EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all'intelligence
Avviso tecnico

ICS Threat Analysis: New, Experimental Malware Can Kill Engineering Processes

Fonte aperta verificata
Intelligence con provenienza tracciabile. EudorIA conserva gli indicatori tecnici acquisiti dai feed supportati, con fonte, data e contesto. Gli IOC condivisibili sono disponibili nei feed STIX; le azioni di rilevamento e blocco richiedono la valutazione di validita, confidenza e applicabilita al perimetro del cliente. Consulta i feed STIX
Sintesi operativa EudorIA

Cosa significa

Priorità 55/100

MISP EudorIA ha pubblicato l'advisory "ICS Threat Analysis: New, Experimental Malware Can Kill Engineering Processes". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.

Perché conta

Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.

DestinatariITSOCCISO

Testo acquisito dalla fonte

Evento MISP pubblicato con TLP:CLEAR: ICS Threat Analysis: New, Experimental Malware Can Kill Engineering Processes. Summary # ICS Threat Analysis: New, Experimental Malware Can Kill Engineering Processes #### Summary * Our analysis of a public malware repository shows a constant drumbeat of OT/ICS malware * Since +20% of all OT/ICS attacks target engineering workstations, we focused on it * We saw 2 incidents with Mitsubishi engineering workstations infected with [Ramnit]([URL rimossa]) worm * We analyzed 3 samples of new malware that kills Siemens engineering processes —we’ve named it Chaya\_003 #### Guidance * Harden engineering workstations * Segment the network * Monitor for threats * Full analysis and recommendations for mitigation are below OT-specific malware – such as FrostyGoop/BUSTLEBERM – is still much less common than malware targeting enterprise software or mobile operating systems by volume. But there’s little room to sleep easily if you’re a security operator in OT or manage [industrial control system security](/glossary/ics-security/). Malware in OT/ICS is more common than you think — and engineering workstations connected to the internet are targets. We [recently analyzed](/blog/targeting-ot-security-ics-threats-malware/) automated botnet families, such as Aisuru, Kaiten and Gafgyt, that could be found on the VirusTotal public malware repository around the same time as FrostyGoop/BUSTLEBERM. What we found included either default credentials of OT devices for initial infectio

Fonte
MISP EudorIA
Entità pubblicatrice
MISP EudorIA
Tipo entità
Comunità di intelligence
Area
Global
Lingua originale
it · traduzione non necessaria
Pubblicazione
30/07/2026 02:52
Condivisione
TLP:CLEAR
Indicatori dichiarati dalla fonte
39
IOC indicizzati per la ricerca
0 valori nel periodo di conservazione
IOC disponibili nel feed STIX
25Ultima verifica di condivisione: 2026-09-26T04:30:44.753867+00:00
Evento MISP
f9db7f4c-b8d6-4ed9-b9f1-d1990a7e1668
Classificazione
Media
Apri la fonte originale