{"id":59818,"date":"2025-09-26T10:54:24","date_gmt":"2025-09-26T10:54:24","guid":{"rendered":"https:\/\/becolve.com\/blog\/enisa-threat-landscape-report-2018-some-notes-on-scada-ics-systems-and-critical-infrastructures\/"},"modified":"2025-09-26T10:54:24","modified_gmt":"2025-09-26T10:54:24","slug":"enisa-threat-landscape-report-2018-some-notes-on-scada-ics-systems-and-critical-infrastructures","status":"publish","type":"blog","link":"https:\/\/becolve.com\/en\/blog\/enisa-threat-landscape-report-2018-some-notes-on-scada-ics-systems-and-critical-infrastructures\/","title":{"rendered":"ENISA Threat Landscape Report 2018. Some notes on SCADA\/ICS systems and critical infrastructures."},"content":{"rendered":"<p>Yesterday, Monday, January 28, 2018, <a href=\"https:\/\/www.enisa.europa.eu\"><strong>ENISA<\/strong><\/a> published its annual threat report: the <em>ENISA Threat Landscape Report 2018 &#8211; 15 Top Cyberthreats and Trends<\/em>, which you can download at this <a href=\"https:\/\/www.enisa.europa.eu\/publications\/enisa-threat-landscape-report-2018\">link<\/a>.<\/p>\n<p>As usual, the report incorporates essential information and data for anyone who wants to stay abreast of current and future threats that affect, I would say, any type of organization.<\/p>\n<p>In the following figure, you can see the main threats that have emerged during 2018 and their position with respect to those detected during 2017.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-28420 size-full aligncenter\" src=\"https:\/\/becolve.com\/wp-content\/uploads\/2023\/04\/ciberseguridad-logitek-4.jpg\" alt=\"\" width=\"710\" height=\"660\"><\/p>\n<p>Additionally, in this entry, we would like to point out some of the most important data collected in the report related to <strong>SCADA\/ICS<\/strong> systems and critical infrastructures.<\/p>\n<p><strong>Malware in SCADA\/ICS environments<\/strong><\/p>\n<p>In point 3.1 of the report, it is highlighted how during the past year the malware <a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2017\/12\/attackers-deploy-new-ics-attack-framework-triton.html\">Triton, <\/a>was the first to affect the SIS (Safety Instrumented Systems), that is, the systems that allow executing &#8220;specific control functions&#8221;, when the process has entered conditions that can seriously affect the safety of workers or cause serious environmental incidents.<\/p>\n<p>In addition, the report indicates that, in the coming years, operating environments and critical infrastructures in general will be a priority target for APT groups.<\/p>\n<p>Similarly, within this malware section, the existence of a specific type of malware, Cryptojacking, appears for the first time as a threat. That is, it is a malware that infects OT systems and devices, allowing the malicious user to mine cryptocurrency. In OT environments, this type of malware can generate a significant degradation in system performance.  <\/p>\n<p>The report mentions the incident suffered by critical infrastructure in the water sector in February 2018, using said malware. As can be seen in the following figure from the report, attacks on critical infrastructures through &#8220;Cryptomining malware&#8221; are increasing sharply in recent months. <\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-28422 size-full aligncenter\" src=\"https:\/\/becolve.com\/wp-content\/uploads\/2023\/04\/ciberseguridad-logitek-5.jpg\" alt=\"\" width=\"880\" height=\"464\"><\/p>\n<p><strong>Attack vectors in SCADA\/ICS environments<\/strong><\/p>\n<p>In section 5 of the report, \u201cAttack Vectors\u201d, mention is made of the so-called \u201cMulti-staged and Modular Threats\u201d, that is, those attacks that are carried out by groups that use very sophisticated, versatile and persistent malware. Some of the examples indicated are VPNFilter, BlackEnergy or CobInt, and these are their characteristics: self-propagation, self-destruction, hidden communications with the C2, persistent behaviors, obfuscation at the origin, etc. <\/p>\n<p>The report provides a brief overview of the characteristics of the first VPNFilter, a malware that affected more than 500,000 network electronics devices. The following figure shows the stages followed by this malware to perpetrate its malicious actions. <\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-28424 size-full\" src=\"https:\/\/becolve.com\/wp-content\/uploads\/2023\/04\/ciberseguridad-logitek-6.jpg\" alt=\"\" width=\"924\" height=\"178\"><\/p>\n<p>Among the specific actions of this malware, it is worth noting that two &#8220;pluging modules&#8221; were found:<\/p>\n<ul>\n<li>One consisting of a \u201csniffer\u201d that collected traffic and data (passwords) from infected networks, as well as traffic associated with the Modbus protocol.<\/li>\n<li>Another consisting of facilitating communication through TOR.<\/li>\n<\/ul>\n<p><strong>Cyber espionage in critical infrastructures<\/strong><\/p>\n<p>Throughout the report, emphasis is placed on alerting how organizations belonging to critical sectors are and will be a preferred target for malicious actions. It should be noted that the importance of monitoring the so-called \u201cSupply Change attacks\u201d is highlighted, as they are a growing threat. <\/p>\n<p>On the other hand, the following data is significant. The use of RATs to exfiltrate sensitive information from OT networks and environments has increased sharply during 2018. A graph is shown revealing the countries in which this medium has been most used. Spain also appears.   <\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-28426 size-full aligncenter\" src=\"https:\/\/becolve.com\/wp-content\/uploads\/2023\/04\/ciberseguridad-logitek-7.jpg\" alt=\"\" width=\"735\" height=\"681\"><\/p>\n<p><strong>Some conclusions<\/strong><\/p>\n<ul>\n<li>Attackers change their techniques, tactics and procedures daily, improving and refining them.<\/li>\n<li>Risk management, a common practice in organizations, must include risk management linked to cybersecurity and information systems.<\/li>\n<li>End users are increasingly exposed to a huge number of threats.<\/li>\n<li>It is highly recommended to increase training and awareness actions at different levels.<\/li>\n<li>The differences between the regulatory and legal frameworks are a barrier to collecting information on threats.<\/li>\n<\/ul>\n<p>From the <a href=\"https:\/\/www.ciberseguridadlogitek.com\/\">industrial cybersecurity unit of Logitek<\/a> we have and want to be up to date with current and future threats, with the aim of fulfilling our mission: <strong><em>to help our clients improve the security levels of their processes, systems and infrastructures associated with OT environments and critical infrastructures<\/em><\/strong>.<\/p>\n<p><a href=\"https:\/\/www.ciberseguridadlogitek.com\/contacto\/\">Call us if you want to talk to us.<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This new EMISA report incorporates essential information and data for anyone who wants to stay abreast of current and future threats affecting any type of organization.<\/p>\n","protected":false},"author":31,"featured_media":59823,"menu_order":0,"template":"","categories":[1371],"tags":[],"arquitectura":[1839],"area":[],"sector":[],"experto":[1396],"weborigen":[157],"productos-tax":[],"soluciones-tax":[],"marcas-tax":[],"coauthors":[],"class_list":["post-59818","blog","type-blog","status-publish","has-post-thumbnail","hentry","category-cybersecurity","arquitectura-industrial-cybersecurity","experto-industrial-cybersecurity-total-availability","weborigen-ciberseguridadlogitek-com"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>ENISA Report: Notes on SCADA\/ICS systems and critical infrastructures.<\/title>\n<meta name=\"description\" content=\"The new EMISA report incorporates essential information and data for anyone who wants to stay abreast of current and future threats affecting any type of organization.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/becolve.com\/en\/blog\/enisa-threat-landscape-report-2018-some-notes-on-scada-ics-systems-and-critical-infrastructures\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ENISA Report: Notes on SCADA\/ICS systems and critical infrastructures.\" \/>\n<meta property=\"og:description\" content=\"The new EMISA report incorporates essential information and data for anyone who wants to stay abreast of current and future threats affecting any type of organization.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/becolve.com\/en\/blog\/enisa-threat-landscape-report-2018-some-notes-on-scada-ics-systems-and-critical-infrastructures\/\" \/>\n<meta property=\"og:site_name\" content=\"Becolve Digital\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.ciberseguridadlogitek.com\/wp-content\/uploads\/ciberseguridad-logitek-9.jpg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@Logitek_es\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"3 minutes\" \/>\n\t<meta name=\"twitter:label2\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data2\" content=\"Becolve Digital\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/becolve.com\\\/en\\\/blog\\\/enisa-threat-landscape-report-2018-some-notes-on-scada-ics-systems-and-critical-infrastructures\\\/\",\"url\":\"https:\\\/\\\/becolve.com\\\/en\\\/blog\\\/enisa-threat-landscape-report-2018-some-notes-on-scada-ics-systems-and-critical-infrastructures\\\/\",\"name\":\"ENISA Report: Notes on SCADA\\\/ICS systems and critical infrastructures.