WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts OT/ICS Threat Awareness – COSMICENERGY: New OT-Focused Malware Discovered by Mandiant
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

OT/ICS Threat Awareness – COSMICENERGY: New OT-Focused Malware Discovered by Mandiant

Author: Jennifer Walker

Created: Thursday, May 25, 2023 - 18:22

Categories: OT-ICS Security

Mandiant published intelligence on what is essentially the 8th known ICS-focused malware discovered. Tracked as COSMICENERGY, Mandiant assesses the malware’s capabilities and overall attack strategy appear reminiscent of the 2016 INDUSTROYER incident. Specifically, the malware is designed to cause electric power disruption by interacting with IEC 60870-5-104 (IEC-104) devices, such as remote terminal units (RTUs), that are commonly leveraged in electric transmission and distribution operations in Europe, the Middle East, and Asia.

COSMICENERGY is believed to have been developed for red team activity for conducting electric power disruption and emergency response exercises. However, given the lack of conclusive evidence, Mandiant reserves the possibility that a different actor may have reused code associated with the cyber range sample to develop this malware to facilitate real world attacks.

While not believed to be an active threat to U.S. critical infrastructure at this time, this activity does represent the latest example of specialized OT malware capable of causing cyber physical impacts and principally takes advantage of insecure by design features of OT environments. As such, “OT defenders and asset owners should take mitigating actions against COSMICENERGY to preempt in the wild deployment and to better understand common features and capabilities that are frequently deployed in OT malware.” Visit Mandiant for more.

Related Resources

(TLP:CLEAR) CISA and Partners Urge Hardening Automatic Tank Gauge Systems

Jun 4, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

(TLP:CLEAR) Privilege Escalation Vulnerabilities Affect Phoenix Contact PLCnext Controllers

Jun 4, 2026 in Cybersecurity, OT-ICS Security, Security Preparedness

(TLP:CLEAR) CISA ICS Advisories, Additional Alerts, Updates, and Bulletins – June 4, 2026

Jun 4, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar