Security researchers reported that malware targeting operational technology is broader than rare, bespoke ICS implants alone. Mandiant detailed COSMICENERGY, an OT-focused malware framework with similarities to INDUSTROYER, TRITON, and INCONTROLLER, built around insecure industrial protocols such as IEC-104 and packaged with common Python tooling. Separate Mandiant reporting on INCONTROLLER described modular tools including TAGRUN for OPC UA reconnaissance, CODECALL for Modbus and Schneider Electric PLC interaction, and OMSHELL for gaining shell access to Omron PLC environments, enabling actions ranging from tag manipulation and credential attacks to file transfer, traffic capture, and program-memory wiping.
At the same time, Forescout found that generic malware families are increasingly reaching into OT environments through exposed devices and weak credentials rather than highly tailored tradecraft. In a VirusTotal hunt, researchers identified botnet-linked samples tied to Aisuru, Kaiten, and Gafgyt that attempted logins against PLCs and other OT products using default credentials, with some samples trying to wipe directories such as /mnt/modbus_rtu; affected technologies included devices from Modicon, Siemens, Emerson, Avocent, and Sierra Wireless. Dragos also documented trojanized "password recovery" tools for industrial assets, including one for Automation Direct DirectLogic 06 PLCs that exploited CVE-2022-2003 to retrieve passwords while infecting engineering workstations with Sality, underscoring that OT operators face both purpose-built ICS malware and commodity malware abusing industrial access paths.

See affected versions and whether adversaries are exploiting it.
13 events from the most recent confirmed update back to the earliest known activity.
Forescout found 17 botnet samples using default credentials for Emerson, Schneider Electric, Siemens, Avocent, and Sierra Wireless devices, all submitted to VirusTotal from the United States on August 21, 2024.
Forescout reported that Aisuru-related samples were re-submitted to VirusTotal from India on July 18, 2024.
Forescout used a YARA rule with 136 OT-related signatures to run a VirusTotal RetroHunt across files submitted from June 11 to September 11, 2024, matching 989 files.
The firmware vulnerability used by the malicious DirectLogic 06 password-recovery tool was assigned CVE-2022-2003 after Dragos recreated the exploit and disclosed it to Automation Direct.
Mandiant reported that COSMICENERGY may also have supported exercises in 2022 for the St. Petersburg International Economic Forum.
Mandiant assessed that COSMICENERGY may have been used to support exercises hosted by Rostelecom-Solar in collaboration with the Russian Ministry of Energy.
Forescout said every Aisuru sample since June 10, 2020 contained wiping capability indicated by the string "/mnt/modbus_rtu".
Forescout reported that Aisuru-related samples tied to the string "hoho4christmastrees" were first submitted to VirusTotal between May and August 2020, primarily from Japan.
Forescout reported that its analysis found only three FrostyGoop/BUSTLEBERM samples but uncovered multiple botnet clusters, including Aisuru, Kaiten, and Gafgyt-related activity abusing default OT credentials and in some cases wiping directories such as "/mnt/modbus_rtu".
Mandiant disclosed COSMICENERGY as a newly identified OT-focused malware family, assessing that its origin and purpose were inconclusive but that it had capabilities comparable to INDUSTROYER and similarities to other OT malware.
Mandiant published technical details on INCONTROLLER tooling, describing TAGRUN, CODECALL, and OMSHELL as tools for reconnaissance, PLC interaction, credential attacks, disruption, and shell access across multiple industrial control systems.
After Dragos disclosed the DirectLogic 06 vulnerability, Automation Direct released firmware updates to fix CVE-2022-2003.
Dragos reported a campaign in which social media accounts advertised password-recovery or "cracking" tools for industrial assets, and the analyzed DirectLogic 06 tool actually exploited a PLC vulnerability while dropping Sality malware on the engineering workstation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 100 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
forescout.com
Open sourcecloud.google.com
Open sourcecloud.google.com
Open sourcedragos.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.