Skip to main content

What is OT malware?

How malware works on Operational Technology (OT) and how to stop it.

Image showing illustration of people in room with computer screens

iconmaker via Getty Images

OT malware is malicious software, specifically designed to target Operational Technology.

The purpose of OT malware can range from modifying how an industrial process operates, through to disruptive or destructive attacks - what we call a cyber-physical attack.

This difference in the nature of potential outcomes is one of the differences I want to draw out between IT and OT Malware, in this blog post. I'll also consider similarities between the two, and some effective means of combatting both varieties of malware.

What about ICS Malware?

Industrial Control Systems (ICS) and Operational Technologies (OT) are closely related. So, ICS malware is also known as OT malware. In this blog post, to cut down on the jargon, I'll be using 'OT Malware'.

The MO of OT malware

The way OT malware works depends on the complexity and context of the control system it's attacking.

For systems that can be controlled remotely - like a Supervisory Control and Data Acquisition (SCADA) system - this might mean gaining control of a management workstation, which can then be used to make changes on the target system, and/or hide valid alerts.

Alternatively, malware can target individual components directly to cause malfunction. For example, changing the state of control system hardware, such as Programmable Logic Controllers (PLCs).

While some malware targets OT systems directly, other malware targets surrounding IT systems to attack a hybrid ICS/OT system. This type of malware can be used successfully by state and non-state actors alike, but can be sufficiently damaging none-the-less.






Written by

Ben H ICS Technical Lead