The Attack Against Danish Critical Infrastructure
Michael Weng
S4x24 - ICS Security Conference · Day 1 · Main Stage
Overview
Michael Weng, representing the Danish sector CERT, delivered a compelling presentation at S4x24, detailing a sophisticated and coordinated cyberattack that targeted Danish critical infrastructure in May 2023. The talk, titled "The Attack Against Danish Critical Infrastructure," illuminated how 22 companies across vital sectors were simultaneously compromised through the exploitation of a critical Zyxel firewall vulnerability. Weng's presentation offered a candid look into the challenges and successes of a relatively small, non-profit national CERT in responding to a significant incident with potential state actor involvement.

Key moments
- 0:00 Introduction to Danish sector cert and its scope
- 2:00 Danish sector cert's organization, coverage, and members
- 3:00 Overview of NSM IDS monitoring solution and deployment
- 4:00 May 2023: 22 critical infrastructure companies compromised
- 5:50 Zyxel firewall vulnerability (CVE-2023-28771) was exploited
The Attack Against Danish Critical Infrastructure
Speakers: Michael Weng
Conference: S4
YouTube: https://www.youtube.com/watch?v=8Tp1k-GzA3g
Overview
Michael Weng, representing the Danish sector CERT, delivered a compelling presentation at S4x24, detailing a sophisticated and coordinated cyberattack that targeted Danish critical infrastructure in May 2023. The talk, titled "The Attack Against Danish Critical Infrastructure," illuminated how 22 companies across vital sectors were simultaneously compromised through the exploitation of a critical Zyxel firewall vulnerability. Weng's presentation offered a candid look into the challenges and successes of a relatively small, non-profit national CERT in responding to a significant incident with potential state actor involvement.
This article delves into the specifics of the attack, the Danish sector CERT's operational model, the technical underpinnings of the compromise, and the crucial lessons learned for global cybersecurity defenders. The incident underscores the persistent threat to critical infrastructure from well-resourced adversaries, highlighting the critical importance of rapid vulnerability management, robust network visibility, and coordinated incident response mechanisms, even for organizations with limited resources.
Background
▶ Watch: Introduction to Danish sector cert and its scope (0:00)
The Danish sector CERT operates as a non-government, non-profit organization, funded by trade organizations whose members are the entities it serves. Despite its modest size, comprising only 13 individuals, the CERT is tasked with covering an expansive scope that includes waste water, water, electricity (energy), district heating, and transport sectors across Denmark, the Faroe Islands, and recently, Greenland. This broad mandate covers approximately 400 member organizations and a population of 5.8 million people.
To fulfill its mission, the CERT deploys a Network Security Monitoring (NSM) and Intrusion Detection System (IDS) solution. This system is built on a Linux distribution and leverages open-source tools such as Suricata for intrusion detection, Zeek (formerly Bro) for network analysis, and Corelight for enhanced visibility and data extraction. Crucially, these sensors are primarily deployed on the outside of member organizations' demarcation firewalls or other edge points. This strategic placement provides the CERT with extensive visibility into incoming and outgoing traffic, allowing them to detect suspicious activity at the network perimeter. When anomalies are detected, the CERT alerts the affected members, initiating a verification process that often uncovers benign activity but occasionally reveals serious incidents, as was the case with the critical infrastructure attack.
The catalyst for the May 2023 attacks was the public disclosure of a critical vulnerability in Zyxel firewalls. On April 25th, a vulnerability with a severity score of 9.8 out of 10 on the Common Vulnerability Scoring System (CVSS) was released. Zyxel firewalls are widely deployed in Denmark, making many critical infrastructure entities susceptible. The rapid exploitation of this highly critical, publicly disclosed vulnerability by attackers underscores a persistent challenge in cybersecurity: the window between vulnerability disclosure and widespread patching often leaves organizations exposed to opportunistic and targeted attacks. This specific vulnerability presented a significant entry point for adversaries seeking to gain initial access to sensitive networks.
