The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Industrial Automation
Breach intelligence, attack campaigns, and threat reports targeting the Industrial Automation sector.
Explore Other Sectors
Industrial Automation Threat Reports
'PassiveNeuron' SQL Server Attacks Expose Global Sectors to Espionage
In early 2024, a cyber-espionage campaign attributed to the 'PassiveNeuron' threat group targeted organizations in government, industrial, and financial sectors across Asia, Africa, and Latin America. Attackers exploited vulnerable SQL servers as entry points, deploying custom malware to stealthily exfiltrate sensitive data and facilitate lateral movement within compromised environments. The adversaries demonstrated a high degree of operational security, leveraging encrypted channels and bespoke tooling to evade conventional detection, resulting in significant data exposure and operational disruptions for affected entities. This incident reflects the increasing sophistication of cyber-espionage actors leveraging less-monitored databases and novel malware. It highlights a shift toward stealthy, persistent attacks against critical sectors—signaling the need for robust internal monitoring, segmentation, and east-west traffic controls to counter evolving threats.
8 months ago
Kill Chain
Blue Angel Suite Faces 2024 Webctrl.cgi OS Command Injection Attempts
In October 2024, threat actors attempted to exploit an OS command injection vulnerability targeting the Blue Angel Software Suite's web interface on embedded Linux devices. Attackers issued crafted POST requests to the '/cgi-bin/webctrl.cgi' endpoint, aiming to inject arbitrary shell commands via the 'ipaddress' parameter. These attacks, detected by honeypots, mirror previous vulnerabilities such as CVE-2025-34033, which allows authenticated attackers to execute code as root by manipulating input passed to system commands like 'ping'. The incidents highlight persistent risks across IoT and broadband equipment, potentially providing attackers with full system control. This incident underscores a growing trend in targeting network appliances and IoT infrastructure for initial access and lateral movement. As regulatory attention increases and attackers shift toward exploiting device misconfigurations and weak input validation, robust segmentation and up-to-date patch management are even more critical.
8 months ago
Kill Chain
Two CVSS 10.0 Flaws in Red Lion RTUs Expose Industrial Control Environments
In October 2025, two critical vulnerabilities (CVE-2023-40151 and CVE-2023-42770) were publicly disclosed in Red Lion Sixnet RTU devices, which are widely used for industrial automation and critical infrastructure. Both flaws received a CVSS 10.0 rating, underscoring their exploitability and impact. Attackers exploiting these vulnerabilities could achieve remote code execution with the highest privileges, granting them full control over affected devices. These RTUs are often deployed in energy, utilities, and manufacturing, raising concerns about the potential for business disruption, safety risks, and further attacks via compromised operational technology networks. This incident is particularly relevant as it highlights how legacy and specialized industrial control systems remain a prime target for threat actors leveraging zero-day vulnerabilities. The convergence of IT and OT, combined with growing regulatory scrutiny and an uptick in supply chain exposures, means that organizations must refocus on asset visibility and patch management for embedded and hard-to-update devices.
8 months ago
Kill Chain
PassiveNeuron: Unraveling the 2024–2025 Advanced Persistent Attack on Global Servers
Between June 2024 and August 2025, the advanced persistent threat (APT) campaign codenamed "PassiveNeuron" targeted government, financial, and industrial organizations primarily across Asia, Africa, and Latin America. Attackers exploited SQL servers—likely leveraging vulnerabilities or credential brute-forcing—to gain initial access, followed by repeated attempts to deploy web shells. When thwarted by robust endpoint protections, the attackers escalated to advanced techniques, implementing a multi-stage DLL loader chain to deliver custom implants ('Neursite' and 'NeuralExecutor') and leveraging Cobalt Strike for lateral movement and persistence. These tools enabled sophisticated data gathering, process management, and network proxying, all while leveraging various encryption and obfuscation tactics to evade detection. This incident exemplifies the ongoing evolution of targeted cyberespionage against server infrastructure, with attribution leaning towards a Chinese-speaking threat actor based on tactics and C2 infrastructure, though with some ambiguity due to apparent false flags. It reflects a rise in multi-stage, stealthy attacks leveraging both custom and widely abused tools, highlighting the elevated risk posed to internet-exposed critical servers.
