Eastern European-based attackers gained access to networks of energy providers by tampering with software updates for industrial control systems, Symantec says. Those affected were energy grid operators, electricity generators and petroleum pipeline operators. The group, which appears to operate from Eastern Europe, added a piece of remote access malware to legitimate software updates, the security vendor says. The companies unwittingly installed the malware by downloading the software updates from the ICS vendors, the company says. Dragonfly group has been around since at least 2011, it targeted defense and aviation companies.”]

