{"id":754,"date":"2021-08-10T12:39:48","date_gmt":"2021-08-10T10:39:48","guid":{"rendered":"https:\/\/www.icsec.pl\/5-cyber-atakow-na-sieci-ics\/"},"modified":"2022-07-08T12:02:10","modified_gmt":"2022-07-08T10:02:10","slug":"5-cyber-atakow-na-sieci-ics","status":"publish","type":"post","link":"https:\/\/icsec.pl\/en\/5-cyber-atakow-na-sieci-ics\/","title":{"rendered":"6 cyberattacks on ICS networks"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><span class=\"TextRun SCXW47000577 BCX0\" xml:lang=\"PL-PL\" data-contrast=\"none\" lang=\"PL-PL\"><span class=\"NormalTextRun SCXW47000577 BCX0\" data-ccp-parastyle=\"Normal (Web)\">Is the OT network bac<\/span><span class=\"NormalTextRun SCXW47000577 BCX0\" data-ccp-parastyle=\"Normal (Web)\">k<\/span><span class=\"NormalTextRun SCXW47000577 BCX0\" data-ccp-parastyle=\"Normal (Web)\">fired or is it an increasingly trendy target for attacks?<\/span><\/span><span class=\"EOP SCXW47000577 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Since the days of the large encyclopedia of computer viruses in cult MS-DOS-era antivirus programs, the evolution of threats has clearly changed direction. In the past several years, various viruses and trojans have given way primarily to phishing and ransomware, and instead of the average Internet user&#8217;s computer, network devices and server components in businesses and corporations have become targets. In addition to the financial motive, cyber-attacks &#8211; sometimes taking the form of APTs (Advanced Persistent Threat) &#8211; are sometimes launched by &#8220;hacktivists&#8221; or groups with likely geopolitical ties, where disrupting a business or critical infrastructure will be of strategic importance to the political or economic relationship between two countries. Therefore, a new niche is slowly growing inexorably in this landscape &#8211; attacks on industrial networks. It&#8217;s increasingly difficult today to imagine OT infrastructure cut off from the Internet at every possible point &#8211; the benefits of combining IT and OT, such as remote monitoring and automation of OT maintenance activities, bring tangible benefits, including financial ones. But there&#8217; s another side to the coin. Here&#8217;s a look at some of the most popular, and yet the only open to the general public, examples of malware targeting OT networks. Knowledge about these attacks can help  analyze the risk in one&#8217;s own infrastructure. It is also worth remembering that malware targeting critical infrastructure is not the only possible cause of industrial failures or downtime (there are also examples of classic attacks where the victims were or were supposed to be industrial companies or critical infrastructures; see WannaCry\/NotPetya, LockerGoga, ransomware at Colonial Pipeline, remote access by a former Post Rock Water District employee). <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">1<br>\r\nStuxnet<br>\r\n\r\nYear of detection: 2010<br>\r\n\r\nCreator: Equation Group (likely: US\/NSA\/TAO, Israel\/IDF\/Unit 8200)<br>\r\n\r\nMotive: geopolitics<br>\r\n\r\nType of attack: worm, APT<br>\r\n\r\nEntry point and direction of attack: Infected media, MS Windows, Siemens WinCC\/PCS 7\/STEP7 (SCADA), Siemens PLC (e.g. Simatic S7-300) with specific VFDs (Vacon or Fararo Paya) operating in a specific frequency range (807 &#8211; 1210 Hz)<br>\r\n\r\nType of activity: industrial espionage, disruption of frequency converters in uranium enrichment centrifuges resulting in destruction of aluminum centrifuge tubes<br>\r\n\r\nFeatures: malicious software specifically targeting the uranium enrichment site at Natanz, Iran; highly complex code and sophisticated PLC attack criteria requiring an enormous amount of specialised knowledge and manpower, which, according to experts, is only possible with government involvement<br>\r\n\r\nKnown victims: Atomic Energy Organization of Iran<br>\r\n\r\nImpact of the attack: up to 1,000 centrifuges (10%) destroyed on Iranian territory, retaliatory cyberattacks on US banks<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span data-contrast=\"none\">2<\/span><br><span data-contrast=\"none\">BlackEnergy<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Year of detection: 2007<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Creator: Sandworm (Russia)<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Motive: unspecified<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Type of attack: Botnet, DDoS<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Entry point and attack direction: Phishing\/spear-phishing, malicious Word\/PowerPoint attachments<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Action type: DDoS, keylogging, password capture, screenshots, &#8220;remote desktop&#8221;, network scanning, destruction of infected system, among others<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Features: several versions of&nbsp;BlackEnergy&nbsp;with new features added over several years of development, rich toolkit<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Known victims: energy infrastructure in Ukraine (Prykarpattyaoblenergo,&nbsp;Chernivtsioblenergo,&nbsp;Kyivoblenergo)<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Impact of the attack: the attack included shutting down power substations via SCADA, disabling or destroying IP infrastructure components (e.g. modems and UPS systems), distributing other malware to destroy data on servers and workstations, DDoS on call-centers; the main impact was the shutdown of dozens of substations (110 kV and 35 kV), blocking the supply of 73 MWh of electricity; more than 200,000 residents were cut off from power for several hours<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span data-contrast=\"none\">3<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Havex<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Year of detection: 2013<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Creator: Energetic Bear (Russia)<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span>\r\n\r\n<span data-contrast=\"none\">Motive: industrial espionage<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span>\r\n\r\n<span data-contrast=\"none\">Type of attack: trojan, APT<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span>\r\n\r\n<span data-contrast=\"none\">Entry point and attack direction: Phishing\/spear-phishing, malicious Word\/PowerPoint attachments, redirection from frequently visited sites to their malware counterparts or&nbsp;&#8211; in case of vulnerable manufacturer sites &#8211; replacement of official software with malware-containing ones, weak security at IT\/OT interface, OPC protocol<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Type of operation: remote control, network scanning for OT devices (e.g. Siemens and Rockwell Automation), logging data capture, screenshots, file transfer<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Features: almost a hundred variants of malware<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Known victims: MESA Imaging,&nbsp;eWON\/Talk2M, MB Connect Line as examples of vendors whose websites were enriched with&nbsp;Havex&nbsp;malware; more than 2,000 sites across the U.S. and Europe became targets of espionage campaigns in multiple sectors (initially in defense and aerospace, then in energy, pharmaceuticals and oil and gas industries, etc.)<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Impact of the attack: difficult to determine<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span data-contrast=\"none\">4<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Industroyer\/Crashoverride<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Year of detection: 2016<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Creator: Electrum\/Sandworm (Russia)<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Motive: unknown<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Type of attack: backdoor,&nbsp;wiperware<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Entry point and direction of attack: exploitation of vulnerabilities in Siemens SIPROTEC\/SIPROTEC 4 equipment, shutting down substations, deleting configuration files on workstations controlling the infrastructure and destroying the operating system<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Type of operation: disruption of ICS systems in substations; mapping of infrastructure based on a number of protocols (OPC, IEC 61850, IEC 101, IEC 104), execution of commands on reachable control devices, deletion of all system registry keys on infected computers and overwriting of files to damage the infected system and make it unbootable, overwriting of ICS configuration files on all local and remote drives (specifically, files related to ABB PCM600)<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Features: versatility and modularity; first known malware specifically targeting energy infrastructure, indicating high specialization of its creator in the area of ICS systems; second known malware (after Stuxnet) directly targeting industrial systems<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Known victims: Kiev, Ukraine<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Effects of the attack: 20% of Kyiv area was cut off from power supply for one hour (probably a test attack)<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span data-contrast=\"none\">5<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">TRITON<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Year of detection: 2017<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Creator: CNIIHM (Russia) or Helix Kitten\/APT34 (Iran)<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Motive: unknown<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Type of attack: APT<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Point of entry and direction of attack: insufficient firewall configuration, taking control of controller machine (Windows), zero-day vulnerability, disrupting industrial process safety systems (SIS)<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Type of operation: maintaining continuous attacker&#8217;s access to Tricon 3008 (Schneider Electric) systems with a specific software version, with the possibility of reprogramming the system, e.g. &#8220;sleeping&#8221; safety mechanisms (allowing to detect e.g. the release of toxic and extremely flammable hydrogen sulfide)<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Features: uncompromising attack with the objective of causing severe physical consequences of the attack with the risk of loss of human lives; first known attack on SIS systems<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Known victims: Petro Rabigh refinery (Saudi Arabia)<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Impact of the attack: failure mode of several controllers while the attackers attempted to reprogram them (which in turn allowed the attack to be detected &#8211; it is suspected that the intruders&#8217; operation may have originated in 2014)<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span data-contrast=\"none\">6<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">EKANS<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Year of detection: 2019\/2020<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Creator: unknown<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Motive: financial<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Type of attack: ransomware<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Entry point and attack direction: phishing\/spear-phishing to capture login credentials, or vulnerabilities in the RDP protocol (no exploitation of this method has been observed)<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Mode of operation: encryption of files on the infected machine and on attached network resources, disabling selected (kill list) processes of security systems,&nbsp;databases (e.g. MS SQL Server), backup systems (e.g. IBM Tivoli) and ICS systems (e.g. Proficy)<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Features: ransomware attack deliberately targeting ICS processes; &#8220;target list&#8221; including system processes and database or industrial applications indicates inspiration\/evolution from&nbsp;MegaCortex&nbsp;ransomware, formerly&nbsp;LockerGog; EKANS appears to be a &#8220;hardened&#8221;&nbsp;MegaCortex&nbsp;variant<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Known victims: Fresenius Group, Honda, Enel Group; affected companies in energy, architecture, healthcare, transportation and manufacturing<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><br><span data-contrast=\"none\">Effects of the attack: from negligible (ended with an attempt to introduce malware) to actually taking programmed actions resulting in, among others, suspension of production in the affected area<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In conclusion, it is worth remembering that besides the easiest way for malware to enter an industrial area is through the IT network or computer stations in the OT network. Risk analysis and security measures adopted should take into account not only the protection of industrial automation systems but also IT devices, because at the organizational level, a successful attack on the IT area itself may also result in the need to halt industrial processes. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Is the OT network backfired or is it an increasingly trendy target for attacks?&nbsp; Since the days of the large encyclopedia of computer viruses in cult MS-DOS-era antivirus programs, the evolution of threats has clearly changed direction. In the past several years, various viruses and trojans have given way primarily to phishing and ransomware, and [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":643,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[29],"class_list":["post-754","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-en"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v21.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>6 cyberattacks on ICS networks - ICsec<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/icsec.pl\/en\/5-cyber-atakow-na-sieci-ics\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"6 cyberattacks on ICS networks - ICsec\" \/>\n<meta property=\"og:description\" content=\"Is the OT network backfired or is it an increasingly trendy target for attacks?&nbsp; Since the days of the large encyclopedia of computer viruses in cult MS-DOS-era antivirus programs, the evolution of threats has clearly changed direction. In the past several years, various viruses and trojans have given way primarily to phishing and ransomware, and [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/icsec.pl\/en\/5-cyber-atakow-na-sieci-ics\/\" \/>\n<meta property=\"og:site_name\" content=\"ICsec\" \/>\n<meta property=\"article:published_time\" content=\"2021-08-10T10:39:48+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-07-08T10:02:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/icsec.pl\/content\/uploads\/2021\/08\/MicrosoftTeams-image-6.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"610\" \/>\n\t<meta property=\"og:image:height\" content=\"343\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Karolina\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@ICsec_SA\" \/>\n<meta name=\"twitter:site\" content=\"@ICsec_SA\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Karolina\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/icsec.pl\/en\/5-cyber-atakow-na-sieci-ics\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/icsec.pl\/en\/5-cyber-atakow-na-sieci-ics\/\"},\"author\":{\"name\":\"Karolina\",\"@id\":\"https:\/\/icsec.pl\/#\/schema\/person\/e4532267aeac86bb8e793fd6ee2052c8\"},\"headline\":\"6 cyberattacks on ICS networks\",\"datePublished\":\"2021-08-10T10:39:48+00:00\",\"dateModified\":\"2022-07-08T10:02:10+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/icsec.pl\/en\/5-cyber-atakow-na-sieci-ics\/\"},\"wordCount\":1345,\"publisher\":{\"@id\":\"https:\/\/icsec.pl\/#organization\"},\"articleSection\":[\"Blog\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/icsec.pl\/en\/5-cyber-atakow-na-sieci-ics\/\",\"url\":\"https:\/\/icsec.pl\/en\/5-cyber-atakow-na-sieci-ics\/\",\"name\":\"6 cyberattacks on ICS networks - ICsec\",\"isPartOf\":{\"@id\":\"https:\/\/icsec.pl\/#website\"},\"datePublished\":\"2021-08-10T10:39:48+00:00\",\"dateModified\":\"2022-07-08T10:02:10+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/icsec.pl\/en\/5-cyber-atakow-na-sieci-ics\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/icsec.pl\/en\/5-cyber-atakow-na-sieci-ics\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/icsec.pl\/en\/5-cyber-atakow-na-sieci-ics\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Strona g\u0142\u00f3wna\",\"item\":\"https:\/\/icsec.pl\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"6 cyberattacks on ICS networks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/icsec.pl\/#website\",\"url\":\"https:\/\/icsec.pl\/\",\"name\":\"ICsec\",\"description\":\"Tworzymy dla przemys\u0142u produkty, kt\u00f3re zwi\u0119kszaj\u0105 cyberbezpiecze\u0144stwo\",\"publisher\":{\"@id\":\"https:\/\/icsec.pl\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/icsec.pl\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/icsec.pl\/#organization\",\"name\":\"ICsec S.A.\",\"url\":\"https:\/\/icsec.pl\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/icsec.pl\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/icsec.pl\/content\/uploads\/2021\/10\/icsec-logo-u-1.svg\",\"contentUrl\":\"https:\/\/icsec.pl\/content\/uploads\/2021\/10\/icsec-logo-u-1.svg\",\"width\":226.8,\"height\":226.8,\"caption\":\"ICsec S.A.\"},\"image\":{\"@id\":\"https:\/\/icsec.pl\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/twitter.com\/ICsec_SA\",\"https:\/\/www.linkedin.com\/company\/icsecsa\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/icsec.pl\/#\/schema\/person\/e4532267aeac86bb8e793fd6ee2052c8\",\"name\":\"Karolina\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/icsec.pl\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/f69546f462690756af217be333db2d2410b6ece505762a4fe9084137ee5e3ea3?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/f69546f462690756af217be333db2d2410b6ece505762a4fe9084137ee5e3ea3?s=96&d=mm&r=g\",\"caption\":\"Karolina\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"6 cyberattacks on ICS networks - ICsec","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/icsec.pl\/en\/5-cyber-atakow-na-sieci-ics\/","og_locale":"en_US","og_type":"article","og_title":"6 cyberattacks on ICS networks - ICsec","og_description":"Is the OT network backfired or is it an increasingly trendy target for attacks?