site-logo
site-logo
site-logo

Deep investigation: Cyber compromise and data exfiltration at Air Traffic and Navigation Services (ATNS)

Deep investigation: Cyber compromise and data exfiltration at Air Traffic and Navigation Services (ATNS)

Deep investigation: Cyber compromise and data exfiltration at Air Traffic and Navigation Services (ATNS)

ATNS cyberattack
author

Prayukth K V

 

Recently the South African government-owned entity that provides air traffic control (ATC) and weather operations reported a ransomware-linked malware that had infected the operational technology (OT) network. This is as per documents made available by the company Air Traffic and Navigation Services (ATNS).

As per ATNS, the cyberattack was prevented from escalating and the operator is gearing up for a detailed investigation of the incident.

The available documentation accessed by Shieldworkz research team points to two significant security events within ATNS infrastructure: a malware incident involving an OT environment supporting aviation-weather services at FAPE, and a separate insider data-access/exfiltration matter at FAMM. Publicly available evidence does not yet establish whether the two events were operationally connected.

Core analytical verdict

Our central analytical Question is this. Was this simply a ransomware incident that happened to reach an aviation OT environment or does it reveal a more consequential weakness in the architecture, dependencies, and operational resilience of modern air traffic infrastructure?

The incident at Air Traffic and Navigation Services (ATNS) is certainly not a routine enterprise IT ransomware infection that spilled over into OT. Primary forensic evidence specifically ATNS Tender/RFQ ATNS/RFQ14/07/2026/27/IT-DIGITAL FORENSIC issued in September 2026 reveals a bifurcated critical infrastructure incident:

  1. A targeted OT network compromise at Chief Dawid Stuurman International Airport (FAPE / Port Elizabeth) involving ransomware-associated tooling deployed within an Operational Technology environment supporting weather-related Air Traffic Services (ATS), accompanied by verified telemetry of data exfiltration to external IP addresses located in China.

  2. A parallel insider-driven data theft campaign at Mafikeng International Airport (FAMM) involving unauthorized access, extraction, and exfiltration of personal and operational datasets by internal personnel.

This incident exposes a strategic vulnerability in global aviation: the unmonitored dependency of Air Traffic Control (ATC) on peripheral operational support networks—specifically Aviation Meteorological (Met) and Aeronautical Information Management (AIM) systems. Attackers do not need to penetrate safety-critical radar processing cores to degrade air navigation capacity; compromising peripheral meteorological OT feeds creates data integrity doubts that force air traffic managers into manual fallback, reduced airspace acceptance rates, and operational degradation.

Evidentiary reconstruction and classification

To establish an evidence-based foundation, every analytical finding is classified according to standard intelligence confidence protocols:

  • CONFIRMED: Directly substantiated by official ATNS documentation, procurement filings, or government disclosures.

  • REPORTED: Documented by credible journalism or established threat intelligence providers.

  • CLAIMED: Asserted by external threat actors or unverified third parties.

  • ASSESSED: Deducted through rigorous technical and operational reasoning based on available telemetry.

  • UNKNOWN: Telemetry or public evidence is insufficient to verify.

Summary of evidence

Analytical Item

Classification

Source / Telemetry Base

Operational Context

Malware Intrusion at FAPE

CONFIRMED

ATNS RFQ ATNS/RFQ14/07/2026/27/IT-DIGITAL FORENSIC

Ransomware-linked malware/toolkit detected in OT environment supporting weather-related services to ATS at Chief Dawid Stuurman Int'l Airport (FAPE).

Data Exfiltration to China-based IPs

CONFIRMED

ATNS RFQ Scope Document / Dark Reading

Log records showed outbound data exfiltration from FAPE systems to external IP addresses registered in China.

Insider Data Theft at FAMM

CONFIRMED

ATNS RFQ ATNS/RFQ14/07/2026/27/IT-DIGITAL FORENSIC

Unlawful access, copying, and exfiltration of personal and operational data at Mafikeng Airport (FAMM) involving internal employees.

Containment Action by ATNS

CONFIRMED

ATNS Official RFQ Statements

Internal technical teams isolated systems and removed malware prior to issuing the September 2026 forensic RFQ.

En-Route Radar Processing Compromise

UNLIKELY

ATNS Scope & Operational Telemetry

No evidence indicates that primary En-Route radar processing cores (Flight Data Processing System / Radar Data Processing System) were compromised.

Active Ransomware File Encryption

UNCONFIRMED

Forensic Scope & Technical Telemetry

Malware toolkit was present; public evidence does not confirm active .encrypted file payloads or operational ransom notes were triggered in the OT zone.

Grounding / Flight Cancellation Direct Impact

ASSESSED

Operational ATS Analysis

Operational disruption was contained to degraded meteorological data workflows rather than total ground stops.

Confirmed incident timeline

Initial Intrusion and Operational Compromise (Estimated)

Q2–Q3 2026

Unidentified threat actor establishes initial access to peripheral networks supporting ATNS operational facilities. Data exfiltration channels initiated from FAPE operational infrastructure to external IP addresses located in China.

Malware Detection and Containment at FAPE

Late August 2026

Automated monitoring systems at Chief Dawid Stuurman International Airport (FAPE) detect suspicious activity and ransomware-associated binaries within the OT network supporting aviation weather data feeds for Air Traffic Services. ATNS internal IT/OT technical teams initiate emergency containment and malware remediation.

Parallel Discovery of Insider Data Theft at FAMM

Late August 2026

Internal audit and log monitoring at Mafikeng International Airport (FAMM) flag unauthorized access to personal and operational data repositories. Evidence indicates deliberate data exfiltration by internal employees.

Public Procurement and RFQ Issue

01 September 2026

ATNS issues official tender document ATNS/RFQ14/07/2026/27/IT-DIGITAL FORENSIC seeking an independent digital forensics firm to perform malware reverse engineering, log analysis, chain-of-custody evidence collection, and impact assessment.

RFQ Bidding Close and Escalation

08 September 2026

Formal tender closing date for forensic investigation proposals. Technical scope mandates determining infection vectors, data exfiltration scope, and POPIA/regulatory compliance impacts.

Public Intelligence Exposure

30 September 2026

Dark Reading discloses details of the ATNS procurement documents, confirming external exfiltration to Chinese IP addresses and highlighting vulnerabilities in aviation OT weather support systems.

2. Technical Attack Reconstruction

Reconstructing the kill chain based strictly on disclosed technical scope and standard OT attack patterns:

Observed

Malware identified → OT weather-support environment involved → investigation/containment → potential/identified outbound communications → forensic investigation

Hypotheses

Initial access → privilege escalation → lateral movement → persistence → data staging → exfiltration mechanism

Stage-by-stage reconstruction analysis

Initial Access

  • Confirmed Evidence: Public evidence is insufficient to determine the exact initial access vector.

  • Plausible Hypotheses:

    1. Compromise of remote access / VPN infrastructure utilized by third-party maintenance contractors servicing airport meteorological sensor gateways.

    2. Phishing against ATNS engineering/maintenance personnel leading to credential theft.

  • Evidence Supporting: ATNS relies heavily on vendor support for regional airport navigational aids and weather sensors.

  • Evidence Against: No public disclosure of specific vendor compromised.

  • Required for Confirmation: Ingress firewall logs, VPN authentication records, and endpoint artifacts from entry-point jump hosts.

Execution and persistence

  • Confirmed Evidence: Presence of "ransomware-linked malware/toolkit" on operational systems at FAPE.

  • Plausible Hypotheses: Execution via living-off-the-land binaries (built-in Windows tools or dual-use admin tools like PowerShell or PsExec) to stage ransomware binaries and establish scheduled tasks or service persistence.

  • Public evidence is insufficient to determine the specific malware family or MD5/SHA256 hashes.

Privilege escalation and discovery

  • Confirmed Evidence: Public evidence is insufficient to determine specific escalation mechanisms.

  • Plausible Hypotheses: Exploitation of unpatched Windows vulnerabilities on legacy engineering workstations or credential harvesting via LSASS dumping on weakly segmented IT/OT boundary hosts.

Lateral movement and OT access

  • Confirmed evidence: The intrusion crossed from initial entry points into an OT network supporting weather services for ATS. Malware was identified within an OT environment supporting weather-related ATS functions.

  • Plausible hypotheses: Traversal across dual-homed workstations bridging the enterprise network and the Meteorological Information System (MIS) network, or via shared Active Directory trust relationships.

Operational impact and exfiltration

  • Confirmed Evidence: Verified network logs indicating data exfiltration to external IP addresses located in China.

