WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts IBM Observed 2000% Increase in OT Attacks, Says Echobot is the Most Interesting
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

IBM Observed 2000% Increase in OT Attacks, Says Echobot is the Most Interesting

Author: Jennifer Walker

Created: Thursday, February 13, 2020 - 18:28

Categories: Cybersecurity, General Security and Resilience

While there were not a lot of changes and expectations in ICS cybersecurity overall for 2019 and 2020, IBM observed, what it cites as, “explosive growth in OT infrastructure targeting” in 2019. IBM Security’s 2020 X-Force Threat Intelligence Index reports a 2000 percent increase in the number of events targeting OT assets since 2018, including a fact that the number of events targeting OT assets in 2019 was greater than the activity volume observed in the past three years. The report further states that most attacks centered around the low-hanging fruit, such as using a combination of known vulnerabilities within SCADA and ICS hardware components, as well as password-spraying attacks using brute force login tactics against ICS targets. Of course there was activity observed from XENOTIME and APT33, but most interesting was Echobot, a variant of the Mirai IoT botnet, that includes exploits for ICS products. ICS-specific exploits used by Echobot target vulnerabilities in Mitsubishi Electric ME-RTU devices and Schneider Electric’s U.Motion Builder. Read the summary at SecurityWeek

Related Resources

(TLP:CLEAR) Vulnerability Notification – Critical Vulnerability in Fortinet EMS Actively Exploited, CVE-2026-35616

May 29, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) GAO Report: Actions Needed to Address Persistent Cybersecurity Threats to the Water and Wastewater Sector

May 28, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

(TLP:CLEAR) FBI Releases Multiple Alerts on Credential Theft and Evolving Ransomware Intrusion Techniques

May 28, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar