Who Is Really Attacking Your ICS Devices?
Industrial Control System (ICS)/SCADA systems have been the talk of the security community for the last three or more years due to Stuxnet, Duqu, and other similar noteworthy attacks. While the importance and lack of security around ICS systems are well documented and widely known, I’ve been researching Internet-facing ICS/SCADA systems, who’s really attacking them, and why. Recently, I spoke at BlackHat Europe about the same research and wrote a research paper to share my findings.
Without knowing if Internet-facing SCADA systems were attacked, I developed a honeypot architecture that would emulate several types of SCADA and ICS devices mimicking those commonly found on these systems. The honeypots included traditional vulnerabilities found across the same or similar systems, showcasing a very realistic honeypot environment.
The findings include real-world attacks from several countries with varying attack attempts.

Figure 1. Percentage of attacks per country
In addition to the statistics gathered about the source of attacking country, my research includes some specific vulnerabilities that threat actors attempted to exploit. Included in some of the attacks I found were an attempt to spearphish a site administrator and a bid to exploit fundamental ICS protocols.
Our expectation is that attack trends will continue to increase in the ICS arena, with possible far reaching consequences. With continued diligence and utilizing secure computing techniques, your ability to deflect and defend these attacks will help secure your organization. For more information about these findings, you may read my report “Who’s Really Attacking Your ICS Equipment?” and find out details of some of these attacks and who are some primary offenders.
Like it? Add this infographic to your site:
1. Click on the box below. 2. Press Ctrl+A to select all. 3. Press Ctrl+C to copy. 4. Paste the code into your page (Ctrl+V).
Image will appear the same size as you see above.
Artículos Recientes
- The Industrialization of Botnets: Automation and Scale as a New Threat Infrastructure
- From Holiday Snap to Custom Scam in 30 Minutes: How AI Turns Public Photos Into Targeted Attacks
- From LinkedIn to Tailored Attack in 30 Minutes: How AI Accelerates Target Profiling for Cybercrime
- Threat Attribution Framework: How TrendAI™ Applies Structure Over Speculation
- AI Skills as an Emerging Attack Surface in Critical Sectors: Enhanced Capabilities, New Risks
The Industrialization of Botnets: Automation and Scale as a New Threat Infrastructure
AI Security Starts Here: The Essentials for Every Organization
Stay Ahead of AI Threats: Secure LLM Applications With Trend Vision One