\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/becolve.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/becolve.com\\\/en\\\/blog\\\/enisa-threat-landscape-report-2018-some-notes-on-scada-ics-systems-and-critical-infrastructures\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/becolve.com\\\/en\\\/blog\\\/enisa-threat-landscape-report-2018-some-notes-on-scada-ics-systems-and-critical-infrastructures\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/becolve.com\\\/wp-content\\\/uploads\\\/2023\\\/04\\\/ciberseguridad-logitek-8.jpg\",\"datePublished\":\"2025-09-26T10:54:24+00:00\",\"description\":\"The new EMISA report incorporates essential information and data for anyone who wants to stay abreast of current and future threats affecting any type of organization.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/becolve.com\\\/en\\\/blog\\\/enisa-threat-landscape-report-2018-some-notes-on-scada-ics-systems-and-critical-infrastructures\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/becolve.com\\\/en\\\/blog\\\/enisa-threat-landscape-report-2018-some-notes-on-scada-ics-systems-and-critical-infrastructures\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/becolve.com\\\/en\\\/blog\\\/enisa-threat-landscape-report-2018-some-notes-on-scada-ics-systems-and-critical-infrastructures\\\/#primaryimage\",\"url\":\"https:\\\/\\\/becolve.com\\\/wp-content\\\/uploads\\\/2023\\\/04\\\/ciberseguridad-logitek-8.jpg\",\"contentUrl\":\"https:\\\/\\\/becolve.com\\\/wp-content\\\/uploads\\\/2023\\\/04\\\/ciberseguridad-logitek-8.jpg\",\"width\":800,\"height\":300},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/becolve.com\\\/en\\\/blog\\\/enisa-threat-landscape-report-2018-some-notes-on-scada-ics-systems-and-critical-infrastructures\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/becolve.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Blog Items\",\"item\":\"https:\\\/\\\/becolve.com\\\/en\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"ENISA Threat Landscape Report 2018. Some notes on SCADA\\\/ICS systems and critical infrastructures.\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/becolve.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/becolve.com\\\/en\\\/\",\"name\":\"Becolve Digital\",\"description\":\"Transformaci\u00f3n digital en industria e infraestructuras\",\"publisher\":{\"@id\":\"https:\\\/\\\/becolve.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/becolve.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/becolve.com\\\/en\\\/#organization\",\"name\":\"Becolve Digital\",\"url\":\"https:\\\/\\\/becolve.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/becolve.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/becolve.com\\\/wp-content\\\/uploads\\\/2023\\\/04\\\/becolve-logo-h-black_200.png\",\"contentUrl\":\"https:\\\/\\\/becolve.com\\\/wp-content\\\/uploads\\\/2023\\\/04\\\/becolve-logo-h-black_200.png\",\"width\":200,\"height\":64,\"caption\":\"Becolve Digital\"},\"image\":{\"@id\":\"https:\\\/\\\/becolve.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/Logitek_es\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/becolve-digital\\\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"ENISA Report: Notes on SCADA\/ICS systems and critical infrastructures.","description":"The new EMISA report incorporates essential information and data for anyone who wants to stay abreast of current and future threats affecting any type of organization.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/becolve.com\/en\/blog\/enisa-threat-landscape-report-2018-some-notes-on-scada-ics-systems-and-critical-infrastructures\/","og_locale":"en_US","og_type":"article","og_title":"ENISA Report: Notes on SCADA\/ICS systems and critical infrastructures.","og_description":"The new EMISA report incorporates essential information and data for anyone who wants to stay abreast of current and future threats affecting any type of organization.","og_url":"https:\/\/becolve.com\/en\/blog\/enisa-threat-landscape-report-2018-some-notes-on-scada-ics-systems-and-critical-infrastructures\/","og_site_name":"Becolve Digital","og_image":[{"url":"https:\/\/www.ciberseguridadlogitek.com\/wp-content\/uploads\/ciberseguridad-logitek-9.jpg","type":"","width":"","height":""}],"twitter_card":"summary_large_image","twitter_site":"@Logitek_es","twitter_misc":{"Est. reading time":"3 minutes","Written by":"Becolve Digital"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/becolve.com\/en\/blog\/enisa-threat-landscape-report-2018-some-notes-on-scada-ics-systems-and-critical-infrastructures\/","url":"https:\/\/becolve.com\/en\/blog\/enisa-threat-landscape-report-2018-some-notes-on-scada-ics-systems-and-critical-infrastructures\/","name":"ENISA Report: Notes on SCADA\/ICS systems and critical infrastructures.","isPartOf":{"@id":"https:\/\/becolve.