EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

ICS Threat Analysis: New, Experimental Malware Can Kill Engineering Processes

Verified open source
Intelligence with traceable provenance. EudorIA retains technical indicators acquired from supported feeds, with source, date and context. Shareable IOCs are available in the STIX feeds; detection and blocking actions require an assessment of validity, confidence and applicability to the customer's environment. Browse STIX feeds
EudorIA operational summary

What it means

Priority 55/100

MISP EudorIA ha pubblicato l'advisory "ICS Threat Analysis: New, Experimental Malware Can Kill Engineering Processes". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.

Why it matters

Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.

AudienceITSOCCISO

Text acquired from the source

Evento MISP pubblicato con TLP:CLEAR: ICS Threat Analysis: New, Experimental Malware Can Kill Engineering Processes. Summary # ICS Threat Analysis: New, Experimental Malware Can Kill Engineering Processes #### Summary * Our analysis of a public malware repository shows a constant drumbeat of OT/ICS malware * Since +20% of all OT/ICS attacks target engineering workstations, we focused on it * We saw 2 incidents with Mitsubishi engineering workstations infected with [Ramnit]([URL rimossa]) worm * We analyzed 3 samples of new malware that kills Siemens engineering processes —we’ve named it Chaya\_003 #### Guidance * Harden engineering workstations * Segment the network * Monitor for threats * Full analysis and recommendations for mitigation are below OT-specific malware – such as FrostyGoop/BUSTLEBERM – is still much less common than malware targeting enterprise software or mobile operating systems by volume. But there’s little room to sleep easily if you’re a security operator in OT or manage [industrial control system security](/glossary/ics-security/). Malware in OT/ICS is more common than you think — and engineering workstations connected to the internet are targets. We [recently analyzed](/blog/targeting-ot-security-ics-threats-malware/) automated botnet families, such as Aisuru, Kaiten and Gafgyt, that could be found on the VirusTotal public malware repository around the same time as FrostyGoop/BUSTLEBERM. What we found included either default credentials of OT devices for initial infectio

Source
MISP EudorIA
Publishing entity
MISP EudorIA
Entity type
Intelligence community
Area
Global
Original language
it · translation not needed
Publication
30/07/2026 02:52
Sharing
TLP:CLEAR
Indicators reported by the source
39
IOCs indexed for lookup
0 values within the retention period
IOCs available in the STIX feed
25Last sharing verification: 2026-09-26T04:30:44.753867+00:00
MISP event
f9db7f4c-b8d6-4ed9-b9f1-d1990a7e1668
Classification
Medium
Open the original source