logo

Malicious OT Project Files within Reach of Attackers

ID: fbba8cf6-561f-5fdb-9b96-bd8299258f2f

STIX ID: report--fbba8cf6-561f-5fdb-9b96-bd8299258f2f

Feed Name: Claroty Team82

Threat Score
85/100

Date Published: 2023-09-27

Date Updated: 2026-04-17

Author: Amir Preminger; Sharon Brizinov

...
...

Google TAG reports a sophisticated social‑engineering campaign attributed to a North Korean APT that delivered malicious Visual Studio project files which compiled into DLL backdoors; the report highlights analogous risks to OT engineering workstation project files that can execute payloads when opened, cites real-world project-file vulnerabilities (including PLCnext), and urges caution and mitigation when sharing or opening project files to protect IT and OT environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.