  • Plausible Hypotheses: Use of encrypted HTTP/S or custom C2 protocols to stream system configuration, weather database records, or operational network diagrams out of the FAPE environment prior to malware discovery.

Containment and recovery

  • Confirmed Evidence: ATNS technical teams executed containment and malware removal. Independent digital forensics engaged via RFQ to validate complete eradication, inspect memory artifacts, and conduct root-cause analysis.

Aviation OT Architecture Investigation

To understand the blast radius, the compromised system must be placed within a strict functional model of aviation technology. The diagram below illustrates the operational boundaries between ATNS Air Traffic Management OT, Airport Infrastructure OT, and Enterprise IT.


Key architectural distinctions

  1. ATNS ATM/ATS OT vs. Airport OT: ATNS operates air navigation, radar, and weather data systems. Airports Company South Africa (ACSA) operates physical airport infrastructure (lighting, baggage, building systems). A compromise in ATNS weather OT does not grant access to ACSA physical building controllers.

  2. Core Radar Processing vs. Weather Support OT: The En-Route radar processing system resides in a highly restricted, deterministic zone. The weather support environment at regional sites (FAPE) gathers data from Automated Weather Observing Systems (AWOS) and feeds METAR/TAF data to controllers and pilots. This peripheral network requires external connectivity for meteorological updates, creating an expanded attack surface.

Dimensions of the incident

Impact assessment across multiple operational dimensions:

[Cyber Intrusion] ──> [Loss of OT Integrity] ──> [Operational Fallback] ──> [Safety Management Action]

  (FAPE Malware /       (Corrupted/Untrusted       (Manual Weather Inputs /     (Increased Controller

   FAMM Exfiltration)   Weather Systems)            Reduced Capacity)            Workload / Spacing)

1. Operational Impact

  • Availability and Reliability: Operational availability of primary radar was maintained, but automatic weather data feeds were isolated, forcing air traffic controllers to rely on manual weather observations or voice-relayed meteorological updates.

  • Capacity and Workload: Manual weather relay increases controller workload per aircraft, reducing the hourly flight processing capacity (Acceptance Rate) at FAPE during instrument meteorological conditions (IMC).

2. Safety Impact

  • Situational Awareness: Loss of real-time automated weather updates (e.g., wind shear alerts, cloud base measurements) degrades situational awareness during precision approaches.

  • Separation Management: Controllers increase buffer distances between aircraft to compensate for manual workload, preventing safety incidents at the cost of flight efficiency.

3. Cyber and Physical Boundaries

  • Confidentiality: Breach confirmed via insider exfiltration at FAMM and external exfiltration to Chinese IP addresses at FAPE.

  • Integrity: Untrusted state introduced across weather OT endpoints, requiring complete forensic validation before restoring automated data pipelines.

  • Physical Boundary: The incident reached the OT layer and caused operational degradation, but safety controls prevented physical safety consequences or aircraft incidents.

Investigation of the Iran hypothesis and attribution assessment

A critical aspect of intelligence analysis is evaluating potential state-sponsored attribution without forcing conclusions.

Attribution Evaluation Matrix

Analytical Dimension

Observed ATNS Incident

Documented Iranian Threat Activity (e.g., CyberAv3ngers, Agrius, MuddyWater)

Primary Target Class

Regional Air Navigation / Weather OT

Energy, Water, Transport, Israel/US/Gulf Infrastructure

Technical Objective

Dual Malware Tooling + Silent Data Exfiltration

Rapid Operational Disruption, Pseudo-Ransomware, Wiper Deployment

Tactical Execution

Covert, Long-term Exfiltration, Low Noise

Loud Defacements, Immediate Lockouts, Telegram Disclosures

Observed Infrastructure

Exfiltration endpoints located in China

Infrastructure hosted in Russia, Middle East, VPS networks

 


Analytical Attribution Assessment

  • Evidence Supporting Iranian Involvement: None. There is no technical telemetry, YARA hit, or C2 overlap linking the ATNS intrusion to Iranian threat groups.

  • Evidence Contradicting Iranian Involvement: Iranian OT campaigns typically emphasize rapid disruption, overt extortion, or destructive wipers accompanied by public claims. The ATNS incident exhibits covert data exfiltration to Chinese network infrastructure and a localized insider data theft campaign.

