The threat landscape for Industrial Control Systems (ICS) and Operational Technology (OT) has reached a new level. Ransomware groups are deliberately targeting the IT and virtualization infrastructure that supports OT operations, APT actors are infiltrating supply chains for long-term prepositioning, and specialized OT malware is ruthlessly exploiting the lack of authentication in unsecured legacy protocols.
This article examines significant real-world incidents, the actual evolution of OT malware, the TTPs (tactics, techniques and procedures) of modern threat actors, and key findings from the situation reports published by Germany’s Federal Office for Information Security (BSI)1 and Dragos2.
1. Major incidents: What has happened in OT networks worldwide
Recent incidents reveal two clear major trends: targeted sabotage and espionage by APT groups against critical infrastructure on the one hand, and major production outages caused by collateral damage from IT ransomware on the other.
Incidents with direct OT impact & sabotage
- Municipal heating utility in Lviv, Ukraine (January 2024): First known real-world deployment of the FrostyGoop malware. The attackers exploited unsecured ENCO controllers (Zelio Logic / Modbus components) that were directly accessible from the internet. They did not downgrade firmware; instead, they sent legitimate Modbus TCP write commands (holding register manipulation) to falsify setpoints. This disrupted heat service to more than 600 residential buildings during subfreezing temperatures.
- Water utilities in the U.S. & Ireland (2023–2024): Several real-world incidents highlighted the vulnerability of exposed systems:
- Aliquippa (U.S., Nov. 2023): The pro-Iranian group CyberAv3ngers compromised Unitronics S70 PLCs that were accessible via default passwords and unsecured remote access.
- Muleshoe (Texas, Jan. 2024): The pro-Russian group Cyber Army of Russia Reborn manipulated SCADA systems, causing water tanks to overflow.
- Erris Water (Ireland, Dec. 2023): Another attack on Unitronics components disrupted water service to hundreds of households.
Collateral damage, supply chain & ransomware in production
- Viasat KA-SAT disruption (February 2022): An attack on the satellite operator’s management infrastructure (overwriting flash memory via AcidRain) disabled tens of thousands of terminals across Europe. Collateral impact on OT: Wind turbine manufacturer Enercon abruptly lost remote access to and monitoring capabilities for approximately 5,800 wind turbines in Germany.
- Contec SolarView compact attacks (May 2024): More than 800 SolarView Compact monitoring devices manufactured by Contec were compromised worldwide through unpatched RCE vulnerabilities (e.g., CVE-2022-29303) and abused as botnet nodes or leverage for extortion.
- Automotive & suppliers (VARTA, ThyssenKrupp, Honda): IT ransomware attacks caused production shutdowns lasting several days. In most cases, the cause was not encrypted PLC hardware, but the failure of OT support servers (e.g., VMware ESXi hosting MES, HMI, and historian VMs) or the preventive isolation of manufacturing networks.
2. The evolution of OT malware: Attackers’ toolsets
While traditional IT malware primarily targets files for encryption, specialized OT malware directly interferes with industrial control processes. A distinction must be made between state-developed APT frameworks and freely available red-team tools.
Key OT malware families at a glance
- TRITON / TRISIS (2017): Specifically targets Schneider Electric Triconex safety instrumented systems (SIS). Its purpose is to disable emergency shutdown mechanisms in critical process facilities (e.g., refineries), potentially enabling physical damage.
- PiPEDREAM / Chernovite (2022): The most versatile and modular OT malware framework identified to date. It covers six MITRE ATT&CK for ICS tactics and can manipulate PLCs (including Schneider Electric and Omron), OPC UA servers, and CODESYS-based systems without exploiting specific zero-day vulnerabilities.
- COSMICENERGY (2023) & Industroyer2 (2022): Both frameworks were developed specifically for power grids. They use the IEC 60870-5-104 (IEC-104) protocol to send commands directly to protection devices and circuit breakers in substations, potentially causing power outages.
- FrostyGoop (2024): The first malware observed in the wild whose sole attack vector is based on native interaction with Modbus TCP (port 502). Because the Modbus protocol provides no authentication, the malware selectively reads and writes holding registers to falsify process data.

3. BSI situation report & Germany focus: Where are the vulnerabilities?
The situation report from Germany’s Federal Office for Information Security (BSI) provides a clear picture of the country’s exposure and threat landscape. Germany ranks fourth worldwide in terms of the number of identified active APT groups. The BSI recorded 22 APT groups primarily targeting public administration, defense, and research, but increasingly also mechanical engineering and the energy sector.
Top vulnerabilities & initial access paths
- Remote access protocols in the crosshairs: Analysis of the internet-exposed attack surface shows SSH (52%), RDP (22%), Telnet (11%), and VNC (10%) as the dominant protocols. Insufficiently secured RDP and VNC access continues to represent a primary entry point into OT-adjacent management environments.
- Web interfaces & misconfigurations: Approximately 47% of reachable IP addresses in the .de domain expose sensitive system information. Forty-four percent of vulnerabilities reported to the BSI are attributable to misconfigurations or known, unpatched security flaws.
- Insufficient logging & OT monitoring: The lack of centralized logging and anomaly detection means that unauthorized interactions at the ICS level (e.g., unexpected Modbus write commands) can often remain undetected for months.
The Reality of OT Ransomware: Attacking the Virtualization Layer
A common misconception is that ransomware actors must develop their own ICS malware to shut down production. The reality is different:
- The target: Attackers use stolen credentials or Initial Access Brokers (IABs), move through enterprise IT (Levels 4/5) using living-off-the-land (LotL) techniques (PsExec, WMI, RDP), and target the hypervisor layer (e.g., VMware ESXi) as well as central support servers at Level 3 (Plant Area).
- The effect: Once servers supporting SCADA systems, HMIs, historian databases, and engineering workstations are encrypted or shut down, operators experience a complete loss of view and loss of control. For safety reasons, they are often left with only two options: a controlled emergency shutdown or a transition to manual island-mode operation.
5. Recommendations for OT Specialists & CISOs
These real-world incidents point to concrete measures for protecting OT environments:
Rhebo Industrial Protector helps eliminate blind spots in OT security: The solution addresses insufficient visibility into network assets, connections, and known vulnerabilities (CVEs), while closing security gaps created by undetected cyberattacks such as brute-force attacks, backdoors, zero-day exploits, lateral movement, or insider threats. It also provides reliable protection against outages caused by technical faults and network anomalies. This enables companies to significantly reduce the risk of OT downtime while efficiently meeting stringent NIS2 and IEC 62443 compliance requirements for network security and threat detection.
1 https://www.bsi.bund.de/DE/Service-Navi/Publikationen/Lagebericht/lagebericht_node.html
2 https://www.dragos.com/ot-cybersecurity-year-in-review

