ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Malware

Irongate ICS Malware targeting SCADA Systems

Kyle by Kyle
June 6, 2016
in Malware, Public
Reading Time: 2 mins read
irongate malware
Share on FacebookShare on Twitter

FireEye experts have released their discoveries on the Irongate ICS/SCADA malware, which targets a Siemens PLC simulation (SIM) environment via a man-in-the middle attack on a particular component of custom PLCSIM code. SIM environments are the place engineers test their PLC code, which suggests Irongate shows no actual threat to ICS operations says FireEye, and there’s been no indication of any attacks or efforts to date.

Irongate, which the analysts think is a proof-of-concept piece of malware, apparently remained underneath the radar for quite a while. It goes back to 2012, but wasn’t revealed until late last year after a number of its samples were submitted to VirusTotal: even so, antivirus scanners overlooked it. FireEye reverse-engineered the samples after observing some SCADA mentions in the code.

This malware is nowhere near as advanced as Stuxnet, but similar to Stuxnet, Irongate targets a unique Siemens control system, and it uses its own DLLs to change a specific task. Each malware family performs some detective work of its own to avoid discovery: while Stuxnet looked for antivirus software to circumvent, Irongate evades sandboxes and other virtual environments so it won’t be reversed.

You might also like

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

The analysts mention it’s uncertain whether Irongate is the work of a nation-state, a cybercriminal, or a researcher assessing threats to ICS. “The question for us is if it’s a simulated environment, then what is it? Is someone trying this in a simulated [environment] before taking it to a production environment? Or is it a researcher saying ‘look what I can do … a Stuxnet-type thing,’” says Dan Scali, senior supervisor for FireEye Mandiant ICS Consulting services.

For Fireeye’s full analysis and findings, you can find their writeup here.

Tags: FireEyeIrongateSCADA
Previous Post

Two spammers found guilty, over $2 million made

Next Post

Cryptolocker ransomware infects 10,000 Australians

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026
Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

FBI Warns of HiatusRAT Targeting Network Devices Worldwide

December 18, 2024

Was Deloitte Hacked Again? Ransomware Group Claims They Did

December 9, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.