Kaspersky Research Finds ICS Energy Sector Under the Highest Cyberthreat Pressure

EIN Kapersky 400

Oct 23, 2019

According to the recent Kaspersky ICS CERT report, a concerning percentage of industrial control system (ICS) computers in the energy sector globally were targeted by cyberattacks in the first six months of 2019. Of the Kaspersky solutions installed on ICS computers, 41.6% experienced and blocked a cyber threat. The three main cyber threats detected in energy ICS environments included worms (7.1%), spyware (3.7%) and cryptocurrency miners (2.9%).

Industrial cyber incidents are among the most dangerous cyberattacks as they typically result in production downtime, tangible financial losses and are difficult to overcome. This is especially true when incidents occur in critical, life-supporting sectors such as energy. Malware infections can also negatively affect the availability and integrity of ICS and other systems that are part of the industrial network.

Among the threats that were detected in H1 2019, a few were particularly unique. This includes Agent Tesla, a specialized Trojan spy malware designed to steal authentication data, screenshots and data captured from web cameras and keyboards. Kaspersky products also identified and blocked cases of the Meterpreter backdoor which was being used to remotely control computers on the industrial networks of energy systems. Attacks that use the backdoor are targeted and often conducted in manual mode. Syswin, a new wiper worm written in Python and packed into the Windows executable format, was also detected. This threat can have a significant impact on ICS computers due to its ability to self-propagate and destroy data.

Kaspersky experts also analyzed the automotive manufacturing (39.3%) and building automation (37.8%) industries, taking the second and the third place respectively to the percentage of ICS computers on which malicious objects were blocked.

Additional report findings include:

  • On average, ICS computers do not operate entirely inside the security perimeter of typical corporate environments, meaning tasks related to protecting the ICS and corporate segment are, to some extent, unrelated.
  • Generally, the level of malicious activity inside the ICS segment is connected with malware activity happening in the country where the ICS environment is located.
  • In countries where the security of ICS is favorable, low levels of compromised ICS computers are attributable to protection measures and tools that are in place rather than a limited level of malicious activity.
  • Self-propagating malicious programs are very active in some countries. In the cases analyzed, these were worms designed to infect removable media (USB flash drives, removable hard drives, mobile phones, etc.). It appears that infections with worms via removable media is the most common infection scenario for ICS computers.

Source

Related Articles


Latest Articles

  • Why Business ERP Software Integrations Matter for Modern Estimating Teams

    Why Business ERP Software Integrations Matter for Modern Estimating Teams

    March 2, 2026 By Melvin Newman, Patabid CEO Construction estimating is a high-stakes game. For large electrical contractors managing multiple projects, millions in material costs, and dozens of estimators, the margin for error is razor-thin. A misquoted job doesn’t just lose money—it can tie up crews, strain supplier relationships, and ripple through your entire operation. Read More…

  • Ontario Building and Construction Tradeswomen Statement on International Women’s Day

    Ontario Building and Construction Tradeswomen Statement on International Women’s Day

    March 2, 2026 This International Women’s Day, the Ontario Building and Construction Tradeswomen (OBCT) proudly celebrates the leadership, resilience, and collective power of women in the trades across Ontario. This year’s theme is Give to Gain, which highlights the strength of reciprocity and collective support. When tradeswomen, organizations, and communities uplift each other through generosity, opportunities for women Read More…

  • Recall: PureVolt Photoelectric Smoke Detector Recalled Due to Potential Failure to Operate

    Recall: PureVolt Photoelectric Smoke Detector Recalled Due to Potential Failure to Operate

    March 2, 2026 This recall involves Purevolt Photoelectric Smoke Detector model SD119-4 for fire alarm systems, compatible with 4 wires, 12V DC. The product measures 100mm x 48mm and is intended for indoor use, with ceiling or wall mounting. The model number can be found on the label affixed to the back of the product. Issue Health Canada’s sampling Read More…

  • Sustainable Urban Development Starts with Streetlighting Transformation in Val-D’or

    Sustainable Urban Development Starts with Streetlighting Transformation in Val-D’or

    March 2, 2026 The City of Val-d’Or, in the heart of Quebec’s Abitibi-Témiscamingue region, undertook a major streetlight revitalization project on 7th Street, a principal north-south artery. By updating public lighting, it would improve energy efficiency, give this iconic area a contemporary look, and preserve its urban identity. Old streetlights on 7th Street had been Read More…


Changing Scene