The boundary separating enterprise Information Technology (IT) networks from physical Operational Technology (OT) environments has permanently dissolved. Historically, industrial facilities relied on the “air-gap” myth-the belief that physical isolation would protect Programmable Logic Controllers (PLCs), Human-Machine Interfaces (HMIs), and Supervisory Control and Data Acquisition (SCADA) networks from digital threats. Modern Industrial IoT (IIoT) convergence, remote maintenance telemetry, and legacy edge gateways have systematically erased those boundaries.
According to industry threat intelligence, ransomware incidents impacting industrial entities soared past 3,000 documented cases annually, with manufacturing alone accounting for over 70% of all targeted facilities. When ransomware impacts an industrial site, the consequences extend far beyond encrypted spreadsheets-unplanned downtime on automated assembly lines averages $2.4 million per hour, while physical process disruption introduces severe worker safety and environmental hazards.
Below is an authoritative, paragraph-by-paragraph technical analysis of the top 15 ransomware variants actively threatening OT, ICS, and critical infrastructure environments.
The Top 15 OT Ransomware Variants
1. EKANS
EKANS represents a watershed moment in industrial cyber threats as one of the first ransomware strains engineered with explicit ICS process-kill mechanisms. Written in Go, EKANS executes a hardcoded kill list targeting specific Windows processes essential to industrial operations, including GE Proficy, Honeywell Process Knowledge System (PKS), Siemens SIMATIC WinCC, and Emerson Ovation. By killing these operational services before initiating AES-256 file encryption, EKANS strips plant engineers of real-time telemetry and HMI control, forcing emergency manual process shutdowns to prevent physical equipment damage.
2. LockBit (v3.0 / 5.0)
LockBit remains one of the most persistent Ransomware-as-a-Service (RaaS) operations infiltrating manufacturing and critical infrastructure subnets. Affiliates heavily employ Bring Your Own Vulnerable Driver (BYOVD) tactics to neutralize Endpoint Detection and Response (EDR) agents on dual-homed engineering workstations. Once inside Level 3 OT networks, LockBit utilizes automated PowerShell scripts and Group Policy Objects (GPOs) to rapidly spread across VMware ESXi hypervisors, encrypting virtualized SCADA servers and historian databases simultaneously.
3. Qilin (Agenda)
Qilin has emerged as a dominant force in industrial extortion, topping incident counts across global supply chains and manufacturing plants. Built on a modular Rust and C architecture, Qilin affiliates leverage compromised VPN credentials and zero-day perimeter exploits to breach OT jump hosts. The payload is highly customizable, allowing operators to explicitly map out target IP ranges, stop underlying hypervisor processes running HMI nodes, and exfiltrate proprietary engineering schematics prior to system locking.
4. Industroyer2 / CaddyWiper Variants
While classified primarily as destructive cyber-weapons rather than traditional financial extortion, Industroyer2 variants represent a direct threat to electrical distribution grids and substation automation. Industroyer2 bypasses corporate IT entirely to speak native industrial protocols-including IEC 60870-5-104, IEC 61850, and OPC DA. By issuing raw malicious protocol commands directly to protection relays and circuit breakers, it forces physical power outages while co-deployed CaddyWiper payloads wipe engineering workstations to hinder recovery.
5. Akira
Akira heavily targets mid-market discrete manufacturing, heavy equipment fabrication, and chemical processing plants. Attackers gain initial footholds by exploiting unpatched vulnerabilities in legacy perimeter remote access appliances (such as Cisco and Fortinet VPNs). Upon entry, Akira maps OT-adjacent subnets, targets Veeam disaster recovery backups to destroy recovery pathways, and exfiltrates CAD/CAM blueprints before executing a fast, multi-threaded C++ file-encryption routine.
6. BlackCat (ALPHV)
BlackCat (ALPHV) was among the pioneer cross-platform RaaS strains written in Rust, allowing native execution across Windows, Linux, and ESXi environments. In operational environments, BlackCat operators specifically target OT jump servers and historian servers. By terminating active database services supporting MQTT, OPC-UA, and SQL Historians, BlackCat blindfolds shop-floor dispatchers, halting production execution systems (MES) and triggering costly assembly line freezes.
7. Black Basta
Black Basta focuses its operations on critical manufacturing, chemical processing, and municipal water treatment infrastructure. Deploying initial access via targeted phishing and QakBot loaders, the threat actors rapidly escalate domain privileges to breach Active Directory architectures spanning enterprise and production zones. Once inside Level 2 operator networks, Black Basta locks HMI consoles, preventing human operators from managing Safety Instrumented Systems (SIS) and physical control loops.
