Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In 2019, ForeScout researchers built proof-of-concept malware to show how an attacker might move from an exposed or vulnerable network device into a building automation system. The demonstration outlined possible consequences such as changing access-control records or disrupting building systems; it was not evidence that this malware had been used in a real attack. SecurityWeek reported the findings on January 15, 2019, and its figures describe that period—not today’s exposure or patch status. SecurityWeek’s report

What building automation systems do

Building automation systems use sensors, controllers, and actuators to manage operational functions such as heating, ventilation, and air conditioning (HVAC), lighting, surveillance, elevators, and physical access. Because connected devices can communicate across networks, a weakness in one device or an exposed connection can potentially create a route toward systems that affect real building operations.

ForeScout characterized these systems as more open and interconnected than conventional industrial control systems. That description is the researchers’ assessment reported by SecurityWeek, not a claim that every building automation network is designed or secured the same way.

How the proof of concept could reach building systems

SecurityWeek described several possible routes into the targeted environment. The demonstration was a scenario showing potential paths, not an operational guide or evidence of an intrusion.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Access condition What the 2019 report described
Internet-exposed PLC A programmable logic controller (PLC) reachable directly from the internet could provide an initial route into the building automation environment.
Reachable workstation or IoT device A publicly reachable workstation or internet-connected device could provide an initial foothold, followed by lateral movement toward PLCs.
Air-gapped network SecurityWeek said an attacker would need physical access to the building network if the target network were air-gapped.

In the reported chain, vulnerabilities in IP cameras could provide an initial foothold; misconfigurations and software vulnerabilities could then assist lateral movement and discovery of targeted PLCs. The account does not establish that the same devices, flaws, or routes remain exposed today.

What ForeScout reported finding

ForeScout reported eight vulnerabilities across the products it examined, according to SecurityWeek. Six were previously unknown at the time: XSS, path-traversal, and arbitrary-file-deletion issues in Loytec products, plus XSS and authentication-bypass flaws in EasyIO products. The report said vendors released patches after notification and described these six issues as less severe than the other two.

The two more serious vulnerabilities had already been known to an unnamed vendor and patched, though their existence had not been publicly disclosed, the report said. Researchers described a hardcoded secret used to store user credentials and a buffer overflow that could permit remote code execution on a PLC; SecurityWeek said the issues were used in developing the proof of concept. The report does not identify affected versions or establish current patch status.

What the malware was designed to demonstrate

SecurityWeek reported that the malware was written in Go and that its final payload was written in Java. The packed binary was about 2 MB, which the researchers said was intended to suit devices with limited storage and support fast, stealthy infection.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The final payload could demonstrate physical and operational consequences, including:

  • Changing an access-control database to add a user and badge.
  • Deleting data.
  • Disrupting building automation.

The proof of concept was also designed to edit log files and persist across a reboot. These are capabilities described for the demonstration; they do not show that criminals deployed this malware or carried out those actions in a real building.

What the 2019 figures do—and do not—show

SecurityWeek reported that ForeScout spent $12,000 on development, including research and testing equipment. ForeScout also said searches of Shodan and Censys found nearly 23,000 matching devices, of which more than 9,000 appeared vulnerable. Those figures describe the company’s 2019 search, not a verified current inventory, a present-day vulnerability count, or a measurement of how many buildings could be compromised now.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Was the proof-of-concept malware used in a real attack?

No evidence was reported at the time that malware specifically designed to target building automation systems was being used in the wild. ForeScout’s demonstration showed a possible attack path and potential effects; it was not a confirmed criminal campaign.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SecurityWeek cited separate incidents as context: ransomware at a luxury hotel in Austria reportedly prevented new keycards from being created, while a DDoS attack reportedly disrupted heating in a residential building in Finland. Neither incident was described as involving ForeScout’s proof of concept.

ForeScout cautioned that reproducing the results in a real-world scenario, especially at scale, could be more difficult, while saying the approach was within the reach of groups with malicious intent. That assessment underscores the demonstration’s security relevance without turning its capabilities into evidence of real-world use.

What building operators should take from the report

The lasting lesson is about exposure and connections: a building system’s risk can depend not only on its controllers, but also on devices and network paths that provide access to them. The 2019 report supports reviewing which devices are reachable and how systems are segmented, but it cannot establish whether a specific building or product is currently vulnerable. Present-day decisions require current vendor advisories and an assessment of the actual installation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.