Key Findings
▶ Watch: Danish sector cert's organization, coverage, and members (2:00)
The primary finding detailed in Michael Weng's talk was the simultaneous compromise of 22 Danish critical infrastructure companies in May 2023. This incident was not isolated but occurred in "waves," indicating a highly coordinated and deliberate campaign rather than random opportunistic attacks. The swift detection by the Danish sector CERT's NSM/IDS solution led to the declaration of a "state of emergency" and the immediate activation of their incident response scheme, initiating close collaboration with the affected organizations.
A significant aspect of the findings revolved around the potential for state actor involvement. While Michael Weng acknowledged the inherent difficulties and complexities of definitive attribution, stating "attribution sucks," he confidently asserted that the CERT observed indicators pointing towards state-sponsored activity. Specifically, a single IP address identified during the investigation was known to be historically attributed to a state actor. Although a single IP is not conclusive proof, the overall nature of the attack – its coordination, the preparation demonstrated by the attackers, and the simultaneous targeting of multiple critical infrastructure entities – strongly suggested a sophisticated adversary with potentially national backing.
The attack was characterized by the attackers being "very prepared" and the operation itself being "very coordinated." This preparation likely involved pre-attack reconnaissance, development or acquisition of exploit capabilities for the Zyxel vulnerability, and a strategic selection of targets. The coordinated nature implied a centralized command-and-control structure orchestrating the exploitation and subsequent activities across the 22 compromised entities. The foundation of this widespread compromise was the exploitation of the critical Zyxel firewall vulnerability (CVSS 9.8), which provided the initial foothold into the victim networks.
Technical Deep Dive
▶ Watch: Overview of NSM IDS monitoring solution and deployment (3:00)
The attack against Danish critical infrastructure primarily leveraged a critical vulnerability in Zyxel firewalls, which was publicly disclosed on April 25th, 2023. This vulnerability, rated 9.8 out of 10 on the CVSS scale, indicated an extremely high severity, likely allowing for remote code execution or unauthorized access without significant user interaction. The widespread deployment of these Zyxel devices within Danish critical infrastructure sectors meant that a single, high-impact vulnerability could serve as a common entry point for a broad campaign.
While the talk did not delve into the specific CVE identifier or the intricate exploit mechanics of the Zyxel vulnerability, its high CVSS score strongly suggests it was a pre-authentication remote code execution (RCE) flaw or a similar severe issue. Such vulnerabilities allow attackers to gain control over the device without needing valid credentials, making them ideal for rapid, large-scale exploitation. The attackers likely scanned for vulnerable Zyxel firewalls exposed to the internet and then deployed their exploit code.
The Danish sector CERT's ability to detect this widespread compromise was thanks to their robust Network Security Monitoring (NSM) and Intrusion Detection System (IDS) setup. This system, built on a Linux distribution, integrates several key components:
- Suricata: An open-source, high-performance network IDS, IPS, and NSM engine. Suricata is capable of real-time intrusion detection by inspecting network traffic against a set of rules (signatures) for known threats, policy violations, and malicious patterns. Its deployment at the network edge allowed the CERT to detect the initial exploitation attempts and subsequent malicious traffic.
- Zeek (formerly Bro): A powerful network analysis framework that provides a comprehensive, high-level overview of network activity. Unlike traditional IDS that focus on signatures, Zeek performs deep protocol analysis to create detailed logs and extract application-layer information. This context-rich data is invaluable for understanding the nature of an attack, identifying command-and-control communications, and tracking lateral movement.
- Corelight: While Zeek is open-source, Corelight provides commercial sensors and software that enhance Zeek's capabilities, offering improved performance, easier deployment, and advanced features for extracting and analyzing Zeek logs. The inclusion of Corelight suggests the CERT aimed for enterprise-grade network visibility and analysis.
These tools were strategically deployed on sensors located outside the members' demarcation firewalls. This "outside-in" monitoring approach allowed the CERT to observe all incoming and outgoing traffic directed at the critical infrastructure networks. This visibility was crucial for:
- Initial Alerting: Detecting the exploit attempts against the Zyxel firewalls, which would likely involve specific malicious payloads or unusual traffic patterns.
