Exploiting Omron's NEX PLC Runtime And Protocol

Logan Carpenter

S4x24 - ICS Security Conference · Day 3 · Stage 3

Overview

This talk, delivered by Logan Carpenter, a malware analyst at Dragos, delves into the critical vulnerabilities discovered within Omron's NEX industrial control system (ICS) protocol and runtime environment. Carpenter’s research builds upon prior analysis of the notorious PipeDream malware, specifically its Bad Omen module, which targeted Omron programmable logic controllers (PLCs). The presentation highlights a significant blind spot in ICS security: the prevalence of undocumented, proprietary protocols and the inherent risks they pose when combined with common embedded system vulnerabilities like hardcoded credentials and root-privileged services.

Watch on YouTube

Visual summary for Exploiting Omron's NEX PLC Runtime And Protocol by Logan Carpenter
Visual summary for Exploiting Omron's NEX PLC Runtime And Protocol by Logan Carpenter

Key moments

  1. 0:00 Introduction: ICS malware and proprietary protocols like NEX.
  2. 1:40 Discovering hidden commands, leading to "Bad Omen 2.0" idea.
  3. 2:42 Overview of findings: hardcoded credentials, 170 undocumented commands.
  4. 3:46 Root cause analysis: hardcoded credentials and root privileges.
  5. 4:40 Fuzzing technique used to discover 170 undocumented commands.
  6. 5:58 Demonstrating directory traversal to write files to root.
  7. 7:00 Disclosing the console command backdoor used by Bad Omen.

Exploiting Omron's NEX PLC Runtime And Protocol

Speakers: Logan Carpenter, Malware Analyst, Dragos

Conference: S4

YouTube: https://www.youtube.com/watch?v=hgihweJeHSU

Overview

This talk, delivered by Logan Carpenter, a malware analyst at Dragos, delves into the critical vulnerabilities discovered within Omron's NEX industrial control system (ICS) protocol and runtime environment. Carpenter’s research builds upon prior analysis of the notorious PipeDream malware, specifically its Bad Omen module, which targeted Omron programmable logic controllers (PLCs). The presentation highlights a significant blind spot in ICS security: the prevalence of undocumented, proprietary protocols and the inherent risks they pose when combined with common embedded system vulnerabilities like hardcoded credentials and root-privileged services.

The core of the research uncovers 170 previously undocumented commands within the NEX protocol, far exceeding the 30 commands utilized by Bad Omen. This extensive attack surface, combined with critical design flaws, demonstrates how adversaries could achieve dynamic, on-demand operational disruption, a more sophisticated approach than previous static code injection methods. The talk serves as a stark reminder for both vendors and defenders about the need for deeper scrutiny of proprietary protocols and the robust implementation of fundamental security principles in ICS devices.

Background

▶ Watch: Introduction: ICS malware and proprietary protocols like NEX. (0:00)

The evolution of ICS-specific malware reveals a recurring characteristic: the exploitation of proprietary protocols. Examples such as Trisis, vulnerabilities in Rockwell's proprietary CIP objects, and the PipeDream malware’s Bad Omen module underscore this trend. Bad Omen, in particular, leveraged the then-unknown NEX protocol to target Omron NX/NJ series PLCs. Initial analysis of Bad Omen by Dragos revealed that the malware's functionality was essentially ripped from Omron's engineering workstation (EWS) software, Sysmac Studio, and adapted into a command-line tool.

During the comparison of network traffic between Sysmac Studio and Bad Omen, researchers noticed a significant disparity: Sysmac Studio utilized a vast array of commands that Bad Omen never employed. This observation immediately raised the question of what a "Bad Omen 2.0" might look like, drawing parallels to the evolution of malware like Industroyer and Industroyer 2. The potential for a more advanced attack leveraging these additional commands prompted a deeper investigation into the NEX protocol. This protocol, designed for Sysmac Studio to monitor, control, and program Omron PLCs, is entirely proprietary and undocumented outside of Omron. While it requires authentication, Dragos, like the Turbite threat group behind PipeDream, discovered hardcoded credentials within Sysmac Studio.

