Kaspersky: Mass spyware campaign targets thousands of ICS computers around the world
From January 20 to November 10, 2021, Kaspersky experts uncovered a new piece of malware that has targeted more than 35,000 computers across 195 countries. the Dubbed “PseudoManuscrypt” for its similarities with the advanced persistent threat (APT) group Lazarus’ Manuscrypt malware, this new malware contains advanced spying capabilities and has been seen targeting both government organizations and industrial control systems (ICS) across numerous industries, the company said in a statement.
Industrial organizations are some of the most coveted targets for cybercriminals – both for financial gain and intelligence gathering. In fact, 2021 saw significant interest in industrial organizations from well-known APT groups like Lazarus and APT41. While investigating another string of attacks, Kaspersky experts uncovered a new piece of malware with some similarities to Lazarus’ “Manuscrypt”, custom malware used in the group’s ThreatNeedle campaign against the defense industry. Hence, they dubbed it PseudoManuscrypt.
From January 20 to November 10, 2021, Kaspersky products blocked PseudoManuscrypt on more than 35,000 computers in 195 countries. Many of the targets were industrial and government organizations, including military-industrial enterprises and research laboratories. 7.2% of attacked computers were part of industrial control systems (ICS), with engineering and building automation representing the most affected industries.