The landscape of threats in the second half of 2023 remained diverse and multifaceted, with threats spreading via the Internet continuing as the main source of cyber risks to OT computers, accounting for 18.1% of the attacks, followed by email clients at 4% and removable media at 1.9%
Kaspersky security solutions blocked malware that belonged to 12,618 families on industrial automation systems. Malicious objects belonged to a number of categories, among the most widespread were malicious scripts and phishing pages, denylisted Internet resources.
“Malicious objects that our solutions block can be grouped into 3 categories: those used for initial infection (such as dangerous web resources, malicious scripts, malicious documents), next-stage malware (including spyware, ransomware or miners) delivered to a victim in most cases via the Internet or email, and self-propagating malware (worms and viruses). All of these can be extremely harmful to an organisation. We investigated cases when even far-from-industrial malware, such as a banking trojan, nearly brought operations of a factory to a halt,” comments Evgeny Goncharov, Head of Kaspersky’s ICS CERT. “With this in mind industrial companies should continue fortifying their defenses bytailoring their cybersecurity strategies and staying informed about the ever-evolving threats.”
To keep OT computers protected from various threats, Kaspersky experts recommend:
The full report on ICS threats is available by the link.
Reference:
¹Supervisory control and data acquisition (SCADA) servers, data storage (Historian) servers, data gateways (OPC), stationary workstations of engineers and operators, mobile workstations of engineers and operators, human machine interface (HMI), OT network administration computers, ICS software development computers.
About Kaspersky ICS CERT
Kaspersky ICS CERT is a global project run by Kaspersky to coordinate the efforts of industrial automation system vendors and industrial facility owners and operators. Kaspersky ICS CERT experts research cyberthreats and detect attacks on industrial facilities; analyze popular industrial control system products and technologies for vulnerabilities and help eliminate any vulnerabilities identified; provide trainings; help developers make their products more secure; consult industrial organizations on industrial cybersecurity issues; develop industrial cybersecurity methodologies, frameworks, and standards. To find out more, visit https://ics-cert.kaspersky.com/