The root cause of the identified vulnerabilities boils down to two major issues. Firstly, hardcoded credentials and encryption keys were found directly within a Sysmac Studio binary. These credentials are used to authenticate with an HTTP/CGI server on the PLC, while the encryption keys secure file transfer command payloads. Secondly, and critically, the HTTP server on the PLC that processes these commands operates with root privileges. This is a common, yet dangerous, practice in many embedded systems, including OT, ICS, and IoT devices. The consequence of a root-privileged web server is severe: any vulnerabilities discovered, whether in the HTTP library itself or in the underlying command processing, will inevitably lead to root-level remote code execution (RCE).

Key Findings

▶ Watch: Overview of findings: hardcoded credentials, 170 undocumented commands. (2:42)

Logan Carpenter's extensive research into Omron's NEX protocol yielded several critical findings that expose a significant attack surface within Omron NX/NJ series PLCs:

  • Discovery of 170 Undocumented Protocol Commands: Through a methodical fuzzing approach, Carpenter uncovered an astonishing 170 commands within the NEX protocol. This is a stark contrast to the mere 30 commands utilized by the Bad Omen malware, revealing a vast, previously unknown operational capability.
  • Hardcoded Credentials and Encryption Keys: Critical authentication credentials for the PLC's HTTP server and encryption keys for file transfer payloads were found hardcoded within the Sysmac Studio binary. These allow any attacker with access to the software to bypass authentication.
  • Root-Privileged HTTP Server: The HTTP server on the Omron PLC responsible for processing NEX protocol commands runs with root privileges. This elevates any successful exploit to full system compromise and remote code execution.
  • Remote Shell Commands: The protocol includes commands that allow for remote shell access, providing an attacker with direct control over the device's operating system.
  • Runtime Debugger: A runtime debugger functionality was identified, which, while useful for development, can be abused by an attacker to gain deep insight into the PLC's internal state and memory.
  • Protocol Vulnerabilities, including Directory Traversal: Specific vulnerabilities were found within file transfer commands (e.g., file upload, file download) that enable directory traversal. This allows an attacker to write arbitrary files to any location on the PLC's filesystem, including the root directory.
  • Dynamic Runtime Memory Manipulation: The research demonstrated the ability to read and write specific variables in the PLC's runtime memory. This enables dynamic manipulation of operational parameters, such as servo speed, without requiring permanent modification of the compiled ladder logic.

Technical Deep Dive

▶ Watch: Root cause analysis: hardcoded credentials and root privileges. (3:46)

The technical depth of this research is rooted in the systematic reverse engineering of a proprietary protocol and the identification of fundamental security flaws.

The discovery of the 170 undocumented NEX protocol commands was a meticulous process. Carpenter devised a fuzzing strategy by first extracting all strings from the PLC's firmware. These strings were then "blasted" at the PLC as potential commands. The key to identifying valid commands was observing the HTTP server's response: if the PLC returned an "invalid command error" (an HTTP status code), the string was discarded. Any other response indicated a potentially valid command, leading to the identification of the extensive command set. This "glorified fuzzer" approach effectively mapped out the protocol's hidden capabilities.

A critical vulnerability identified was the presence of hardcoded credentials and encryption keys. These were located within the Sysmac Studio binary, the legitimate engineering software. The credentials are used for authenticating with the PLC's CGI/HTTP server, which handles incoming NEX protocol requests. The encryption keys are specifically used to encrypt the payloads of file transfer commands, ensuring confidentiality during legitimate operations. The hardcoding of these secrets means that an attacker with access to the Sysmac Studio software can easily extract them, effectively bypassing the authentication mechanism designed to protect the PLC.

Compounding this authentication bypass is the fact that the PLC's HTTP server operates with root privileges. This is a common design flaw in embedded systems where services are often run with excessive permissions for convenience. The implications are severe: any vulnerability found within the HTTP server's libraries or the processing of its received commands immediately escalates to root-level remote code execution. This means an attacker can gain complete control over the device, execute arbitrary code, and manipulate its functionality without restriction.