8 months ago
Kill Chain
How BlackSuit Ransomware Hit a Global Equipment Manufacturer in 2024
In early 2024, a global equipment manufacturer experienced a significant ransomware attack carried out by the threat actor Ignoble Scorpius, leveraging the BlackSuit ransomware. The attack began with a sophisticated vishing campaign targeting an employee, leading to credential compromise and lateral movement within the company’s network. Attackers bypassed multiple defenses, ultimately deploying the ransomware to encrypt critical business systems and disrupt operations worldwide. The incident required rapid response, threat intelligence analysis, and comprehensive remediation to restore services and protect sensitive data. This incident highlights the growing danger of human-centric social engineering combined with advanced ransomware—a tactic increasingly adopted by organized threat actors. With the resurgence of targeted and blended attacks, organizations face urgent pressure to strengthen security controls and resilience against such evolving threats.
8 months ago
Kill Chain
Attackers Exploit Milesight Routers to Launch European SMS Phishing Wave
In early 2025, unidentified threat actors exploited vulnerabilities in Milesight industrial cellular routers to launch a large-scale smishing campaign across Europe. By abusing the routers’ publicly exposed APIs, attackers sent malicious SMS messages containing phishing URLs directly to mobile users in countries including Sweden and Italy. This campaign has been ongoing since at least February 2022, with attackers leveraging compromised infrastructure to bypass traditional security filters, resulting in widespread delivery of credential-theft links and potential downstream attacks. This incident highlights the increasing trend of attackers targeting edge infrastructure and IoT devices to amplify their phishing and malware operations. As threat actors shift tactics toward abusing legitimate network equipment, organizations face new regulatory and operational risks, with urgent need to secure device APIs, implement segmentation, and strengthen monitoring to counter evolving smishing threats.
8 months ago
Kill Chain
China-Linked PlugX and Bookworm Malware Strike Asian Telecoms in Advanced Attack
In mid-2025, a coordinated advanced persistent threat (APT) campaign linked to China targeted telecommunications and manufacturing entities across Central and South Asia. Attackers leveraged new PlugX and Bookworm malware variants, utilizing DLL side-loading techniques via legitimate applications to achieve persistence and evade detection. The intrusions allowed the threat actors to perform extensive reconnaissance, deploy additional payloads, and exfiltrate sensitive operational data from ASEAN and Asian telecom networks, demonstrating a high degree of stealth and sophistication in lateral movement. This incident underscores a growing uptick in nation-state cyber activity against Asian critical infrastructure, highlighting emerging malware evolution and increasingly covert lateral movement. With similar TTPs proliferating, organizations must elevate east-west traffic security and anomaly detection to stay ahead.
8 months ago
Kill Chain
ICS Malware Attacks Spike in Q2 2025: Key Lessons for Industrial Automation Security
In Q2 2025, industrial automation systems worldwide experienced significant and persistent threats, with 20.5% of ICS (Industrial Control Systems) computers encountering malicious objects, despite a slight quarterly decrease. Attackers leveraged a multi-stage campaign, beginning with phishing emails and malicious documents to gain access, and subsequently deploying next-stage malware such as spyware, ransomware, and cryptominers. Regions like Africa and sectors such as biometrics were among the most targeted, while common initial infection sources included malicious internet resources, infected emails, and removable media devices. Multiple sophisticated malware families (over 10,000 variants) exploited ICS security gaps to enable lateral movement, persistent access, and data exfiltration, impacting operational resilience and increasing risk of service disruption for critical industries. This incident underscores the continued evolution of ICS-targeting malware and the increasing sophistication of attack vectors in the operational technology sector. The upward trend in email-based infiltration and malicious cloud links, coupled with persistent use of multi-stage payloads, highlights the urgent need for robust, layered security, Zero Trust policies, and compliance alignment to protect critical infrastructure environments against both commodity and targeted threats.
8 months ago
Kill Chain
Active Exploitation of Critical CVE-2025-5086 in DELMIA Apriso Threatens Manufacturing Operations
In September 2025, a critical vulnerability (CVE-2025-5086, CVSS 9.0) in Dassault Systèmes DELMIA Apriso Manufacturing Operations Management software was found to be actively exploited in the wild. Threat actors leveraged this flaw to gain unauthorized access, bypassing authentication and executing arbitrary code on exposed systems. The breach impacted several manufacturing sector organizations globally, leading to disruptions in operational technology, potential data compromise, and urgent incident response actions. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) responded by adding the flaw to its Known Exploited Vulnerabilities (KEV) catalog and issuing public guidance for immediate patching and mitigation. This incident is significant as adversaries continue to target vulnerable OT/IoT platforms central to manufacturing operations. The increased frequency of high-severity vulnerabilities in critical infrastructure software, combined with rapid weaponization by threat actors, is driving regulatory scrutiny and highlighting the urgent need for robust vulnerability management and zero trust controls across industrial environments.
8 months ago
Kill Chain
Bridgestone Americas 2024 Cyberattack Disrupts North American Manufacturing
In early 2024, Bridgestone Americas, a leading tire manufacturer, experienced a cyberattack that impacted several of its North American manufacturing plants. The incident led to operational disruptions, with reports confirming at least one plant in Quebec suspending activity. Bridgestone acted promptly, implementing its established cyber incident response protocols and containing the breach while launching a forensic investigation to determine the incident's scope. According to statements from company officials and local authorities, no employee or customer data was reported compromised, and business operations have largely returned to normal as of the latest updates. This attack highlights how IT/OT convergence in manufacturing continues to expose critical infrastructure to cyber threats, even in the absence of clear threat actor attribution or significant data loss. The event underscores the rising necessity for robust east-west security controls and rapid response capabilities within industrial environments facing increasing cyber risk.
8 months ago
Kill Chain
U.S. Indicts Ukrainian Ransomware Operator Behind Hundreds of Global Attacks
In June 2024, the U.S. Department of Justice indicted Volodymyr Tymoshchuk, a Ukrainian national linked to the development and deployment of the Nefilim, LockerGoga, and MegaCortex ransomware variants. Operating under aliases such as 'deadforz' and 'farnetwork,' Tymoshchuk and his co-conspirators targeted organizations—including healthcare, industrial, and blue-chip companies—across the U.S., Europe, and Australia from at least 2018 onward. Over 250 U.S. and hundreds of global victims experienced encrypted systems, data theft, and significant operational disruption, resulting in tens of millions of dollars in damages attributed to ransom payments, mitigation, and recovery costs. This indictment underscores increasing law enforcement cooperation and heightened government focus on disrupting ransomware-as-a-service ecosystems. The ongoing campaign and associated public rewards for information highlight how ransomware actors continue evolving tactics, targeting high-revenue organizations and leveraging affiliate networks to scale global extortion operations.
8 months ago
Kill Chain
Jaguar Land Rover Ransomware Breach Disrupts Global Operations in 2024
In June 2024, Jaguar Land Rover (JLR), the renowned luxury automotive manufacturer, experienced a major ransomware-related cyber incident that forced the company to shut down vital portions of its IT infrastructure. The disruption, which began on a Sunday and quickly affected production and retail activities globally, resulted in assembly line stoppages at key UK plants including Halewood and Solihull. JLR responded by disabling systems to prevent further attacker movement and data loss, launching an internal investigation with forensics partners to determine entry vectors, potential data exposure, and persistent threats. While the company stated there was no evidence of customer data being compromised, the operational and financial impacts were significant. This incident underscores the ongoing trend of ransomware actors targeting critical manufacturing and supply chain operations, where downtime can rapidly translate into massive losses. The event serves as a stark reminder that even mature organizations face evolving threats that can bypass traditional security controls, highlighting the urgent need for zero trust segmentation, enhanced network monitoring, and rapid anomaly detection.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports