logo

Dragos ICS/OT Ransomware Analysis: Q4 2021

ID: b0e59e17-7b1a-5665-8318-021d6b6b88ce

STIX ID: report--b0e59e17-7b1a-5665-8318-021d6b6b88ce

Feed Name: Dragos Blog

Threat Score
78/100

Date Published: 2022-02-09

Date Updated: 2026-04-27

...
...

This Dragos intelligence report analyzes ransomware activity affecting IT and OT during Q4 2021 using Dark Web victim postings, noting 176 ICS-related postings (58 in Oct, 57 in Nov, 61 in Dec), with 41% of victim locations in the U.S. and 65% of victims in the Manufacturing sector; it highlights LockBit 2.0 (28% of postings) and Conti (18%) as primary actors, describes OT-targeting techniques (including built-in OT kill processes in several strains), outlines TTPs such as double extortion, credential recruitment, and use of tooling like Cobalt Strike, and assesses continued ransomware risk to OT operations and potential for follow-on IP theft or increased extortion severity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.