
OT/ICS malware targets Operational Technology, Industrial Control Systems, SCADA, and PLCs — systems that control real-world physical processes: power grids, water treatment, oil refineries, nuclear facilities. Attacks can cause physical destruction, environmental damage, and loss of life.
| Milestone | Year | Details |
|---|
| Stuxnet | 2010 | Iranian centrifuges; first physical destruction |
| BlackEnergy | 2015 | Ukraine power grid; 230K people |
| Industroyer | 2016 | 2nd Ukraine outage; modular ICS |
| TRITON/TRISIS | 2017 | Safety systems; Middle East petrochem |
| INCONTROLLER | 2022 | Multi-ICS toolkit; multiple vendors |
| Aspect | IT | OT/ICS |
|---|
| Priority | CIA (Confidentiality) | Safety, Availability, Integrity |
| Patching | Regular, automated | Rare; downtime unacceptable |
| Protocols | TCP/IP, standard | Modbus, DNP3, IEC 61850, PROFIBUS |
| Auth | Standard auth | Often none (Modbus, DNP3) |
| Lifecycle | 3-5 years | 15-30 years |
| Safety Systems | N/A | SIS (Safety Instrumented Systems) |
| Malware | Year | Attribution | Target | Impact |
|---|
| Stuxnet | 2010 | USA/Israel (Eq. Group) | Iranian centrifuges | Physical destruction |
| BlackEnergy | 2015 | Russia (Sandworm) | Ukraine power | 230K without power |
| Industroyer | 2016 | Russia (Sandworm) | Ukraine power | Modular ICS framework |
| TRITON/TRISIS | 2017 | Russia (Sandworm) | Petrochem SIS | Safety system bypass |
| INCONTROLLER | 2022 | Unknown | Multi-ICS | Schneider, Omron, etc. |
| Technique | Description |
|---|
| IT→OT Pivot | Inadequate segmentation; jump from IT to OT |
| Engineering WS Compromise | Target Windows WS used to program PLCs |
| Protocol Exploitation | Modbus/DNP3/IEC 61850 — no auth |
| PLC Logic Modification | Upload malicious ladder logic |
| Safety System Targeting | Bypass SIS (TRITON) |
| Firmware Attack | RTU, IED, PLC firmware modification |
| Aspect | Details |
|---|
| Target | Iranian Natanz uranium enrichment |
| Mechanism | PLC logic → centrifuge overspeed |
| Spread | USB + LAN + print spooler + LNK + WinCC |
| Zero-days | 4 Windows zero-days |
| PLC Target | Siemens S7-300/400 (Profibus) |
| Impact | ~1000 centrifuges destroyed |
- ✅ Strict IT/OT Segmentation — DMZ, data diodes, unidirectional gateways
- ✅ OT Asset Inventory — Discover undocumented field devices
- ✅ Patch Management — Compensating controls where unpatchable
- ✅ OT Monitoring — Claroty, Dragos, Nozomi, OT-specific IDS
- ✅ Change Control — All PLC programming changes approved
- ✅ OT-Specific IR — Safety-aware recovery procedures
- ✅ Physical Security — Secure all access points
- ✅ Training — OT-specific security training
| Technique | ID | Description |
|---|
| Modify Controller | T0831 | PLC logic modification |
| Alarm Suppression | T0836 | Hide alarms |
| Inhibit Response | T0837 | Block safety response |
| Damage to Property | T0879 | Physical destruction |