Industrial sector threats on the rise: an annual overview by Kaspersky

According to the 2022 ICS threat landscape report by Kaspersky ICS CERT, more than 40 percent of operational technology (OT) computers were affected by malicious objects. H2 2022 was the period with the highest rate of attacks against industrial sectors with 34.3 percent of computers affected. The second half of the last year was also marked by a rising number of attacks carried out using malicious scripts, phishing pages (JS and HTML) and denylisted resources. Attacks on automotive manufacturing and energy sector showed unprecedented growth and accounted for 36.9 percent and 34.5 percent of all industries.

In H2 2022, Kaspersky security solutions blocked malware from 7,684 different families on industrial automation systems, such as building automation, automotive, oil and gas, energy and engineering. This number is slightly more (6%) compared with the previous half of the year and almost 1.5 times more than in the second half of 2021. Overall, the 2022 ended up being the year that accounts for the highest percentage of OT computers affected by malware (40.6%).

In terms of malware categories, only the two top rankings showed growth in the second half of 2022, namely malicious scripts and phishing pages (JS and HTML) anddenylisted internet resources. Other categories of malicious objects either decreased or remained unchanged.

Malicious scripts and phishing pages (JS and HTML) are distributed both online and via email. A significant part of denylisted internet resources are used to distribute malicious scripts and phishing pages.

Threat actors use malicious scripts for a broad range of tasks from collecting information, tracking activity, and redirecting browser requests to malicious web resources, to downloading various malicious programs or loading malware ‎(spyware or tools for covert cryptocurrency mining)‎ in the user’s browser.

When it comes to the industries being effected in North America (U.S. and Canada), building automation saw the highest percent of OT computers that were attacked (22%) following by manufacturing (21%), ICS engineering and integration (19%), oil and gas (19%) and energy (16%).

“Overall, 2022 stands out for its abnormal absence of any seasonal changes,” said Kirill Kruglov, senior researcher at Kaspersky ICS CERT. “Our team observed a steadily high rate of attacks on industrial sectors – without a typical drop-in attacks during summer vacations or winter holidays period. However, the growing attack rates in industrial sectors, that are being conducted using social engineering, seem alarming. We strongly recommend customers in these sectors to revise their existing approach to security and check whether all security systems are up-to-date and their personnel is well-trained.”

Read more about the ICS threat landscape in H2 2022 on the Kaspersky ICS CERT website.

LEAVE A REPLY

Please enter your comment!
Please enter your name here