Chemical — Cyber Threat Activity
Chemical holds no recorded incidents in our log and the thinnest actor graph in this dataset, with a single group carrying a researched association and 13 malware families linked through it. The page is therefore a sparse view and not an assessment of the sector's risk, which is substantial and documented elsewhere. Chemical manufacturers are classified under manufacturing in most of our incident records, and Dragos measured chemicals as a small share of industrial ransomware incidents in early 2025, well behind construction, food and beverage and consumer goods, while tracking several distinct activity groups that specifically target chemical operations using phishing, password spraying and watering-hole techniques. Pro-Russia hacktivist activity against internet-exposed industrial interfaces has reached chemical manufacturing alongside energy, water and food production. The reason the sector matters more than its incident count suggests is consequence. Chemical processes hold energy and reactivity that other manufacturing does not, and safety instrumented systems exist precisely because a process pushed outside its envelope can injure people and communities rather than merely halt production. Malware built specifically to interfere with safety controllers at a petrochemical facility has already been documented publicly, which established that an attacker willing to accept physical harm is not hypothetical in this sector. Formulations, process parameters and regulatory submissions are also durable espionage targets. Read the near-empty graph here as a limit of our sector classification rather than a finding, and treat the association shown as published research rather than an incident we have attributed.
- Recorded incidents: 27
- Incidents, trailing 180 days: 7
- Tracked threat actors: 18
- Malware families: 25
Threat actors targeting Chemical
- Qilin 4 incidents
- Akira 3 incidents
- INC Ransom 3 incidents
- SafePay 2 incidents
- Sarcoma 2 incidents
- 8Base 1 incident
- Blackwater 1 incident
- Cl0p 1 incident
- DragonForce 1 incident
- Hunters International 1 incident
- Lamashtu 1 incident
- Lynx Ransomware 1 incident
- Medusa Ransomware 1 incident
- Meow 1 incident
- NightSpire 1 incident
- The Gentlemen 1 incident
- APT37 researched targeting
- Head Mare researched targeting
Malware used against Chemical
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Cobalt Strike Malware
- Mimikatz Tool
- PsExec Tool
- Sliver Tool
- Babuk Malware
- ngrok Tool
- ProcDump Tool
- Rclone Tool
- ADRecon Tool
- BLUELIGHT Malware
- CORALDECK Malware
- DOGCALL Malware
Where these victims are
- United States 4
- Spain 3
- France 2
- Japan 2
- United Kingdom 2
- Egypt 1
- Germany 1
- Hong Kong 1
- India 1
- Indonesia 1
- Oman 1
- Peru 1
Recent incidents
- Sinarmas Cepsa Pte. Ltd. 2026-08-24
- Geb Sas 2026-08-21
- Alto Ingredients, Inc. 2026-08-07
- DISCOLABINDU 2026-06-11
- iql-nog.com 2026-06-02
- olipes.com 2026-05-19
- Luna Group 2026-05-04
- Siwax Specialties Group 2026-03-06
- Golden GBC 2026-02-27
- GreenBest 2025-12-02
- Wiraswasta Gemilang 2025-11-12
- José Guma S.A. 2025-11-05
- WEST Inc. 2025-09-25
- Rad-Solutions, LLC 2025-09-08
- ffs.com 2025-08-13
- Woodtect 2025-06-27
- Megachem Limited 2025-05-06
- King Industries Inc. 2025-04-15
- Tohpe Corporation 2025-03-12
- PRESPERSE.COM 2025-02-27
Coverage. 95.5% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.