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/becolve.com\/en\/blog\/enisa-threat-landscape-report-2018-some-notes-on-scada-ics-systems-and-critical-infrastructures\/#primaryimage"},"image":{"@id":"https:\/\/becolve.com\/en\/blog\/enisa-threat-landscape-report-2018-some-notes-on-scada-ics-systems-and-critical-infrastructures\/#primaryimage"},"thumbnailUrl":"https:\/\/becolve.com\/wp-content\/uploads\/2023\/04\/ciberseguridad-logitek-8.jpg","datePublished":"2025-09-26T10:54:24+00:00","description":"The new EMISA report incorporates essential information and data for anyone who wants to stay abreast of current and future threats affecting any type of organization.","breadcrumb":{"@id":"https:\/\/becolve.com\/en\/blog\/enisa-threat-landscape-report-2018-some-notes-on-scada-ics-systems-and-critical-infrastructures\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/becolve.com\/en\/blog\/enisa-threat-landscape-report-2018-some-notes-on-scada-ics-systems-and-critical-infrastructures\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/becolve.com\/en\/blog\/enisa-threat-landscape-report-2018-some-notes-on-scada-ics-systems-and-critical-infrastructures\/#primaryimage","url":"https:\/\/becolve.com\/wp-content\/uploads\/2023\/04\/ciberseguridad-logitek-8.jpg","contentUrl":"https:\/\/becolve.com\/wp-content\/uploads\/2023\/04\/ciberseguridad-logitek-8.jpg","width":800,"height":300},{"@type":"BreadcrumbList","@id":"https:\/\/becolve.com\/en\/blog\/enisa-threat-landscape-report-2018-some-notes-on-scada-ics-systems-and-critical-infrastructures\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/becolve.com\/en\/"},{"@type":"ListItem","position":2,"name":"Blog Items","item":"https:\/\/becolve.com\/en\/blog\/"},{"@type":"ListItem","position":3,"name":"ENISA Threat Landscape Report 2018. Some notes on SCADA\/ICS systems and critical infrastructures."}]},{"@type":"WebSite","@id":"https:\/\/becolve.com\/en\/#website","url":"https:\/\/becolve.com\/en\/","name":"Becolve Digital","description":"Transformaci\u00f3n digital en industria e infraestructuras","publisher":{"@id":"https:\/\/becolve.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/becolve.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/becolve.com\/en\/#organization","name":"Becolve Digital","url":"https:\/\/becolve.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/becolve.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/becolve.com\/wp-content\/uploads\/2023\/04\/becolve-logo-h-black_200.png","contentUrl":"https:\/\/becolve.com\/wp-content\/uploads\/2023\/04\/becolve-logo-h-black_200.png","width":200,"height":64,"caption":"Becolve Digital"},"image":{"@id":"https:\/\/becolve.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/Logitek_es","https:\/\/www.linkedin.com\/company\/becolve-digital\/"]}]}},"_links":{"self":[{"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/blog\/59818","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/blog"}],"about":[{"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/types\/blog"}],"author":[{"embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/users\/31"}],"version-history":[{"count":0,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/blog\/59818\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/media\/59823"}],"wp:attachment":[{"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/media?parent=59818"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/categories?post=59818"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/tags?post=59818"},{"taxonomy":"arquitectura","embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/arquitectura?post=59818"},{"taxonomy":"area","embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/area?post=59818"},{"taxonomy":"sector","embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/sector?post=59818"},{"taxonomy":"experto","embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/experto?post=59818"},{"taxonomy":"weborigen","embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/weborigen?post=59818"},{"taxonomy":"productos-tax","embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/productos-tax?post=59818"},{"taxonomy":"soluciones-tax","embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/soluciones-tax?post=59818"},{"taxonomy":"marcas-tax","embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/marcas-tax?post=59818"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/becolve.com\/en\/wp-json\/wp\/v2\/coauthors?post=59818"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}