The Tardigrade Incident: What Happens When Assessments Go Wrong
The Tardigrade malware report dropped in late 2021, with Wired calling it a shockingly sophisticated strain targeting COVID vaccine supply chains. Jimmy Wylie had analyzed the same hash months earlier and identified it as Cobalt Strike Beacon delivering Conti ransomware. Vitali Kremez reached the same conclusion. The misidentification triggered customer panic, required a damage-control internal report, and left analysts answering managers about a threat that wasn’t there. That experience drove Dragos to build an evidence-driven process for ICS threat assessment.
Three Properties That Define ICS Malware
Dragos requires three properties before classifying something as ICS malware: ICS capability, malicious intent, and adverse effects. ICS capability means the code performs OT actions, speaking protocols like Modbus TCP or uploading ladder logic to PLCs. Malicious intent requires evidence the software was designed to cause harm, not just function as a red team tool. Adverse effects means demonstrable harm: stolen process data, unauthorized PLC access, or arbitrary code execution on the device. Missing any one property changes the verdict.
Hunting ICS Threats in VirusTotal
TRISIS, Frosty Goop, and Cosmic Energy were all found on VirusTotal. Defenders upload samples during investigations; threat actors upload them to test detection rates. Dragos hunts this pool using string-based queries. ICS protocol names, vendor names, and PLC model numbers are starting points. PIPEDREAM and Frosty Goop showed that actors reuse open-source libraries, so hunting for library-specific strings narrows results to ICS-capable code. Python and .NET binaries get priority because decompiling them takes minutes, not days, making static analysis far more practical.
IoT Exploit: When Dual-Use Evidence Stalls an Assessment
A half-gigabyte Cython zip held an IoT exploitation toolkit with 1,000-plus exploits targeting cameras, routers, and industrial devices. The ICS category alone had 175 tools for disclosed vulnerabilities in Siemens SIMATIC and Rockwell products, with partial support for 19 protocols. ICS capability and adverse effects were clear. Malicious intent wasn’t. CVE advisory data and dual-use features pointed both ways, and the linked organization did both offensive and defensive research. No zero-days, no deployment evidence. Dragos called it an ICS red team tool.
Three Cases, One Pattern: Follow the Evidence
Kurtlar SCADA was a compiled Python VNC client sold on Telegram with 3,500 followers, used to brute-force HMI logins and capture screenshots. The operators compromised dozens of HMIs. The tool lacked ICS capability, but the campaign was real. Dragos contacted CISA. A fake Rapid SCADA update exploiting CVE-2023-38831 stole SCADA-related files until its C2 shared an SSL certificate with a CTF training site. A .NET Modbus cluster made Modbus TCP connections but issued no control commands. Both stayed unclassified.
Notable Quotes
shockingly sophisticated strain Jimmy Wylie · ▶ 1:21
binary analysis was inconclusive. Jimmy Wylie · ▶ 11:01
new information, assessments can change. Sam Hanson · ▶ 11:52
defenses don’t have to be complicated. Sam Hanson · ▶ 15:10
you know, people actually listen to us. Jimmy Wylie · ▶ 23:42
Key Takeaways
- All three of Dragos’s criteria must be met before classifying a sample as ICS malware.
- Simple VirusTotal string queries found tools actively targeting and compromising industrial HMIs.
- A VNC client with a hardcoded credential list compromised dozens of HMIs in the real world.
- Overhyping a misidentified threat wastes defenders’ time and erodes community trust when real threats arrive.
- Missing any single criterion forces a “not ICS malware” verdict regardless of how dangerous the sample looks.
About the Speakers
Jimmy Wylie is a malware analyst at Dragos, Inc., who searches for and analyzes threats to critical infrastructure. He was the lead analyst on PIPEDREAM, the first ICS attack “utility belt,” and TRISIS, the first malware to target a safety instrumented system. Formerly a DoD contractor and malware analysis instructor, he has over 14 years of experience with reverse engineering and malware analysis.
Sam Hanson is an Associate Principal Vulnerability Analyst at Dragos, where he researches vulnerabilities and malware affecting OT/ICS systems. He discovers zero-day vulnerabilities in industrial software and threat hunts for ICS-related malware in public data sources. He has analyzed notable ICS-related malware including components of PIPEDREAM and Fuxnet, and has presented at DISC ‘22 and ‘23, DISC:EU ‘24, and BSides:Zurich.