The 2015 Ukrainian grid attack began with Office documents that asked users to enable macros. Which technique is this?
- A.Default credentials on an internet facing HMI panel
- B.Spearphishing attachment carrying a macro document
- C.Drive-by compromise through a watering hole web site
- D.Exploitation of an exposed vendor web portal
Why B is correct
A document that prompts for macros delivered by email is a spearphishing attachment, which gave BlackEnergy its foothold. A watering hole, a web portal bug, and default credentials are different entry techniques.
Know someone studying for OT Security Fundamentals? Send them this one.