← Back to Daily Briefing (#Baseband)

A sophisticated supply chain attack has targeted Slovakia's critical transport infrastructure through the procurement of NERO R-ONE high-speed traffic cameras. The compromise involved a Cyprus-based shell company utilizing fraudulent certifications to secure no-bid contracts, bypassing standard security vetting. Investigation by the National Security Authority (NBU) identified a hardware-level backdoor within the devices, facilitating remote code execution (RCE) via SMS-based command-and-control (C2) using hardcoded Russian mobile numbers. This vulnerability allows for unauthorized remote manipulation of traffic data and potentially high-level espionage against government facilities, representing a significant escalation in Russian hybrid warfare tactics within the European Union.

  • Incident Overview

    • Targeted Infrastructure: NERO R-ONE high-speed traffic cameras deployed across Slovakian transport networks.
    • Primary Whistleblower: Slovakia’s National Security Authority (NBU) identified the presence of unauthorized access capabilities.
    • Institutional Friction: Significant tension exists between NBU security warnings and the Slovak Ministry of Interior's official rejection of the claims.
  • Attack Vector & Procurement Fraud

    • Shell Company Intermediary: Use of a Cyprus-based entity with no operational history to obscure the hardware's true origin.
    • Procurement Manipulation: Acquisition of hardware via non-transparent, no-bid direct contracts to circumvent standard vetting.
    • Credential Fraud: Deployment of unverified and fake digital certifications to satisfy regulatory compliance requirements.
  • Technical Deep Dive: Hardware Backdoor

    • Vulnerability Class: Hardware-level supply chain compromise embedding unauthorized functionality.
    • C2 Mechanism: SMS-based remote code execution (RCE) utilized as a covert command-and-control channel.
    • Trigger Mechanism: Hardcoded list of Russian mobile phone numbers used to initiate unauthorized device commands.
  • Impact Analysis

    • Operational Risk: Potential for remote manipulation of traffic monitoring data and disruption of national road safety infrastructure.
    • Espionage Potential: High risk of surveillance/intelligence gathering near sensitive Ministry of Interior (MVS) buildings.
    • National Security Threat: Vulnerability of critical transport corridors and border crossings to coordinated disruption.
    • Financial Implications: Misuse of public funds through non-transparent procurement processes involving shell organizations.
  • Indicators of Compromise (IoCs)

    • Procurement Indicators: Use of no-bid contracts and entities lacking established commercial history.
    • Documentary Indicators: Presence of fraudulent digital certifications from non-standard Cypriot entities.
    • Hardware Indicators: Firmware or hardware logic containing hardcoded foreign mobile number sequences.

Related posts

  1. Risky Business Newsletters — Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras
  2. Spectator
  3. Kompas
  4. Newsnow
  5. Etasr
  6. Tasr
  7. Theguardian
  8. Medium
  9. Ua

LINK COPIED TO CLIPBOARD