logo

Threat landscape for industrial automation systems. H2 2023

ID: 4c484a7c-007d-5e2f-91b7-d660bc6fcbe0

STIX ID: report--4c484a7c-007d-5e2f-91b7-d660bc6fcbe0

Feed Name: Securelist by Kaspersky

Date Published: 2024-03-19

Date Updated: 2026-04-29

Author: Kaspersky ICS CERT

...
...

Kaspersky ICS CERT’s H2 2023 statistics show the share of ICS computers with blocked malicious objects declined by 2.1 pp to 31.9%, with building automation most affected; the internet, email, and removable media remained the main threat sources, and only Windows miner executables rose markedly. Regional exposure ranged from 38.2% in Africa to 14.8% in Northern Europe, with increases in South Asia, Eastern Europe (up 6 pp), and Southern Europe; regions led different categories (e.g., Africa for spyware/worms/web miners, Southern Europe for email threats, Latin America for scripts/phishing and malicious documents, South Asia and the Middle East for ransomware, Central Asia for denylisted sites and Windows miners). The report highlights varied industry and regional threat mixes without detailing specific actors, campaigns, vulnerabilities, or IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.