HomeSecurityHackers target ICS computers with malicious scripts

Hackers target ICS computers with malicious scripts

Industrial automation systems ( ICS) have become the latest battleground for sophisticated cybercriminals, who use cleverly designed malicious scripts and phishing pages to compromise ICS computers .

ICS computers

In the first half of 2025, attackers shifted significantly towards web-based attack vectors, exploiting legacy interfaces, weak authentication, and outdated software in OT environments. These threat actors deliver malicious JavaScript payloads via compromised websites and phishing emails that mimic legitimate vendor pages or internal control panels.

Once a user interacts with the page, the script is automatically executed, allowing the adversary to deliver next-stage payloads designed to extract credentials, install backdoors, and move laterally within the network.

Data from Securelist shows that the percentage of ICS computers that had malicious scripts and phishing pages reached 6.49% in Q2 2025 (down slightly from the previous quarter). Despite the small decrease, these remain the most prevalent web-based threats to industrial networks, surpassing traditional malware families such as trojans and keyloggers.

See also: Steam game stole donations from cancer-stricken streamer

The analysis shows that Africa and Southeast Asia were the focus of cyberattacks, while Northern Europe was the least targeted. The decline in blocked scripts may reflect both improved defenses and a shift by attackers toward more targeted, low-volume campaigns.

Securelist analysts have identified that many of these attacks exploit common industrial protocols —such as Modbus and OPC UA—to embed command sequences within seemingly innocent script hosts. By disguising control commands as part of a legitimate maintenance interface, threat actors can manipulate programmable logic controllers (PLCs) and supervisory control and data acquisition (SCADA) systems without triggering conventional antivirus signatures.

Hackers target ICS computers with malicious scripts

Attackers often bundle multiple JavaScript modules: the initial loader script pulls in a second-stage downloader, which in turn retrieves a lightweight reverse shell written in Node.js. While most cases involve credential harvesting and identification, several campaigns have also allowed direct manipulation of industrial processes.

In one case, adversaries changed setpoints on a chemical processing line, causing temperature fluctuations that triggered emergency shutdowns. In another case, attackers used phishing pages that mimicked a well-known remote support portal to steal privileged accounts, later deploying malicious scripts that disabled safety switches.

See also: New Botnet Exploits DNS Misconfiguration

These businesses highlight the urgent need for deep-inspection proxies and multi-factor authentication on all ICS-facing web interfaces.

ICS computers: Infection mechanism and distribution Scripts

The initial infection usually starts with a phishing email containing a link to a cloned vendor portal. When the page is visited, a JavaScript snippet is automatically downloaded and executed from an external server. The loader script then writes a Node[.]js-based shell in Node.js to disk and registers it as a system service, ensuring persistence across reboots. It also injects WebSocket hooks into the browser process to pipe PLC commands over the existing network channel. Detection avoidance is further achieved by hiding function names and encoding payloads in Base64, decoding them only at runtime.

Great risk for industrial environments

The threat shift to web interfaces in industrial environments is not just a technical problem — it’s a fundamental shift in how we should perceive risk in physical production. The core issue is not just “who got in,” but “how cyberspace is now becoming a gateway to physical impacts”: unwanted interference with production lines, broken compliance protocols, even personnel safety issues.

See also: Hackers bypass Windows MoTW files with LNK Stomping

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Hackers target ICS computers with malicious scripts

This requires a transformation of defense strategy: traditional endpoint solutions are not enough. IT–OT coordination is needed at the policy and technology levels, with a focus on privilege minimization, network micro-segmentation, and cutting off external interfaces that have no proven utility. Security must be “pre-installed” in vendor relationships — code audits, third-party transparency, and compliance commitments.

At the operational control level, automated routines for detecting unusual behavior can break chains of infection. At the same time, investments in employee training, tabletop scenarios, and clear recovery playbooks are critical.

In short, the answer is not just technical: it is operational and organizational. Organizations that understand this first will reduce the risk of downtime and the potential humanitarian and financial consequences of a successful cyberattack.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS