Industrial giant Honeywell on Wednesday released its 2025 Cybersecurity Threat Report, which shows that ransomware and Ramnit malware have increased significantly in the industrial sector.
See also: Fake DocuSign pages distribute NetSupport RAT malware

report a significant increase in ransomware attacks on industrial organizations. While these attacks did not necessarily impact operational technology (OT) systems, more than half of the 55 cybersecurity incidents reported to the SEC in 2024 had an impact on OT.
However, the most interesting findings in Honeywell's latest report are based on data collected by the company's own industrial cybersecurity products, which monitor networks for attacks, scan USB devices for malware like Ramnit, and provide threat and risk intelligence.
The company's SMX USB scanning solution examined over 31 million files during Q4 2024 and Q1 2025, blocking nearly 5,000 files and detecting more than 1,800 unique threats , including 124 that had not previously appeared.
See also: Malware analysis reveals sophisticated RAT
The most frequently detected malware, accounting for 42% of detections, were Win32.Worm.Ramnit, Trojan.scar/shyape, Trojan.lokibot/stealer, and Win32.Worm.Sohanad.

The one that stands out the most is Ramnit, a Windows malware that has been around for many years and has several variants. There are Ramnit worms and viruses that spread via USB flash drives, as well as trojans that give attackers control of the victim's computer, allowing them to steal sensitive information such as banking data and credentials.
Honeywell recorded an impressive 3,000% in Ramnit malware infections during the fourth quarter of 2024, compared to the second quarter of the same year.
Paul Smith, Honeywell's director of OT Cybersecurity and author of the report, told SecurityWeek that the estimate of a shift toward industrial control systems (ICS) credentials is based on the fact that the company did not detect any Ramnit infections in the first quarter of 2024, but this malware soon became the threat with the highest number of detections.
See also: APT41 – ToughProgress malware: Abuse of Google Calendar for C2 purposes
The expert emphasized that many ICS products run on Windows devices, and it would not be surprising if such malware, which leverages living-off-the-land (LOL) to perform malicious actions, was the weapon of choice for attackers seeking system control credentials, given that the targeted systems likely already host the required LOL tools.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
