SonicWall: Targeted Attacks on Manufacturing

Manufacturing Sector Faces Precise, Targeted Attacks, SonicWall Reports

HIGH
July 22, 2026
5m read
Industrial Control SystemsCyberattackVulnerability

Related Entities

Organizations

SonicWall Hikvision

Products & Tech

SCADALog4j2

Other

Zhen

CVE Identifiers

Full Report

Executive Summary

The manufacturing sector is at a 'breaking point' as the convergence of Information Technology (IT) and Operational Technology (OT) creates new, high-value targets for cybercriminals. According to the 2026 SonicWall Manufacturing Protect Brief, attackers are shifting from high-volume, indiscriminate attacks to more precise, surgical strikes. While overall intrusion attempts fell, the manufacturing industry experienced the highest detection rate for SCADA attacks of any tracked sector. Attackers are successfully exploiting the expanded attack surface, with old vulnerabilities like the 2021 Hikvision camera flaw and Log4j2 still proving effective. This trend highlights the critical danger of a stolen IT credential being used to pivot to the production floor, potentially causing operational shutdowns and physical damage.

Threat Overview

Data from SonicWall's global sensor network in H1 2026 revealed a complex threat picture for manufacturing. While total intrusion prevention system (IPS) events declined by 56.2% year-over-year, the absolute volume was still massive at 474 million. This suggests a move away from 'spray and pray' tactics toward more focused attacks.

Key findings include:

  • Targeted OT Attacks: The sector recorded the highest rate of SCADA-specific attacks, indicating a deliberate focus on industrial control systems.
  • Exploitation of Old Vulnerabilities: Attackers are still finding success with older, unpatched flaws. The CVE-2021-36260 command injection flaw in Hikvision IP cameras continued to generate a high volume of attacks. The Log4j2 vulnerability (CVE-2021-44228) was responsible for 13.8 million detection events on manufacturing networks alone.
  • Targeted Ransomware: The Zhen ransomware family was observed generating 22.2 million hits against just two devices within the sector, suggesting a highly targeted, active incident rather than a broad campaign.

Technical Analysis

The core of the issue is the insecure convergence of IT and OT networks. Historically, OT networks were air-gapped and isolated. As they become connected to corporate IT networks for data analysis and remote management, they inherit risks from the IT side. A threat actor can use a common IT entry point, like a phishing email, to gain a foothold and then pivot to the OT network.

This lateral movement is often enabled by flat network architectures and weak access controls between the two domains. The exploitation of the Hikvision camera flaw is a prime example of an IoT device being used as an entry point. These cameras are often placed on the network without proper security considerations, providing a beachhead for attackers. This aligns with MITRE ATT&CK for ICS techniques like T0819 - Exploitation for Initial Access and T0886 - Remote Services to pivot from a compromised device.

Impact Assessment

Cyberattacks in the manufacturing sector have consequences that go beyond data theft. A successful attack on OT systems can lead to:

  • Production Downtime: Halting production lines can result in millions of dollars in lost revenue per day.
  • Physical Damage: Manipulation of industrial controllers can cause machinery to operate outside of safe parameters, leading to physical damage or destruction.
  • Safety Risks: In some environments, such as chemical or energy production, a cyberattack could lead to catastrophic safety failures, endangering workers and the public.
  • Supply Chain Disruption: An attack on a single key manufacturer can have a ripple effect, disrupting an entire global supply chain.

IOCs — Directly from Articles

No specific Indicators of Compromise (IOCs) were mentioned in the source articles.

Cyber Observables — Hunting Hints

The following patterns could help identify threats in a converged IT/OT environment:

Type
network_traffic_pattern
Value
RDP/SMB traffic from an IT workstation to an HMI or PLC
Description
Any direct communication from a standard IT asset to a critical OT asset is highly suspicious.
Context
Network Intrusion Detection Systems (NIDS), NDR solutions with ICS protocol awareness.
Type
url_pattern
Value
/PSIA/Custom/IO/inputs/
Description
A URL path associated with the Hikvision command injection exploit (CVE-2021-36260).
Context
Web server logs on cameras, WAF logs.
Type
command_line_pattern
Value
jndi:ldap://
Description
The classic indicator for Log4j exploitation attempts.
Context
Application logs, WAF logs, network traffic analysis.
Type
process_name
Value
plclogic.exe (example)
Description
Unusual processes running on engineering workstations or HMIs.
Context
EDR on OT-adjacent systems.

Detection & Response

  • ICS-Aware Monitoring: Deploy security monitoring tools that understand OT protocols (e.g., Modbus, DNP3, S7). These tools can detect anomalous commands or values that could indicate an attack (D3-NTA: Network Traffic Analysis).
  • Network Segmentation Monitoring: Monitor the traffic crossing the IT/OT boundary. Any protocol or connection that is not explicitly allowed should trigger an alert.
  • Asset Inventory: Maintain a complete and up-to-date inventory of all IT, IoT, and OT assets on the network, including their patch status.

Mitigation

  • Robust Network Segmentation: The most critical mitigation is to enforce strict segmentation between IT and OT networks using a DMZ (Demilitarized Zone). All traffic between the zones must be inspected and restricted based on the principle of least privilege (M0930 - Network Segmentation).
  • Patching OT Systems: While challenging, a risk-based approach to patching OT systems is necessary. Prioritize patching devices that are exposed to the IT network or have known, exploited vulnerabilities.
  • Access Control: Implement strict access controls for any user or system that needs to interact with the OT environment. Use separate, privileged accounts for OT administration and enforce MFA.
  • Secure Remote Access: Prohibit direct remote access to the OT network from the internet. All remote access should be funneled through a secure, monitored gateway in the IT/OT DMZ.

Timeline of Events

1
July 22, 2026
This article was published

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

ICSOT SecurityManufacturingSonicWallSCADAHikvisionLog4j

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.