Industrial malware falls globally but East Asia climbs

Between April and June, Kaspersky's industrial security team blocked malware from 10,904 separate families on industrial control computers. The share of those machines that ran into anything malicious at all fell to 19.15%, the lowest reading since 2022.

That headline number is the least interesting thing in the report.

Underneath it, the regional figures run from 8.1% in Northern Europe to 27.9% in Africa, a gap of 3.4 times, and five regions went up over the quarter rather than down. We covered the Q1 edition of the same series in July, when the global figure first hit a three-year low. The decline is real. It is not being shared out evenly.

The global average hides two rising regions

East Asia moved furthest. The share of ICS computers there with something blocked rose 2.03 percentage points to 21.84%, lifting the region above the global average. Kaspersky ICS CERT ranks it first for growth in malicious scripts and phishing pages, in spyware and in viruses, and first for growth in threats arriving from the internet. Every surveyed industry there rose except building automation and construction, and Mongolia carried the region's highest rate of malicious scripts and phishing pages at 8.19%.

Africa's figure moves around from quarter to quarter, and this was its highest since Q2 2025, up 0.55 points. The biggest jump there was in denylisted internet resources, and the region ranked first for growth in both ransomware and malware written for AutoCAD, the drafting software that holds plant and machine designs.

Why fingerprint readers top the table

Biometrics systems, the badge and fingerprint terminals that control who gets through a door, again led every sector in the report at 26.44%, and were the only one to go up while the rest came down. The report puts that down to how they are deployed: internet access, heavy use of email, and very little security control wrapped around them. In Southern Europe the figure reached 33.28%.

Biometrics also ranked first for malicious scripts, malicious documents, spyware, ransomware and worms. It is the one sector where email is a bigger source of blocked threats than the web is.

Email gains while the web recedes

Across all ICS computers, threats arriving from the internet slipped from 7.88% to 7.61%, while threats arriving through email clients rose from 2.59% to 2.84%. Removable media (0.24%) and network folders (0.02%) stayed marginal. Malicious scripts and phishing pages remain the most common category at 5.42% globally, from 1.67% in Northern Europe to 8.76% in Southern Europe.

Denylisted internet resources, meaning attempted connections to addresses the vendor's products refuse outright, climbed for a second straight quarter to 4.31% and moved from third place to second, displacing spyware. Russia posted the highest regional figure at 5.17%, and within it electric power (6.61%) was worst hit.

Malicious documents rose to 1.77%, worms to 1.43%, and ransomware to 0.16%. Ransomware is still the smallest category here. It is also one of the ones going up, alongside separate findings this month that industrial intrusions aimed at physical damage are becoming more common.

Aim at the mail path and the door readers

The report measures rather than instructs, but its numbers point somewhere specific. Email is the channel that grew while the web shrank, so mail filtering and attachment handling on the office machines sitting next to OT deserve the budget that used to go to web gateways. Access-control and biometric terminals are worth a fresh inventory: they are the most-hit category in the data, often internet-facing, and rarely owned by the team that owns the plant network.

Kaspersky ICS CERT published the full quarterly report, with the regional and per-industry breakdowns, on 25 August. Its telemetry covers computers running the company's own products, so the figures describe that population rather than every industrial network. A falling global average is thin comfort in a quarter when five regions moved the other way.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions