logo

Threat landscape for industrial automation systems in Q4 2025

ID: 1665f0f1-4b7b-5d90-a1cd-2e858b0cdca0

STIX ID: report--1665f0f1-4b7b-5d90-a1cd-2e858b0cdca0

Feed Name: Securelist by Kaspersky

Threat Score
60/100

Date Published: 2026-04-15

Date Updated: 2026-04-29

Author: Kaspersky ICS CERT

...
...

Kaspersky’s Q4 2025 ICS threat report shows an overall decline in malicious object detections but highlights a notable global phishing campaign (“Curriculum‑vitae‑catalina”) that distributed the Backdoor.MSIL.XWorm worm via CV‑named executables, causing a 1.6× increase in worms on ICS computers (1.60% blocked). The report details regional and industry statistics, primary infection vectors (email, internet, removable media), growth in Windows executable miners and worms, and provides sector-specific visibility with Biometrics, Oil & Gas, and regions such as Southern Europe and South Asia notably affected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.