ICS Threat Analysis: New, Experimental Malware Can Kill Engineering Processes
Cosa significa
MISP EudorIA ha pubblicato l'advisory "ICS Threat Analysis: New, Experimental Malware Can Kill Engineering Processes". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.
Perché conta
Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.
Azioni consigliate
- Verificare tecnologie, versioni e servizi interessati nel proprio inventario.
- Consultare la fonte originale prima di pianificare la mitigazione.
Testo acquisito dalla fonte
Evento MISP pubblicato con TLP:CLEAR: ICS Threat Analysis: New, Experimental Malware Can Kill Engineering Processes. Summary # ICS Threat Analysis: New, Experimental Malware Can Kill Engineering Processes #### Summary * Our analysis of a public malware repository shows a constant drumbeat of OT/ICS malware * Since +20% of all OT/ICS attacks target engineering workstations, we focused on it * We saw 2 incidents with Mitsubishi engineering workstations infected with [Ramnit]([URL rimossa]) worm * We analyzed 3 samples of new malware that kills Siemens engineering processes —we’ve named it Chaya\_003 #### Guidance * Harden engineering workstations * Segment the network * Monitor for threats * Full analysis and recommendations for mitigation are below OT-specific malware – such as FrostyGoop/BUSTLEBERM – is still much less common than malware targeting enterprise software or mobile operating systems by volume. But there’s little room to sleep easily if you’re a security operator in OT or manage [industrial control system security](/glossary/ics-security/). Malware in OT/ICS is more common than you think — and engineering workstations connected to the internet are targets. We [recently analyzed](/blog/targeting-ot-security-ics-threats-malware/) automated botnet families, such as Aisuru, Kaiten and Gafgyt, that could be found on the VirusTotal public malware repository around the same time as FrostyGoop/BUSTLEBERM. What we found included either default credentials of OT devices for initial infectio
- Fonte
- MISP EudorIA
- Entità pubblicatrice
- MISP EudorIA
- Tipo entità
- Comunità di intelligence
- Area
- Global
- Lingua originale
- it · traduzione non necessaria
- Pubblicazione
- 30/07/2026 02:52
- Condivisione
- TLP:CLEAR
- Indicatori dichiarati dalla fonte
- 39
- IOC indicizzati per la ricerca
- 0 valori nel periodo di conservazione
- IOC disponibili nel feed STIX
- 25Ultima verifica di condivisione: 2026-09-26T04:30:44.753867+00:00
- Evento MISP
- f9db7f4c-b8d6-4ed9-b9f1-d1990a7e1668
- Classificazione
- Media