logo

Dangerous ICS Malware Targets Orgs in Russia and Ukraine

ID: d8a2cfa3-2df9-5f79-8ff1-d52fb454e9b7

STIX ID: report--d8a2cfa3-2df9-5f79-8ff1-d52fb454e9b7

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-04-17

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

The report describes two ICS/OT-focused malware: Kapeka, a Sandworm-linked backdoor used for early-stage access, persistence, and remote operations, and Fuxnet, a destructive Blackjack-linked tool that overwrites gateway NAND and floods sensors with M‑Bus traffic — reportedly bricking ~1,700 gateways and disabling ~87,000 sensors; the incidents illustrate nation-state-linked, high-impact attacks on critical infrastructure and emphasize basic mitigations like strong credentials, network segmentation, and device management.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.