Threat landscape for industrial automation systems. Q2 2026
In Q2 2026, the percentage of ICS computers on which malicious objects were blocked decreased to 19.15%. The biometrics sector remains the most affected industry due to internet exposure and minimal cybersecurity controls. Denylisted internet resources and ransomware saw increases, while threats from removable media and network folders continued to decline.
Detection / Hunteropenrouter
What Happened
A report on industrial computer security for Q2 2026 shows a decrease in overall attacks, reaching the lowest level since 2022. However, the biometrics sector is heavily targeted, experiencing high rates of phishing, spyware, and ransomware. Africa and East Asia saw notable increases in various threats, including ransomware and viruses. Organizations using industrial control systems should review their security postures, focusing on email security, internet access controls, and sector-specific vulnerabilities.
Key Takeaways
- The percentage of ICS computers with blocked malicious objects decreased to 19.15%, the lowest since 2022.
- The biometrics sector leads in affected ICS computers at 26.44%, driven by internet access, email usage, and minimal cybersecurity controls.
- Denylisted internet resources rose to second place in threat categories, reaching 4.31% globally.
- Ransomware activity on ICS computers increased to 0.16%, with Africa and the electric power industry being heavily impacted.
- Malware for AutoCAD increased to 0.31%, notably affecting the construction industry in East Asia and Southeast Asia.
Affected Systems
- Industrial automation systems (ICS computers)
- Biometric systems
- Building automation systems
- Electric power infrastructure
- Manufacturing systems
- Engineering and ICS integration systems
- Construction industry systems
- Oil and gas industry systems
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: Threat actors target ICS computers via internet resources, email, or removable media.
- Execution: Malicious scripts, phishing pages, or malicious documents are delivered to the target system.
- Persistence and Impact: Spyware, ransomware, or worms execute, maintaining presence and affecting operations.
- Exfiltration and Spread: Data is potentially exfiltrated, and worms spread via network folders or removable media.
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
The article is a statistical report and does not provide specific detection rules or queries.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Low | The report provides statistical data on blocked malicious objects but does not detail specific EDR telemetry or detection logic. |
| Network Visibility | Low | The report mentions internet and email as threat sources but does not provide network-level indicators or detection mechanisms. |
| Detection Difficulty | Moderate | Detecting these threats requires standard endpoint and network security controls, but the report lacks specific IOCs for targeted hunting. |
Required Log Sources
- Endpoint detection logs
- Email gateway logs
- Web proxy logs
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Investigate an increase in malicious script execution or phishing page access on systems in the biometrics sector. | Web proxy logs, endpoint browser history, EDR script execution logs | Initial Access | Medium - legitimate scripts or administrative access to web resources may trigger alerts. |
| Hunt for ransomware activity targeting electric power infrastructure systems. | EDR process execution, file modification logs, backup system logs | Impact | Low - ransomware behavior is typically distinct. |
| Monitor for malicious documents being opened on ICS computers, particularly in Southern Europe and South America. | Email gateway logs, endpoint file creation logs, EDR document reader process logs | Execution | Medium - legitimate documents with macros or embedded content may trigger alerts. |
Control Gaps
- Lack of email security controls in the biometrics sector
- Insufficient internet access restrictions for ICS computers
- Minimal cybersecurity controls within biometric system organizations
Key Behavioral Indicators
- Execution of malicious scripts (JS/HTML) from internet or email sources
- Access to denylisted internet resources from ICS networks
- Presence of ransomware or worm activity on industrial automation systems
- Malware targeting AutoCAD files in construction industry environments
False Positive Assessment
Medium - The report provides statistical trends rather than specific indicators, so applying these findings to specific environments may require tuning to avoid false positives from legitimate industrial software and communications.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Review recent alerts and blocked malicious objects on ICS computers, particularly in the biometrics and electric power sectors.
- Consider implementing or tightening email filtering rules to block malicious documents and scripts targeting ICS environments.
Infrastructure Hardening
- Evaluate whether network segmentation can further isolate ICS computers from general internet access, particularly in sectors like biometrics and building automation.
- Consider restricting access to denylisted internet resources and monitoring for attempts to reach them from OT networks.
User Protection
- Consider deploying enhanced endpoint protection on ICS computers to detect and block spyware, ransomware, and worms.
- If applicable, evaluate whether AutoCAD installations on ICS computers require additional application control measures to prevent malware execution.
Security Awareness
- Consider incorporating targeted phishing awareness training for employees in the biometrics, building automation, and electric power sectors.
- Educate users on the risks of opening email attachments and accessing internet resources from ICS computers.