The research specifically highlighted directory traversal vulnerabilities within NEX protocol file transfer commands, such as file upload and file download. These commands are legitimately used by Sysmac Studio and were also leveraged by Bad Omen to transfer logic and configuration files to and from the PLC. The vulnerability stems from how the PLC handles file paths. File type identifiers, such as user PG (which might signify a compiled ladder logic binary), are internally mapped to hardcoded directories on the PLC. When the PLC appends a user-supplied filename to this directory path, it fails to properly sanitize the input. By injecting directory traversal sequences (e.g., ../../) into the filename, an attacker can escape the intended directory and write files to arbitrary locations, including the root directory of the device. Carpenter demonstrated this by writing a file to the root directory, leveraging a console command that was previously disclosed in the initial Bad Omen reporting for enabling a Telnet interface. This specific console command highlights how an attacker could activate dormant services on the PLC.

Beyond file system manipulation, a key technical contribution was the demonstration of dynamic runtime memory manipulation. The initial Bad Omen attacks involved a complex process of pulling compiled logic, unpacking it, locating specific function blocks (like MC move relative for servo control), injecting code to modify values, repackaging, and re-uploading the logic. This method is permanent and highly complex. Carpenter's goal was to achieve on-demand manipulation. This was made possible by identifying NEX protocol commands like memory read text and memory write (part of six variations). These commands, while not allowing arbitrary memory access, enable reading and writing specific variables within the PLC's runtime environment. To execute these commands, an attacker needs several arguments: a tag revision (to ensure agreement on the task state), a count (for writing multiple variables), and specific variable characteristics (e.g., offsets, data types) that the runtime needs to process the read/write operation. Initially, obtaining this variable data was cumbersome, requiring analysis of unstructured dumps from a runtime debugger. However, Carpenter discovered a highly useful command, variable browse info, which, when sent to the PLC, returns information about every single variable in the entire runtime environment, simplifying the process significantly.

Demo / Proof of Concept

▶ Watch: Demonstrating directory traversal to write files to root. (5:58)

The demonstration focused on showcasing the ability to impact physical operations dynamically, a significant advancement over previous static code injection methods. The lab setup comprised an Omron PLC, a servo drive (controlling the servo's speed, torque, and acceleration), and a servo motor (an electric motor for precise physical control, commonly used in conveyor belts, valves, etc.).

The core of the demo involved a custom ladder logic program implemented on the PLC. This logic was designed to make the servo motor spin. Specifically, it used a timer to power on the servo every second and an MC move relative function block to control the servo's movement. Crucially, unlike an earlier Defcon experiment where values like speed and acceleration were statically programmed into the logic, this demonstration's logic utilized variables (e.g., test disk, speed, test acceleration) as inputs to the MC move relative function block. These variables were initialized with default values but were designed to be manipulated externally.

This strategic use of variables was key. By making these parameters accessible as runtime variables, Carpenter was able to leverage the newly discovered memory write commands within the NEX protocol. The proof of concept demonstrated how an attacker could connect to the PLC (bypassing authentication using the hardcoded credentials) and then issue memory write commands to alter the values of test speed, test acceleration, or test disk variables in real-time. As these values were changed, the physical servo motor's behavior immediately reflected the modifications, such as spinning faster or slower. This dynamic manipulation capability represents a far more potent and versatile attack vector than the complex, permanent code injection method previously employed by Bad Omen, allowing for on-demand operational disruption without leaving permanent traces in the PLC's compiled logic.

Defensive Implications

▶ Watch: Disclosing the console command backdoor used by Bad Omen. (7:00)

The findings from this research carry profound implications for defenders operating and securing ICS environments, particularly those utilizing Omron NX/NJ series PLCs.

Firstly, the prevalence of proprietary protocols like NEX highlights a significant blind spot. Defenders often lack visibility into these protocols, making it difficult to detect anomalous behavior or the use of undocumented commands. Organizations must prioritize solutions that can parse and analyze proprietary ICS traffic for signs of compromise, rather than relying solely on generic network monitoring.

Secondly, the discovery of hardcoded credentials and encryption keys within engineering software like Sysmac Studio is a critical vulnerability. This underscores the need for thorough security assessments of all software used to interact with ICS devices, not just the devices themselves. Defenders should assume such credentials may be compromised and implement compensating controls, such as network segmentation to restrict access to PLCs, strong authentication mechanisms where possible, and continuous monitoring for unauthorized access attempts. Regular firmware updates are also crucial, as vendors may patch these issues.

Thirdly, the practice of running HTTP servers with root privileges on embedded ICS systems is a fundamental security flaw that must be addressed by vendors. For defenders, this means that any perceived "minor" vulnerability in these services could lead to full device compromise. It emphasizes the importance of minimizing the network exposure of such devices and implementing robust intrusion detection systems that can identify attempts to exploit web-based vulnerabilities.

Finally, the demonstration of dynamic runtime memory manipulation shows that adversaries can impact operations without altering the PLC's compiled logic, making detection more challenging. Defenders need to monitor for unusual read/write operations to PLC memory areas and changes in operational parameters that deviate from expected ranges. Behavioral analytics applied to PLC operations could help identify these subtle, on-demand attacks. Regular backups of PLC logic and configurations are also vital for rapid recovery and integrity verification.

Key Takeaways

  • Proprietary protocols are a critical attack surface: Undocumented, proprietary protocols like Omron's NEX present vast, hidden attack surfaces that can be exploited by advanced threat actors, often containing far more capabilities than initially understood.
  • Fundamental security flaws persist: Hardcoded credentials and HTTP servers running with root privileges on ICS devices are pervasive and severe vulnerabilities that dramatically lower the bar for attackers to achieve remote code execution and full system compromise.
  • Malware capabilities are often limited: Known ICS malware like Bad Omen may only utilize a fraction of the available commands and functionalities within a protocol, indicating a much larger potential attack surface that defenders must prepare for.
  • Dynamic operational impact is a growing threat: The ability to manipulate PLC runtime memory variables on demand allows for sophisticated, less detectable operational disruption compared to permanent code injection, demanding advanced monitoring strategies.
  • Thorough software analysis is crucial for threat intelligence: Reverse engineering engineering workstation software (e.g., Sysmac Studio) is a powerful method for uncovering hidden protocol commands, vulnerabilities, and expanding defensive threat intelligence.
  • Vendor responsibility for secure design: ICS vendors must prioritize secure development practices, eliminate hardcoded secrets, and implement least privilege principles to prevent critical services from running with excessive permissions.

About the Speaker(s)

Logan Carpenter is a Malware Analyst at Dragos, a leading company in industrial cybersecurity. His work focuses on analyzing sophisticated threats targeting industrial control systems. Carpenter has been deeply involved in the analysis of significant ICS malware, including the PipeDream malware and its Bad Omen module, contributing to the understanding of advanced persistent threats in critical infrastructure. He is dedicated to uncovering vulnerabilities in proprietary ICS protocols and sharing his findings to help fortify global industrial defenses.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

Carpenter's deep dive into Omron's NEX protocol is precisely the kind of no-bullshit research this industry needs. Building on the PipeDream analysis, he didn't just rehash findings; he systematically uncovered a staggering 170 undocumented commands, exposed hardcoded vendor incompetence, and demonstrated dynamic operational disruption capabilities far beyond what Bad Omen achieved. This isn't theoretical; it's a stark, live-demoed reality check for Omron and a critical intelligence drop for anyone defending industrial systems.

Heather Calloway (CISO) — STRONG ACCEPT

This talk exposes profound systemic vulnerabilities in Omron's NEX PLC runtime and protocol, moving beyond typical static code injection to demonstrate dynamic, real-time operational disruption. The research uncovers critical governance failures, including hardcoded credentials and root-privileged services, which severely lower the bar for sophisticated adversaries. While technically deep, the implications for business impact, risk ownership, and defensive strategy are immediate and demand executive attention, offering clear takeaways for advanced defenders to enhance visibility and response in OT environments.

→ Top-rated talks at S4x24 - ICS Security Conference

All talks from S4x24 - ICS Security Conference