New Report Identifies the Internet as the Leading Threat to Industrial Automation Systems

A new report from Kaspersky ICS CERT on the global threat landscape for Industrial Control Systems (ICS) in the first quarter of 2025 underscores a critical development: the internet remains the principal vector for cyberthreats targeting industrial automation systems.

Despite advances in cybersecurity awareness, the global percentage of ICS computers on which malicious objects were blocked stayed at a persistent 21.9%, revealing ongoing vulnerabilities within operational technology (OT) networks worldwide.

Internet as the Top Threat Vector

The internet continues to outpace all other threat sources for ICS environments, with Kaspersky’s telemetry attributing the majority of initial infection attempts to malicious or compromised web resources, along with payloads delivered via cloud services, messengers, and content delivery networks.

Regional data shows varied exposures: Africa leads with 12.76% of ICS computers affected by internet-borne threats, followed by Southeast Asia at 12.32%, and South Asia at 10.83%.

Automation Systems
Changes in the percentage of attacked ICS computers in Q1 2025

Even in more secure regions like Northern Europe, 5.24% of systems encountered internet-based attacks.

The most prevalent internet threats include access to denylisted resources, malicious scripts and phishing sites, cryptocurrency web miners, and spyware.

High exposure often correlates with insufficient OT-IT network segmentation and underdeveloped cybersecurity policies that allow ICS endpoints inappropriate access to external networks.

Email clients remain the second most common vector for ICS intrusions, primarily through phishing emails containing malicious documents and scripts.

Southern Europe, the Middle East, and Latin America are especially impacted, with rates of 6.76%, 5.17%, and 4.55% respectively.

While email threats remain a global concern, Russia, for example, reported the lowest rate at just 0.88%.

Removable media USB drives and similar devices continue to propagate worms, viruses, and spyware, although these threats are gradually declining in prevalence.

Africa remains the most affected region, with 2.44% of ICS computers encountering malware from removable media, a figure nearly five times the global average.

Technical Attack Trends

The analysis groups malicious objects by their function and propagation methods: initial infection tools (malicious links, documents, and scripts), next-stage malware (spyware, ransomware, miners), and self-propagating malware (worms, viruses).

Initial infection is still linked predominantly to internet and email exposure, with denylisted resources and phishing scripts the most-blocked categories globally.

The report highlights an increase in cryptocurrency mining attacks within ICS environments.

Threat actors are leveraging both web-based miners and Windows executables, often distributed as archives containing malicious shortcut (LNK) files that initiate PowerShell-based, fileless attacks.

Such methods evade traditional antivirus solutions and underscore the growing sophistication of adversaries targeting industrial networks.

Spyware also maintains a high profile, particularly in Africa and Southern Europe, where it is leveraged for credential theft, data exfiltration, and as a precursor to targeted ransomware campaigns.

Ransomware detection rates were highest in East Asia, the Middle East, and Africa, revealing the penetration of advanced persistent threats into critical industrial sectors.

While the internet is universally acknowledged as the dominant threat source for ICS, regional differences illustrate disparities in cyber defense readiness.

Africa and Southeast Asia exhibit rates of ICS compromise that significantly exceed the global average, attributed to underinvestment in cybersecurity, lack of basic protections, and rapid industrialization outpacing deployment of secure architectures.

Conversely, regions like Northern and Western Europe, along with Australia and New Zealand, report markedly lower levels of detected attacks, reflecting stronger isolation of OT environments and greater cybersecurity maturity.

According to the Report, Kaspersky’s Q1 2025 assessment reiterates that internet connectivity is the Achilles’ heel of industrial automation.

The findings reinforce the need for rigorous network segmentation, robust perimeter defenses, least-privilege internet access policies for OT assets, and continual employee awareness training.

As threat actors refine their techniques pushing fileless malware, mining operations, and multi-stage intrusions ICS operators must pursue proactive, adaptive security strategies to defend against the internet-driven wave of industrial cyberthreats.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Update

Mandvi
Mandvi
Mandvi is a Security Reporter covering data breaches, malware, cyberattacks, data leaks, and more at Cyber Press.

Trending News

Related Stories