- Command and Control (C2) Detection: Identifying subsequent communication channels established by the attackers from the compromised firewalls back to their infrastructure.
- Lateral Movement (Limited): While primarily external, some lateral movement indicators might be visible if compromised internal systems attempted to communicate externally in unusual ways or if the firewall itself was used to initiate connections into the internal network that were then mirrored externally.
The repeated emphasis on the "very prepared" and "coordinated" nature of the attack implies that the adversaries likely had a clear understanding of their targets' network perimeters, potentially through prior reconnaissance. They rapidly capitalized on the newly disclosed Zyxel vulnerability, indicating an advanced capability to integrate new exploits into their toolkit and deploy them at scale. The simultaneous nature of the compromises suggests automated tools for scanning and exploitation, followed by a centralized management of compromised hosts.
The CERT's detection process involved receiving alerts from their NSM/IDS solution, which then triggered a manual investigation. If the alerts were validated as serious, the CERT would contact the affected company, initiating a collaborative incident response. This human-in-the-loop validation process is vital to differentiate genuine threats from false positives, especially in critical infrastructure environments where disruptions can have significant consequences.
Demo / Proof of Concept
▶ Watch: May 2023: 22 critical infrastructure companies compromised (4:00)
The technical article focuses on a real-world incident response and analysis. As such, the speaker did not present a live demonstration or a proof of concept during the S4x24 talk. The content was centered on the documented attack, its detection, and the subsequent incident response efforts by the Danish sector CERT.
Defensive Implications
▶ Watch: Zyxel firewall vulnerability (CVE-2023-28771) was exploited (5:50)
The attack against Danish critical infrastructure provides several critical lessons and actionable implications for cybersecurity defenders across all sectors, particularly those safeguarding critical infrastructure.
- Prioritize Patch Management for Critical Vulnerabilities: The rapid exploitation of a Zyxel firewall vulnerability (CVSS 9.8) highlights the absolute necessity of an agile and effective patch management program. When a critical vulnerability in an edge device is disclosed, especially one with a public exploit, organizations must treat it as an immediate emergency. Delaying patches, even for a few days or weeks, can create a wide-open window for sophisticated adversaries. Defenders should implement robust vulnerability scanning, subscribe to vendor security advisories, and have a streamlined process for deploying critical security updates, particularly for internet-facing infrastructure.
- Enhance Network Security Monitoring (NSM) at the Perimeter: The Danish sector CERT's success in detecting this coordinated attack was largely attributed to their NSM/IDS solution, comprising Suricata, Zeek, and Corelight, strategically deployed outside demarcation firewalls. This "outside-in" visibility is paramount. It allows organizations to detect initial reconnaissance, exploit attempts, and command-and-control traffic before it penetrates deeper into the network. Defenders should invest in comprehensive NSM capabilities that capture and analyze traffic at key network junctures, enabling early detection of malicious activity that might bypass traditional endpoint or firewall logs.
- Develop and Practice Incident Response Plans: The CERT's ability to declare a "state of emergency" and launch an "incident response scheme" underscores the importance of pre-defined and practiced incident response plans. These plans should include clear roles, communication protocols, and escalation procedures for critical incidents. Regular tabletop exercises and drills help ensure that teams can respond effectively and efficiently under pressure, minimizing damage and recovery time. The coordinated response with 22 affected companies also highlights the need for inter-organizational communication and collaboration during widespread incidents.
- Recognize and Mitigate Supply Chain Risks: The widespread use of Zyxel firewalls across Danish critical infrastructure demonstrates a common supply chain vulnerability. Organizations rely on a limited number of vendors for critical infrastructure components. A single vulnerability in a widely adopted product can create a systemic risk. Defenders should conduct thorough due diligence on all third-party hardware and software, understand the security posture of their vendors, and plan for potential compromises affecting common technologies. Diversification of vendors, where feasible, can also reduce single points of failure.