&nbsp; Since the days of the large encyclopedia of computer viruses in cult MS-DOS-era antivirus programs, the evolution of threats has clearly changed direction. In the past several years, various viruses and trojans have given way primarily to phishing and ransomware, and [&hellip;]","og_url":"https:\/\/icsec.pl\/en\/5-cyber-atakow-na-sieci-ics\/","og_site_name":"ICsec","article_published_time":"2021-08-10T10:39:48+00:00","article_modified_time":"2022-07-08T10:02:10+00:00","og_image":[{"width":610,"height":343,"url":"https:\/\/icsec.pl\/content\/uploads\/2021\/08\/MicrosoftTeams-image-6.jpg","type":"image\/jpeg"}],"author":"Karolina","twitter_card":"summary_large_image","twitter_creator":"@ICsec_SA","twitter_site":"@ICsec_SA","twitter_misc":{"Written by":"Karolina","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/icsec.pl\/en\/5-cyber-atakow-na-sieci-ics\/#article","isPartOf":{"@id":"https:\/\/icsec.pl\/en\/5-cyber-atakow-na-sieci-ics\/"},"author":{"name":"Karolina","@id":"https:\/\/icsec.pl\/#\/schema\/person\/e4532267aeac86bb8e793fd6ee2052c8"},"headline":"6 cyberattacks on ICS networks","datePublished":"2021-08-10T10:39:48+00:00","dateModified":"2022-07-08T10:02:10+00:00","mainEntityOfPage":{"@id":"https:\/\/icsec.pl\/en\/5-cyber-atakow-na-sieci-ics\/"},"wordCount":1345,"publisher":{"@id":"https:\/\/icsec.pl\/#organization"},"articleSection":["Blog"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/icsec.pl\/en\/5-cyber-atakow-na-sieci-ics\/","url":"https:\/\/icsec.pl\/en\/5-cyber-atakow-na-sieci-ics\/","name":"6 cyberattacks on ICS networks - ICsec","isPartOf":{"@id":"https:\/\/icsec.pl\/#website"},"datePublished":"2021-08-10T10:39:48+00:00","dateModified":"2022-07-08T10:02:10+00:00","breadcrumb":{"@id":"https:\/\/icsec.pl\/en\/5-cyber-atakow-na-sieci-ics\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/icsec.pl\/en\/5-cyber-atakow-na-sieci-ics\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/icsec.pl\/en\/5-cyber-atakow-na-sieci-ics\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Strona g\u0142\u00f3wna","item":"https:\/\/icsec.pl\/en\/"},{"@type":"ListItem","position":2,"name":"6 cyberattacks on ICS networks"}]},{"@type":"WebSite","@id":"https:\/\/icsec.pl\/#website","url":"https:\/\/icsec.pl\/","name":"ICsec","description":"Tworzymy dla przemys\u0142u produkty, kt\u00f3re zwi\u0119kszaj\u0105 cyberbezpiecze\u0144stwo","publisher":{"@id":"https:\/\/icsec.pl\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/icsec.pl\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/icsec.pl\/#organization","name":"ICsec S.A.","url":"https:\/\/icsec.pl\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/icsec.pl\/#\/schema\/logo\/image\/","url":"https:\/\/icsec.pl\/content\/uploads\/2021\/10\/icsec-logo-u-1.svg","contentUrl":"https:\/\/icsec.pl\/content\/uploads\/2021\/10\/icsec-logo-u-1.svg","width":226.8,"height":226.8,"caption":"ICsec S.A."},"image":{"@id":"https:\/\/icsec.pl\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/twitter.com\/ICsec_SA","https:\/\/www.linkedin.com\/company\/icsecsa\/"]},{"@type":"Person","@id":"https:\/\/icsec.pl\/#\/schema\/person\/e4532267aeac86bb8e793fd6ee2052c8","name":"Karolina","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/icsec.pl\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/f69546f462690756af217be333db2d2410b6ece505762a4fe9084137ee5e3ea3?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f69546f462690756af217be333db2d2410b6ece505762a4fe9084137ee5e3ea3?s=96&d=mm&r=g","caption":"Karolina"}}]}},"_links":{"self":[{"href":"https:\/\/icsec.pl\/en\/wp-json\/wp\/v2\/posts\/754","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/icsec.pl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/icsec.pl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/icsec.pl\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/icsec.pl\/en\/wp-json\/wp\/v2\/comments?post=754"}],"version-history":[{"count":44,"href":"https:\/\/icsec.pl\/en\/wp-json\/wp\/v2\/posts\/754\/revisions"}],"predecessor-version":[{"id":1376,"href":"https:\/\/icsec.pl\/en\/wp-json\/wp\/v2\/posts\/754\/revisions\/1376"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/icsec.pl\/en\/wp-json\/wp\/v2\/media\/643"}],"wp:attachment":[{"href":"https:\/\/icsec.pl\/en\/wp-json\/wp\/v2\/media?parent=754"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/icsec.pl\/en\/wp-json\/wp\/v2\/categories?post=754"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}