8. Cl0p
Cl0p specializes in massive double-extortion supply chain campaigns, systematically exploiting zero-day vulnerabilities in Managed File Transfer (MFT) platforms and web gateways used by industrial contractors and equipment suppliers. Rather than relying strictly on real-time file encryption, Cl0p exfiltrates sensitive operational architecture maps, PLC configuration files, and network topologies, extorting industrial enterprises with the threat of releasing critical infrastructure blueprints to the dark web.
9. C3RBERUS
C3RBERUS derivatives target legacy industrial environments running unpatched or end-of-life operating systems (such as Windows XP, 7, or Server 2008) that remain active due to vendor certification restrictions. Utilizing multi-threaded encryption routines optimized for older hardware, C3RBERUS quickly encrypts legacy HMI nodes and engineering stations that lack modern endpoint protection capabilities, causing immediate loss of process visibility.
10. DragonForce
DragonForce actively targets energy utilities, industrial logistics, and heavy manufacturing subsectors. The group utilizes advanced command-and-control (C2) evasion techniques, routing lateral movement traffic through legitimate administrative web protocols and web-relays to pass perimeter security undetected. Once established in the network, DragonForce systematically locks production scheduling databases and dispatch servers.
11. Inc Ransom
Inc Ransom employs a RaaS model focused on manufacturing firms, transport infrastructure, and supply chain logistics. Inc affiliates rely heavily on “Living off the Land” (LotL) tactics-abusing administrative utilities like PsExec, WMI, and NetScan-to move laterally across OT subnets undetected. Prior to payload execution, the malware systematically deletes Volume Shadow Copies and local network backups to prevent bare-metal restoration.
12. SafePay
SafePay targets food and agriculture processing facilities, logistics hubs, and consumer packaged goods plants. The operators exploit internet-exposed Remote Desktop Protocol (RDP) connections and unpatched web interfaces on edge IIoT gateways. By encrypting central access control systems and automated dispatch nodes, SafePay forces facilities into manual overrides, creating massive supply chain bottlenecks.
13. Play Ransomware
Play ransomware is recognized for targeting transport networks, municipal utilities, and industrial logistics across North America and Europe. The strain utilizes a specialized RSA/AES hybrid encryption binary configured to hunt specifically for database formats (.mdf, .ldf), SCADA configurations, and project files, while deliberately avoiding standard operating system directories to keep the host booted for ransom negotiations.
14. Royal / BlackSuit
Royal (and its successor BlackSuit) frequently impacts industrial electronics and semiconductor manufacturing facilities. The payload employs an intermittent encryption algorithm-encrypting only every N bytes of a target file. This math-based approach bypasses basic statistical anomaly detection systems and drastically accelerates the time required to lock multi-terabyte historian databases and Manufacturing Execution Systems (MES).
15. Babuk (Industrial Strains)
Re-compiled variants derived from leaked Babuk source code explicitly target non-x86 hardware architectures. These payloads are compiled for ARM and MIPS architectures used in embedded industrial routers, IIoT field gateways, and Linux-based Programmable Logic Controllers (PLCs). By corrupting embedded flash storage and firmware binaries, Babuk variants brick physical hardware devices, requiring physical board replacement or low-level serial reflashing.
Defensive Strategies for OT Security Leaders
Mitigating the threat of industrial ransomware requires strict adherence to international safety and cybersecurity standards, such as IEC 62443 and NIST SP 800-82:
- Enforce Strict Purdue Model Micro-Segmentation: Establish strict firewalls and demilitarized zones (DMZs) between Enterprise IT (Levels 4/5) and Operational zones (Levels 0–3). Enforce multi-factor authentication (MFA) and granular Access Control Lists (ACLs) on all jump hosts.
- Deploy Passive Traffic & Protocol Monitoring: Utilize non-intrusive network taps to analyze native industrial protocols (Modbus, DNP3, EtherNet/IP) for unauthorized PLC re-programming, unapproved firmware modifications, or abnormal baseline behavior.
- Maintain Offline, Immutable Backups: Secure offline, air-gapped backups of all PLC ladder logic, HMI runtime files, SCADA configurations, and historian databases. Test full bare-metal recovery routines regularly, assuming enterprise Active Directory is completely compromised.
- Control Transient Assets & USBs: Enforce strict media scanning and host isolation policies for contractor laptops and maintenance USB drives before allowing physical connection to Level 1 and 2 control networks.
Conclusion
The evolution of industrial ransomware from generic IT file encrypters to process-aware cyber threats marks a fundamental shift in operational risk. Modern attackers no longer need to compromise physical PLCs directly; by targeting hypervisors, dual-homed engineering stations, and historian databases, they achieve the same result-stopping production lines and forcing costly operational downtime. Protecting critical infrastructure demands moving away from the outdated belief in physical air gaps and adopting defensible, zero-trust architectures grounded in standards like IEC 62443. By combining strict network micro-segmentation, passive protocol monitoring, and OT-specific incident playbooks, industrial operators can build the resilience required to keep production running safely amidst an increasingly aggressive threat landscape.