Vendor Sheet
COSMICENERGY – Not an Immediate Threat
COSMICENERGY is a newly identified OT malware targeting IEC‑104 devices by exploiting MS SQL servers connected to remote terminal units. While initial reports suggested it could disrupt power grids, Dragos’ independent analysis found that it does not currently pose an immediate operational threat. The malware appears linked to Russian emergency response exercises rather than active deployment. Although its capabilities are limited, its discovery highlights how tools developed for training or simulations can surface in the wild and underscores the need for continued vigilance in protecting ICS environments.
