it was external or internal to the victims. So just curious, if you could explain that aspect of it. Yes. So I didn't get a chance to talk too much about it in the presentation. I did want to mention that there was actually very little commentary and theories around that portion of the attack. So it was definitely very interesting to think about it. There was some, there was some commentary, which I found helpful, but I categorized it into two scenarios, right? The external network and the internal network. And I also didn't mention during the presentation. So this is a good opportunity to mention that is that my personal opinion leans more towards the internal network usage. I'm not saying that the external network is an impossible, let's say, you know, method or approach, but I felt that there were two key elements that would hamper the reliance on on on that approach. And the first one is detailed configuration parameters for the pages, because even though the threat actors designed these pages, there were certain elements that could be reconfigured by Hezbollah, like the digital addressing. They could have reconfigured that and that was by design. And it's interesting because sometimes I wonder like, was there some functionality in the pages that also would remotely emit information about the pages to the threat actors? So they, you know, reveal information about the page or configuration parameters. But that would be quite quite sophisticated, whether it's even necessary. I'm not sure. Maybe there were insiders that could provide the page or configuration parameters. Or, you know, maybe as part of this package of 5,000 pages, Hezbollah also got a message gateway as a free gift that was also compromised. And, you know, that could be used, that could be used to, you know, have the information about the page or parameters. But regardless, I think this roadblock is not a major one or is not as much of a roadblock as the second, the second consideration, which was the terrain and bunkers. Because these attacks happened over multiple regions in Lebanon. So it wasn't just in the capital Beirut, it wasn't the south and in Balbuk, you know, which is surrounded by mountainous regions. There were reports of explosions in Syria. So that made me, you know, you know, think that airborne platforms or although they have been used in the past to deliver remotely triggered, you know, remotely triggered explosions, at this scale, it for me, it seems difficult. Because of the transmission power and because of the, yeah, transmission power and because of the coverage. That's why I lean more towards the internal. So, yeah, a compromised internal asset. So the message gateway example that I gave before, where, you know, you order 5,000 pages and you get a free message gateway that's compromised. That would fall under the internal. Right. If you have just insiders that somehow send a message that is coded in the firmware, that's going to remotely trigger the, the, the pages, that would be another example of insider. And for me personally, it seems more likely. And then it had to be obviously introduced into the supply chain in order to get to the victims. So there was an understanding of that. But the, the introduction of the supply chain is probably a really fascinating and maybe unknown aspect at this point as well. Right. Yeah. So this based on everything that I analyzed, not just on this attack, but in terms of terminology and so on, this threat was a, you know, clearly a supply chain compromised, but specifically a hardware Trojan. And I also talk about it. It's not, it, just a traditional hardware Trojan because there's a modified or not really modified by design a malicious firmware. So there's the hardware Trojan and then there's the malicious firmware. And the malicious firmware is actually the piece that is acting as, let's say, the logic trigger versus in traditional hardware Trojans. And I didn't get to, you know, explain this in the presentation. They're kind of more self-sufficient. There's some element of logic that is incorporated that, you know, ends up triggering whatever reaction or functionality that is hidden or embedded. So hardware Trojan and with, with a firmware maliciousness. And this supply chain part is interesting because this was done, you know, at the design phase. But hardware Trojans, when we look at the literature and in the academia, there's actually a lot of thought on hardware Trojans. Unfortunately, I feel in the, you know, in the literature, they kind of struggle to find real life scenarios because they're not often reported, not identified as much. And the characteristic of a hardware Trojan is that it doesn't have to be just at the design phase. And it can be at any point of the supply chain. And that's, you know, a possible scenario or a reality that these types of attacks can be at any point of the supply chain. It could be at the design of the product, design of the chips, assembly of the products, assembly of the boards, manufacturing, transport. And even in, oh, and I did quote Andrew Huang. He does an excellent job of breaking, of breaking this down. And he specializes really in identifying hardware Trojans. And he runs a blog round out. And he talks about this is sort of the gray or secondary market. So if you, for example, you know, if you're playing the role of a threat actor, you can buy a hundred keyboards from an official store. And you can, you know, maliciously or with intent, modify those hundred keyboards to have some sort of a hardware Trojan. And you can return them. And those hundred keyboards actually enter the ecosystem. And now they're part of the ecosystem. So I thought that's very interesting as well. Yeah. All right. So before we wrap up, I'd love to hear just kind of your take on, let, from a lessons learned perspective, how could this ever extend into the OT ecosystem? For example, do you imagine there are a class of OT assets that might, might be susceptible in a similar way? For example, yeah, that's a, that's a great question. So, from my standpoint, really, this type of attack is applicable on any electronic device. And I mentioned that because modern electronics are, you know, relying on chips when there's chips involved or integrated circuits, then there is a modification. that can be done in terms of the logic, the chip itself can be modified, and new logic can be introduced. So there's let's say a few angles to be able to come up with a hardware Trojan. And so the thing is it can apply to, and I list those out, peripheral devices, controllers, sensors, your CPU, charging cable, battery packs, anything. But the reality is, and this will allow me to start talking a bit about the lessons and the security standards, is that security standards, you know, they realize that or acknowledge that technical mitigations can't be done on everything at the same time. So that's why as part of supply chain risk management, there's an approach in terms of quantifying the risk or assigning risk profiles to the various devices based on how important they are, like their criticality, based on the vendor, based on the source of origin of that vendor, the influence of the government of that country where the vendor resides, the visibility into the suppliers of that vendor. So all of those are important because that will give different risk profiles to different types of devices that go into the OT system or OT networks. And it's going to be really on a case by case basis, based on that organization, and based on what vendors they're using. So I wish I could, you know, give more, let's say, thoughts about the solution to this entire problem, but I feel it's more like, you know, deep seated, it comes back to supply chain security, supply chain security is something that's been, you know, been evolving and the its importance has been discussed for the past couple of decades. And I think it will continue evolve as we see more and more efforts in terms of the types of security standards, types of technical mitigations, but it's, it's certainly not a easy challenge. And I guess my final key message, it's not that, you know, organizations shouldn't be panicking and saying like, you know, oh, do we have an equivalent of a pager or a controller and not even just a kinetic impact, maybe just data leakage or something that is designed. And no, like that's that wasn't my message of my presentation and my message now. It's more about do you have a supply chain risk management program that thoroughly evaluates your vendors? Do you have specific criteria to determine or at least objectively give some sort of a metric to quantify the visibility that you have into that vendor and their suppliers? And are you actually utilizing that to apply it on your critical, critical assets? And if you don't, then there's a lot of security standards around that. And you should be, be, be, you know, putting efforts to focus on that. Final question. So from the victim's point of view, how is this over what? How did they miss this? Is it, or is it fairly easy to miss something like this? I guess it's what I'm asking. Well, I mean, for his, I don't really assume that they would be relying on any missed frameworks when they're evaluating their vendors. So I would reframe it more into what OT organizations, like if this was an organization that is, you know, a legitimate organization that is in this scenario, what could they, what could have they done to not overlook this? Well, first of all, they should realize, and I guess that's the lesson learned, don't rely too much on the idea of the simplicity of the device, because that was a very big factor that was actually taken advantage of or utilized to, to be able to execute this attack. They thought, Oh, because pages are kind of like these dumb devices, there's going to be no impact. The evaluation of the vendor wasn't, you know, a done thoroughly the devices themselves, again, based on criticality. If, you know, if you know that these devices have such a critical role, then you need to have some sort of a criteria. Like, how many of the devices do I sample? What sampling techniques do I use? Do I, you know, am I, you know, reverse engineering the devices or what type of, am I doing firmware level mitigations for these devices? So all of those would come as part of a supply chain risk management program. And if you are first, you know, overlooking the importance of the device, you're not having to go through those procedural and then technical mitigations, then you're going to be overlooking, you know, an attack factor that will, will lead to such a kinetic or not just a kinetic impact, but a sort of a cyber physical impact. Alright, FAL. Great stuff. This is obviously a very fascinating story. And, you know, I'm sure we only scratch the surface of it. But I want to thank you so much for coming on the podcast. I really appreciate it. And I think people are really going to enjoy this conversation. Thanks a lot, Michael. It was great talking to you. And yeah, let's stay in touch. Absolutely. Alright, take care.

