Skip to content

OT/ICS Malware

Risk Level

OT/ICS malware targets Operational Technology, Industrial Control Systems, SCADA, and PLCs — systems that control real-world physical processes: power grids, water treatment, oil refineries, nuclear facilities. Attacks can cause physical destruction, environmental damage, and loss of life.

MilestoneYearDetails
Stuxnet2010Iranian centrifuges; first physical destruction
BlackEnergy2015Ukraine power grid; 230K people
Industroyer20162nd Ukraine outage; modular ICS
TRITON/TRISIS2017Safety systems; Middle East petrochem
INCONTROLLER2022Multi-ICS toolkit; multiple vendors
AspectITOT/ICS
PriorityCIA (Confidentiality)Safety, Availability, Integrity
PatchingRegular, automatedRare; downtime unacceptable
ProtocolsTCP/IP, standardModbus, DNP3, IEC 61850, PROFIBUS
AuthStandard authOften none (Modbus, DNP3)
Lifecycle3-5 years15-30 years
Safety SystemsN/ASIS (Safety Instrumented Systems)
MalwareYearAttributionTargetImpact
Stuxnet2010USA/Israel (Eq. Group)Iranian centrifugesPhysical destruction
BlackEnergy2015Russia (Sandworm)Ukraine power230K without power
Industroyer2016Russia (Sandworm)Ukraine powerModular ICS framework
TRITON/TRISIS2017Russia (Sandworm)Petrochem SISSafety system bypass
INCONTROLLER2022UnknownMulti-ICSSchneider, Omron, etc.
TechniqueDescription
IT→OT PivotInadequate segmentation; jump from IT to OT
Engineering WS CompromiseTarget Windows WS used to program PLCs
Protocol ExploitationModbus/DNP3/IEC 61850 — no auth
PLC Logic ModificationUpload malicious ladder logic
Safety System TargetingBypass SIS (TRITON)
Firmware AttackRTU, IED, PLC firmware modification
AspectDetails
TargetIranian Natanz uranium enrichment
MechanismPLC logic → centrifuge overspeed
SpreadUSB + LAN + print spooler + LNK + WinCC
Zero-days4 Windows zero-days
PLC TargetSiemens S7-300/400 (Profibus)
Impact~1000 centrifuges destroyed
  • Strict IT/OT Segmentation — DMZ, data diodes, unidirectional gateways
  • OT Asset Inventory — Discover undocumented field devices
  • Patch Management — Compensating controls where unpatchable
  • OT Monitoring — Claroty, Dragos, Nozomi, OT-specific IDS
  • Change Control — All PLC programming changes approved
  • OT-Specific IR — Safety-aware recovery procedures
  • Physical Security — Secure all access points
  • Training — OT-specific security training
TechniqueIDDescription
Modify ControllerT0831PLC logic modification
Alarm SuppressionT0836Hide alarms
Inhibit ResponseT0837Block safety response
Damage to PropertyT0879Physical destruction