A sophisticated supply chain attack has targeted Slovakia's critical transport infrastructure through the procurement of NERO R-ONE high-speed traffic cameras. The compromise involved a Cyprus-based shell company utilizing fraudulent certifications to secure no-bid contracts, bypassing standard security vetting. Investigation by the National Security Authority (NBU) identified a hardware-level backdoor within the devices, facilitating remote code execution (RCE) via SMS-based command-and-control (C2) using hardcoded Russian mobile numbers. This vulnerability allows for unauthorized remote manipulation of traffic data and potentially high-level espionage against government facilities, representing a significant escalation in Russian hybrid warfare tactics within the European Union.
-
Incident Overview
- Targeted Infrastructure: NERO R-ONE high-speed traffic cameras deployed across Slovakian transport networks.
- Primary Whistleblower: Slovakia’s National Security Authority (NBU) identified the presence of unauthorized access capabilities.
- Institutional Friction: Significant tension exists between NBU security warnings and the Slovak Ministry of Interior's official rejection of the claims.
-
Attack Vector & Procurement Fraud
- Shell Company Intermediary: Use of a Cyprus-based entity with no operational history to obscure the hardware's true origin.
- Procurement Manipulation: Acquisition of hardware via non-transparent, no-bid direct contracts to circumvent standard vetting.
- Credential Fraud: Deployment of unverified and fake digital certifications to satisfy regulatory compliance requirements.
-
Technical Deep Dive: Hardware Backdoor
- Vulnerability Class: Hardware-level supply chain compromise embedding unauthorized functionality.
- C2 Mechanism: SMS-based remote code execution (RCE) utilized as a covert command-and-control channel.
- Trigger Mechanism: Hardcoded list of Russian mobile phone numbers used to initiate unauthorized device commands.
-
Impact Analysis
- Operational Risk: Potential for remote manipulation of traffic monitoring data and disruption of national road safety infrastructure.
- Espionage Potential: High risk of surveillance/intelligence gathering near sensitive Ministry of Interior (MVS) buildings.
- National Security Threat: Vulnerability of critical transport corridors and border crossings to coordinated disruption.
- Financial Implications: Misuse of public funds through non-transparent procurement processes involving shell organizations.
-
Indicators of Compromise (IoCs)
- Procurement Indicators: Use of no-bid contracts and entities lacking established commercial history.
- Documentary Indicators: Presence of fraudulent digital certifications from non-standard Cypriot entities.
- Hardware Indicators: Firmware or hardware logic containing hardcoded foreign mobile number sequences.
Related posts
- Risky Business Newsletters — Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras
- Spectator
- Kompas
- Newsnow
- Etasr
- Tasr
- Theguardian
- Medium
- Ua