Podcast Summary

Key Points:

  1. Operation Grim Beeper was a 2024 attack in the Middle East where explosives were placed in pagers and walkie-talkies used by Hezbollah, resulting in over 1,500 injuries and dozens of deaths.
  2. The attack involved a highly complex supply chain compromise, with dummy companies and modifications at the design phase, including the addition of explosives (PETN) and non-metallic detonators to evade X-ray detection.
  3. Researcher Rafael Arkelyan, an OT and IoT cybersecurity manager at Accenture, analyzed the technical aspects, including firmware modifications, circuitry changes, and concealment methods.
  4. Arkelyan suggests the attack likely used an internal network (e.g., a compromised message gateway or insider) for remote triggering, rather than external airborne platforms, due to terrain and coverage challenges.
  5. The attack is classified as a hardware Trojan combined with malicious firmware, highlighting critical OT and supply chain security gaps.

Summary:

Operation Grim Beeper, a two-day attack in 2024, involved the remote detonation of pagers and walkie-talkies favored by Hezbollah, causing mass casualties. Researcher Rafael Arkelyan, from Accenture, conducted in-depth analysis, focusing on the technical and supply chain dimensions. The operation was highly complex, requiring a sophisticated supply chain compromise that included creating dummy companies and embedding explosives (PETN) and non-metallic detonators into the devices during manufacturing.

The firmware was modified to receive specific messages that triggered detonation, while circuitry changes ensured the electro-kinetic effect. Concealment was key, with materials chosen to bypass X-ray inspections. Arkelyan posits that remote triggering likely relied on an internal network, such as a compromised message gateway or insider, rather than external airborne platforms, due to Lebanon's mountainous terrain and the need for broad coverage.

He categorizes this as a hardware Trojan with malicious firmware, emphasizing lessons for OT and supply chain security. The attack underscores the need for robust supply chain verification, firmware integrity checks, and defense-in-depth strategies to prevent similar cyber-physical threats. Arkelyan's research highlights how traditional security assumptions, especially around trusted hardware and software, can be exploited in modern warfare.

FAQs

Operation Grim Beeper is the name given to a two-day attack in 2024 in the Middle East where explosives were introduced into pagers and walkie-talkies favored by Hezbollah, killing dozens and injuring over 1,500 people.

Rafael was motivated by the attack's complexity, success, and scale, which he compared to a James Bond movie, and he wanted to break it down from an OT and ICS cybersecurity perspective.

The five key elements are a power source, a switch, explosives (main charge), a detonator (initiator), and a container or casing.

They inherently included a power source (battery), a switch, and a container (casing), so attackers only needed to add explosives and a detonator.

Pentaerythritol tetranitrate (PETN) was reportedly used because it is an organic compound that is harder to detect with X-ray machines.

The firmware was designed to receive a specific message that triggered an electric effect, which then initiated a kinetic effect via the detonator and explosives.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.