Dragos ICS/OT Ransomware Analysis: Q4 2021
ID: b0e59e17-7b1a-5665-8318-021d6b6b88ce
STIX ID: report--b0e59e17-7b1a-5665-8318-021d6b6b88ce
Feed Name: Dragos Blog
This Dragos intelligence report analyzes ransomware activity affecting IT and OT during Q4 2021 using Dark Web victim postings, noting 176 ICS-related postings (58 in Oct, 57 in Nov, 61 in Dec), with 41% of victim locations in the U.S. and 65% of victims in the Manufacturing sector; it highlights LockBit 2.0 (28% of postings) and Conti (18%) as primary actors, describes OT-targeting techniques (including built-in OT kill processes in several strains), outlines TTPs such as double extortion, credential recruitment, and use of tooling like Cobalt Strike, and assesses continued ransomware risk to OT operations and potential for follow-on IP theft or increased extortion severity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
