Kaspersky Research Finds ICS Energy Sector Under the Highest Cyberthreat Pressure

EIN Kapersky 400

Oct 23, 2019

According to the recent Kaspersky ICS CERT report, a concerning percentage of industrial control system (ICS) computers in the energy sector globally were targeted by cyberattacks in the first six months of 2019. Of the Kaspersky solutions installed on ICS computers, 41.6% experienced and blocked a cyber threat. The three main cyber threats detected in energy ICS environments included worms (7.1%), spyware (3.7%) and cryptocurrency miners (2.9%).

Industrial cyber incidents are among the most dangerous cyberattacks as they typically result in production downtime, tangible financial losses and are difficult to overcome. This is especially true when incidents occur in critical, life-supporting sectors such as energy. Malware infections can also negatively affect the availability and integrity of ICS and other systems that are part of the industrial network.

Among the threats that were detected in H1 2019, a few were particularly unique. This includes Agent Tesla, a specialized Trojan spy malware designed to steal authentication data, screenshots and data captured from web cameras and keyboards. Kaspersky products also identified and blocked cases of the Meterpreter backdoor which was being used to remotely control computers on the industrial networks of energy systems. Attacks that use the backdoor are targeted and often conducted in manual mode. Syswin, a new wiper worm written in Python and packed into the Windows executable format, was also detected. This threat can have a significant impact on ICS computers due to its ability to self-propagate and destroy data.

Kaspersky experts also analyzed the automotive manufacturing (39.3%) and building automation (37.8%) industries, taking the second and the third place respectively to the percentage of ICS computers on which malicious objects were blocked.

Additional report findings include:

  • On average, ICS computers do not operate entirely inside the security perimeter of typical corporate environments, meaning tasks related to protecting the ICS and corporate segment are, to some extent, unrelated.
  • Generally, the level of malicious activity inside the ICS segment is connected with malware activity happening in the country where the ICS environment is located.
  • In countries where the security of ICS is favorable, low levels of compromised ICS computers are attributable to protection measures and tools that are in place rather than a limited level of malicious activity.
  • Self-propagating malicious programs are very active in some countries. In the cases analyzed, these were worms designed to infect removable media (USB flash drives, removable hard drives, mobile phones, etc.). It appears that infections with worms via removable media is the most common infection scenario for ICS computers.

Source

Related Articles


Latest Articles

  • NSAA Apprenticeship Management System (AMS) is Now Available

    NSAA Apprenticeship Management System (AMS) is Now Available

    June 19, 2026 NSAA has now launched the Apprenticeship Management System (AMS) to provide a faster, easier, and more transparent way for apprentices and employers to manage apprenticeship activity. For Apprentices, Apprenticeship Management System will allow you to:  For Employers, with Apprenticeship Management System, you will be able to:  For Tradespersons Your launch of Apprenticeship… Read More…

  • IP Ratings in Lighting: What They Actually Mean in the Field

    IP Ratings in Lighting: What They Actually Mean in the Field

    By CSC LED IP ratings are among the most frequently referenced specifications in lighting, yet they are often misunderstood or oversimplified. While they may appear to be just another number on a specification sheet, IP ratings play an important role in determining where a fixture can be installed and how it will perform over time.… Read More…

  • The Role of Offshore Sourcing: An Editorial Perspective for Manufacturers, Distributors, Agents, Contractors, and Industry Stakeholders

    The Role of Offshore Sourcing: An Editorial Perspective for Manufacturers, Distributors, Agents, Contractors, and Industry Stakeholders

    The real divide is not domestic versus offshore. It is between committed, accountable partners and transactional, price‑only players. The CSA mark sits inside that story as one important signal but it is only a subset of what the market should be looking at. Read More…

  • Alberta OHS Code Review

    Alberta OHS Code Review

    June 15, 2026 Albertans are invited to provide feedback for Alberta’s ongoing review of Alberta’s OHS Code. Complete the surveys by July 8. Albertans are invited to participate in our ongoing review of the Occupational Health and Safety Code (OHS Code). This is an opportunity to improve health and safety outcomes for workers and streamline… Read More…


Changing Scene

  • AEMC® Instruments welcomes Mark Stathenas as Authorized Factory Representative for Eastern Canada

    AEMC® Instruments welcomes Mark Stathenas as Authorized Factory Representative for Eastern Canada

    June 19, 2026 AEMC® Instruments, part of the Chauvin Arnoux Group® welcomes Mark Stathenas as Authorized Factory Representative for Eastern Canada.  Mark will serve as your primary point of contact for product information, technical support, and order coordination in the Eastern Canada region. With over two decades of experience in technical sales, distribution and business development, Mark brings a… Read More…

  • BCCA Response to Investment Announcement

    BCCA Response to Investment Announcement

    June 19, 2026 Statement from BCCA: The British Columbia Construction Association (BCCA) welcomes today’s joint announcement by the federal and provincial governments to invest in housing, infrastructure, healthcare, and public transit across British Columbia, including funding to reduce Development Cost Charges (DCCs). These investments will help support the infrastructure needed to enable new housing and… Read More…

  • ECAO Recognition of Safety Achievement Award Recipients

    ECAO Recognition of Safety Achievement Award Recipients

    June 15, 2026 ECAO is proud to recognize the recipients of their Recognition of Safety Achievement Award. This award honours member companies that demonstrate exceptional commitment to workplace safety through outstanding safety performance and a strong culture of prevention. The Recognition of Safety Achievement Award celebrates organizations that maintain injury and illness statistics below the… Read More…

  • ECS Announces the Promotion of Jeff Bartlette to Branch Manager, Winnipeg

    ECS Announces the Promotion of Jeff Bartlette to Branch Manager, Winnipeg

    June 15, 2026 ECS is pleased to announce the promotion of Jeff Bartlette to Branch Manager, Winnipeg. Jeff joined ECS with a mandate to establish the company’s presence in Manitoba. Having successfully balanced both sales and leadership responsibilities, he will now focus fully on developing his team, strengthening branch capabilities, and positioning Winnipeg for continued… Read More…