Threat landscape for industrial automation systems in Q3 2024
ID: b1f85219-eaae-5bff-b133-8619d1f5ddee
STIX ID: report--b1f85219-eaae-5bff-b133-8619d1f5ddee
Feed Name: Securelist by Kaspersky
In Q3 2024, Kaspersky ICS CERT observed malicious objects blocked on 22% of ICS computers (−1.5 pp QoQ; −1.7 pp YoY), with activity lowest in August and highest in July/September; rates ranged from 9.7% in Northern Europe to 31.5% in Africa, and the biometrics sector led industries. Protection solutions blocked 11,882 malware families, with the largest proportional growth in malicious scripts and phishing pages; all major threat sources (internet, email, removable media) declined, with email/removable/network-folder threats at their lowest in the observation period. Initial infection categories rose for denylisted internet resources (6.84%, +0.21 pp), malicious documents (1.97%, +0.01 pp), and especially scripts/phishing (6.24%, +0.55 pp), while next-stage malware decreased (spyware 3.91%, −0.17 pp; ransomware 0.16%; miners 0.71% exec/0.41% web). Self-propagating malware continued to fall (worms 1.30%, lowest since 2022; viruses 1.53%), and AutoCAD malware remained low at 0.40%.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
