logo

Malware Campaign Against Industrial Systems Almost 3 Years Old

ID: 5e1943cf-17c2-5860-9a28-5223e4cbcbaf

STIX ID: report--5e1943cf-17c2-5860-9a28-5223e4cbcbaf

Feed Name: Security Ledger

Threat Score
78/100

Date Published: 2014-10-30

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

ICS-CERT reported a long-running campaign (since Jan 2012) compromising HMI products (GE Cimplicity, Advantech/Broadwin WebAccess, Siemens WinCC) with BlackEnergy variants; some infections involved exploitation of a known Cimplicity vulnerability, others have unknown initial vectors. The malware was used for network reconnaissance and lateral movement, ICS-CERT found no confirmed process manipulation but warned of prolonged dwell time and noted forensic links (shared C2) to the Sandworm campaign, urging asset owners to look for and report compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.