- Embrace Sector-Specific Information Sharing and Collaboration: The Danish sector CERT's model—a non-profit, member-driven organization covering specific critical sectors—proved highly effective. This structure facilitates trust-based information sharing and coordinated defense efforts within a community facing similar threats. Defenders should actively participate in Information Sharing and Analysis Centers (ISACs) or other sector-specific CERTs/CSIRTs. These collaborative platforms enable the rapid dissemination of threat intelligence, best practices, and lessons learned, significantly enhancing collective resilience against sophisticated adversaries.
- Understand the Nuances of Attribution: While Michael Weng acknowledged that "attribution sucks," the CERT's observation of a single IP linked to a state actor was a significant piece of intelligence. Defenders need to understand that while definitive public attribution can be challenging and often politically charged, internal intelligence gathering can still provide crucial context about adversary capabilities, motives, and likely targets. This understanding can inform defensive strategies, threat modeling, and resource allocation, even if it doesn't lead to public naming and shaming.
- Resource Limitations are not an Excuse for Inaction: Michael Weng's candid admission that the Danish sector CERT is a small team (13 people) covering a vast area demonstrates that even organizations with limited resources can achieve significant defensive successes. By focusing on smart deployments (like edge NSM), leveraging open-source tools (Suricata, Zeek), and fostering strong relationships with members, effective cybersecurity can be achieved. Defenders should focus on maximizing the impact of their existing resources through strategic investments and process optimization.
Key Takeaways
- Rapid Exploitation of Critical Vulnerabilities: Adversaries are quick to weaponize and exploit newly disclosed critical vulnerabilities, especially those in internet-facing devices like firewalls. Patching must be immediate and prioritized.
- Importance of Sector-Specific CERTs: Non-profit, member-driven CERTs can effectively coordinate defense and information sharing across critical infrastructure sectors, significantly enhancing national resilience.
- Strategic Network Security Monitoring (NSM): Deploying comprehensive NSM tools like Suricata, Zeek, and Corelight at network perimeters provides essential visibility for early detection of sophisticated attacks.
- Challenges of Attribution: While definitive attribution to state actors is complex and often elusive, internal intelligence can still provide valuable context for understanding adversaries and informing defensive strategies.
- Coordinated Attacks against Critical Infrastructure: The simultaneous compromise of 22 companies underscores the reality of highly coordinated campaigns targeting vital national assets, requiring a unified and rapid response.
- Resourcefulness in Cybersecurity: Even small teams with limited resources can achieve significant defensive successes by making strategic choices, leveraging open-source tools, and fostering strong collaborative relationships.
About the Speaker(s)
Michael Weng is a cybersecurity professional working for the Danish sector CERT. His role involves monitoring and responding to cyber threats targeting critical infrastructure within Denmark. As a representative of a non-government, non-profit, member-driven organization, Weng is deeply involved in protecting vital sectors such as waste water, water, energy, district heating, and transport. His presentation at S4x24 showcased his practical experience in incident response and his team's capabilities in detecting and managing significant cyber incidents, even with limited resources.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This presentation from the Danish sector CERT provides a candid and highly valuable retrospective on a coordinated, state-actor level attack against 22 critical infrastructure companies. Michael Weng's detailed account of the incident, from detection via their 'outside-in' NSM/IDS setup (Suricata, Zeek, Corelight) to the challenges of attribution and the coordinated response, offers critical, actionable insights for any defender. It highlights the brutal reality of rapid zero-day exploitation and demonstrates how a small, well-placed team can achieve significant defensive success through strategic monitoring and robust incident response. This is essential learning, devoid of marketing fluff.
Heather Calloway (CISO) — STRONG ACCEPT
Michael Weng's presentation on the Danish critical infrastructure attack is a stark, credible account of simultaneous compromise leveraging a critical firewall vulnerability. It provides a clear, actionable roadmap for strengthening national resilience through strategic network monitoring, robust incident response, and sector-specific collaboration, demonstrating that even small teams can achieve significant defensive success when focused on the right priorities.