ICS Threat Analysis: New, Experimental Malware Can Kill Engineering Processes
What it means
MISP EudorIA ha pubblicato l'advisory "ICS Threat Analysis: New, Experimental Malware Can Kill Engineering Processes". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.
Why it matters
Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.
Recommended actions
- Verificare tecnologie, versioni e servizi interessati nel proprio inventario.
- Consultare la fonte originale prima di pianificare la mitigazione.
Text acquired from the source
Evento MISP pubblicato con TLP:CLEAR: ICS Threat Analysis: New, Experimental Malware Can Kill Engineering Processes. Summary # ICS Threat Analysis: New, Experimental Malware Can Kill Engineering Processes #### Summary * Our analysis of a public malware repository shows a constant drumbeat of OT/ICS malware * Since +20% of all OT/ICS attacks target engineering workstations, we focused on it * We saw 2 incidents with Mitsubishi engineering workstations infected with [Ramnit]([URL rimossa]) worm * We analyzed 3 samples of new malware that kills Siemens engineering processes —we’ve named it Chaya\_003 #### Guidance * Harden engineering workstations * Segment the network * Monitor for threats * Full analysis and recommendations for mitigation are below OT-specific malware – such as FrostyGoop/BUSTLEBERM – is still much less common than malware targeting enterprise software or mobile operating systems by volume. But there’s little room to sleep easily if you’re a security operator in OT or manage [industrial control system security](/glossary/ics-security/). Malware in OT/ICS is more common than you think — and engineering workstations connected to the internet are targets. We [recently analyzed](/blog/targeting-ot-security-ics-threats-malware/) automated botnet families, such as Aisuru, Kaiten and Gafgyt, that could be found on the VirusTotal public malware repository around the same time as FrostyGoop/BUSTLEBERM. What we found included either default credentials of OT devices for initial infectio
- Source
- MISP EudorIA
- Publishing entity
- MISP EudorIA
- Entity type
- Intelligence community
- Area
- Global
- Original language
- it · translation not needed
- Publication
- 30/07/2026 02:52
- Sharing
- TLP:CLEAR
- Indicators reported by the source
- 39
- IOCs indexed for lookup
- 0 values within the retention period
- IOCs available in the STIX feed
- 25Last sharing verification: 2026-09-26T04:30:44.753867+00:00
- MISP event
- f9db7f4c-b8d6-4ed9-b9f1-d1990a7e1668
- Classification
- Medium