Executive Summary
In Q2 2026, Kaspersky's industrial threat landscape report revealed a significant shift in cybersecurity threats targeting industrial control systems (ICS), with malicious objects blocked on 19.15% of ICS computers—the lowest level since 2022. The report identified 10,904 different malware families affecting industrial automation systems, with malicious scripts and phishing pages leading threat categories at 5.42% globally. Notable regional variations emerged, with Africa showing the highest attack rates at 27.9% while Northern Europe recorded the lowest at 8.1%. The biometrics sector faced the most severe threats at 26.44%, experiencing increases across multiple threat vectors including ransomware, spyware, and malicious documents.
This trend reflects the evolving sophistication of threat actors targeting critical infrastructure, coinciding with increased adoption of cloud-native industrial systems and the expansion of attack surfaces through IoT integration. The data highlights growing concerns around industrial cybersecurity as nation-state actors and cybercriminal groups increasingly focus on operational technology environments.
Why This Matters Now
Industrial systems are experiencing unprecedented threat evolution as attackers exploit the convergence of IT and OT environments, making traditional security approaches insufficient for protecting critical infrastructure in an increasingly connected industrial landscape.
Attack Path Analysis
Industrial control systems faced multi-vector malware campaigns exploiting internet-connected biometric systems and ICS networks with minimal cybersecurity controls. Attackers leveraged malicious scripts, phishing pages, and email-based document delivery to compromise systems, then used legitimate remote access tools like AnyDesk for persistence and lateral movement within industrial networks. Command and control was maintained through denylisted internet resources and covert channels, enabling data exfiltration of sensitive operational technology data. The campaign culminated in ransomware deployment targeting critical infrastructure, particularly electric power systems and manufacturing facilities across multiple regions.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited internet-connected industrial systems through malicious scripts and phishing pages (5.42% of ICS computers affected), targeting biometric systems with extensive email use and minimal cybersecurity controls
MITRE ATT&CK® Techniques
Spearphishing Attachment
Spearphishing Link
JavaScript
Malicious File
Proxy
Data Encrypted for Impact
Disable or Modify Tools
Replication Through Removable Media
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Network and Environment Pillar
Control ID: Network Segmentation
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
PCI DSS 4.0 – Software Engineering Techniques
Control ID: 6.2.4
Digital Operational Resilience Act (DORA) – Identification
Control ID: Article 8
ISO 27001:2022 – Web Filtering
Control ID: A.8.23
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Industrial Automation
Multi-vector malware campaigns targeting ICS computers with 19.15% global attack rate, requiring enhanced zero trust segmentation and threat detection capabilities.
Oil/Energy/Solar/Greentech
Energy sector leads in miner threats (0.66%) with elevated ransomware risks, necessitating encrypted traffic protection and egress security enforcement.
Utilities
Critical infrastructure faces persistent malware targeting with regional variations up to 27.9%, demanding comprehensive east-west traffic security and anomaly detection.
Construction
Construction industry experiences high AutoCAD malware rates (6.38% in East Asia) and elevated virus infections, requiring specialized endpoint protection measures.
Sources
- Threat landscape for industrial automation systems. Q2 2026https://securelist.com/industrial-threat-report-q2-2026/121159/Verified
- CISA Industrial Control Systems Securityhttps://www.cisa.gov/topics/industrial-control-systemsVerified
- NIST Cybersecurity Framework for Critical Infrastructurehttps://www.nist.gov/cyberframeworkVerified
- ICS-CERT Advisorieshttps://www.cisa.gov/news-events/ics-advisoriesVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained this multi-vector industrial control systems campaign by limiting lateral movement pathways and reducing attacker reach across interconnected ICS networks. The segmented architecture could have reduced the blast radius of ransomware deployment across critical infrastructure facilities.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud-native security fabric controls would likely have reduced the attack surface of internet-facing industrial systems by enforcing identity-aware access policies and constraining direct internet connectivity to critical ICS components.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely have constrained privilege escalation by limiting access scope between different industrial system components and reducing the ability to exploit elevated permissions across segmented network zones.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely have significantly reduced lateral movement capabilities by constraining inter-system communication pathways and limiting the reachability of legitimate remote access tools across segmented industrial network zones.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls would likely have detected and constrained command and control communications by providing centralized monitoring across distributed industrial infrastructure and limiting connectivity to known malicious internet resources.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security controls would likely have constrained data exfiltration by monitoring and limiting outbound data flows from industrial systems, potentially reducing the volume of operational technology data accessible through unauthorized channels.
While some ransomware deployment may still occur within compromised segments, the overall impact would likely be significantly reduced through contained blast radius, with isolated network zones potentially limiting ransomware spread across critical infrastructure facilities.
Impact at a Glance
Affected Business Functions
- Industrial Control Systems Operations
- Manufacturing Process Control
- Building Automation Systems
- Critical Infrastructure Management
Estimated downtime: 3 days
Estimated loss: $150,000
Industrial control system configurations, operational technology network topology, biometric access control data, engineering documentation, and AutoCAD design files across multiple industry sectors including electric power, manufacturing, and building automation systems
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with microsegmentation policies to isolate industrial control systems from corporate networks and prevent lateral movement between OT and IT environments
- • Deploy Egress Security & Policy Enforcement to block unauthorized outbound communications to denylisted internet resources and detect covert C2 channels used by threat actors
- • Enable East-West Traffic Security monitoring to detect and prevent worm propagation and lateral movement within industrial networks, particularly between building automation and critical infrastructure systems
- • Establish Multicloud Visibility & Control with centralized monitoring of industrial automation systems to detect anomalous interactions and suspicious remote access tool usage like AnyDesk
- • Implement Encrypted Traffic (HPE) protection with MACsec and IPsec to secure data in transit and prevent exfiltration of sensitive operational technology data through email and internet channels