    Alternative Explanations:

  • Chinese-Nexus Espionage Group: Supported by verified exfiltration logs to China-based IPs, aiming to gather intelligence on African transportation infrastructure, flight movements, or VIP transport logs.

  • Financial Ransomware / Access Broker Group: Opportunistic deployment of commercial ransomware toolkits, utilizing proxy infrastructure in Asia for exfiltration.

  • Disgruntled Insider / Commercial Data Theft: At FAMM, employee-driven data exfiltration operating independently or in collusion with external actors.

Iran Attribution: Not Established

·       “The available evidence does not currently provide a technical basis for attributing the ATNS incident to an Iranian state or state-aligned actor. The reported targeting of critical infrastructure and OT environments is consistent with activity previously documented from multiple state-linked and criminal actors, including Iranian-linked groups, but those characteristics are not unique to Iran.”

·       “The location of observed or suspected exfiltration infrastructure is also insufficient to establish or exclude attribution. Infrastructure geography should be treated as a technical indicator requiring correlation with malware, tooling, victimology, operational timing, authentication artifacts, infrastructure reuse and other forensic evidence.”

·       “At present, Iranian involvement should therefore remain an attribution hypothesis rather than an intelligence conclusion.”

 

Comparison with recent critical infrastructure attacks

Dimension

ATNS Incident (2026)

Eurocontrol Attack (2023)

DP World Cyber Attack (2023)

Colonial Pipeline (2021)

Threat Actor

Undisclosed / Insider + External

Hacktivist (Killnet)

Financial / Ransomware

Financial (DarkSide)

Primary Objective

Espionage & Data Exfiltration

Service Disruption (DDoS)

Extortion & Disruption

Extortion

Initial Access Vector

Vendor / Remote / Insider

Public Web Layer

Unpatched Gateway

Stolen VPN Credentials

IT → OT Traversal

Yes (Reached Weather OT)

No (Web/IT only)

Partial (IT system halt)

No (Proactive OT Shutdown)

OT Systems Affected

Weather Support for ATS

None

Logistics DB / Terminals

Pipeline Operational IT

Operational Consequence

Degraded Weather Feeds

Website Down / Manual Ops

Port Operations Halted

Pipeline Suspended 5 Days

Safety Consequence

Zero (Workload Absorbed)

Zero

Zero

Zero

Data Exfiltration

Confirmed (China IPs & Insider)

No

Confirmed

Confirmed

Unique and under-discussed analytical observations

Standard reporting focused heavily on the word "ransomware." Deep technical analysis reveals ten critical insights overlooked by mainstream coverage:

  1. Weather Infrastructure is an Asymmetric Attack Vector: Modern Air Traffic Management relies on automated, digitized meteorological feeds (AWOS, METAR, TAF) for automated flight profile calculations. Compromising the integrity of weather data forces controllers into manual verification, instantly cutting airspace capacity without needing to touch radar systems.

  2. Pre-Impact Reconnaissance vs. Immediate Extortion: The presence of ransomware toolkits alongside silent exfiltration indicates the attacker was in a "pre-impact" phase—mapping operational topology and exfiltrating data before executing destructive encryption.

  3. The Danger of Peripheral OT Misclassification: Organizations often classify weather data receivers as "Low-Criticality IT" because they do not control physical aircraft. However, because they directly feed ATS decision-making, their failure degrades safety-critical operations.

  4. Insider Convergence with Cyber Intrusion: The simultaneous occurrence of insider data theft at FAMM and external OT malware at FAPE highlights how physical/internal security gaps compound cyber vulnerabilities during critical incidents.

  5. Configuration Integrity Blind Spots: Once malware touches an OT environment, the primary challenge is not merely removing the binary, but proving the absolute integrity of controller configuration files, sensor calibrations, and system baselines.

  6. Legacy Sensor Protocols Lack Authentication: Serial-to-Ethernet converters and legacy meteorological sensor gateways lack cryptographic authentication, enabling man-in-the-middle data manipulation once the local OT segment is breached.

  7. The Hidden Cost of Vendor Remote Management: Regional airports rely on third-party vendors for navigational aid and weather sensor maintenance. These persistent vendor remote-access tunnels are rarely subjected to zero-trust inspection.

  8. Asymmetric Disruption via Data Integrity Doubt: Attackers do not need to alter weather values; simply creating doubt regarding data validity forces air traffic safety managers to suspend automated operations.

  9. Manual Fallback Exercises Scalability Gap: While air traffic controllers train for manual operations, manual processing cannot sustain peak modern traffic density, creating cascading flight delays.

  10. Siloed Cyber and Aviation Safety Governance: Incident response in aviation often treats IT security and Flight Safety Management Systems (SMS) as separate domains, delaying joint risk-based operational decisions.

Potential attack paths into aviation OT

The following analytical hypotheses map plausible entry routes into the ATNS operational environment:

[HYPOTHETICAL / NOT CONFIRMED IN THIS INCIDENT]

Path 1: Enterprise Network -> IT/OT DMZ -> Weather OT Workstation

Internet --> Phishing / Credential Theft --> Enterprise Active Directory --> Dual-Homed Jump Host --> FAPE Weather OT

Path 2: Third-Party Vendor Access -> Remote Maintenance Gateway -> Sensor Network

Vendor Laptop --> Compromised VPN / AnyDesk --> Remote Access Server --> Regional Airport AWOS OT Network

Path 3: Direct Exposure of Edge Meteorological Gateways

Internet --> Unpatched Edge Router / Serial Gateway --> Meteorological Data Server --> ATS Display Terminal

Path 4: Insider-Facilitated Lateral Movement

Local Employee Physical Access --> USB / Local Maintenance Port --> OT Workstation / Exfiltration Channel

Evaluation of Attack Path Hypotheses

Path 1: Enterprise IT to OT Traversal via Jump Host

  • Technically Plausible: High. Common path for IT-born ransomware toolkits moving into operational zones.

  • Telemetry Required: Active Directory Kerberos ticket requests, RDP/SSH logs between IT and OT DMZ, Sysmon event IDs 1 (Process Creation) and 3 (Network Connection).

  • Defensive Controls: Micro-segmentation, multi-factor authentication on all jump hosts, disablement of cross-domain trust.

Path 2: Compromised Third-Party Remote Maintenance Gateway

  • Technically Plausible: Very High. Navigational aids and weather stations are frequently maintained remotely by overseas or regional contractors.

  • Telemetry Required: VPN session logs, vendor authentication timestamps, unexpected outbound C2 traffic from vendor jump servers.

  • Defensive Controls: Just-In-Time (JIT) access approval, session recording, strict IP whitelisting.

Global aviation sector impact and dependency chains

The ATNS incident serves as a critical case study for global Air Navigation Service Providers (ANSPs) and airport operators.


Transferable vulnerabilities for global operators

  • Shared Technology Stacks: ANSPs globally utilize standardized ATM systems and standardized weather integration protocols (ICAO IWXXM, TAC). Vulnerabilities in support integrations are systemic across the industry.

  • Transboundary Data Dependencies: Flight Information Regions (FIRs) continuously exchange flight plans, radar tracks, and meteorological forecasts. A compromised data feed in one FIR impacts adjacent international airspace management.

Aviation OT attack-surface analysis

Attack Surface / Asset

Primary Threat

Technical Exposure

Operational Consequence

Preventive Control

Detection Opportunity

Automated Weather Systems (AWOS)

Data Spoofing / Malware

Unauthenticated serial/Ethernet converters

Corrupted wind/visibility data forcing manual ops

Cryptographic payload signing; network isolation

Anomaly detection on sensor data bounds

Vendor Remote VPN Gateways

Credential Theft / Exploitation

Always-on, unmonitored third-party tunnels

Direct bridge into OT subnet

MFA + Just-In-Time access approval

Unexpected connection hours or volume

Engineering Workstations (EWS)

Ransomware / RAT Deployment

Dual-homed interfaces, unpatched OS

Loss of OT configuration capabilities

Application whitelisting; disable USB ports

Process creation monitoring (Sysmon/EDR)

Aeronautical Info Systems (AIM)

Insider Data Theft / Tampering

Over-privileged internal user access

Exfiltration of flight routing & sensitive logs

Least privilege; PAM; DLP controls

Excessive database export queries

Voice Communication Systems (VCS)

Denial of Service

Unsegmented IP-based VoIP / RoIP networks

Loss of air-to-ground controller communications

Dedicated physical/VLAN separation

Network traffic volume anomaly alerts

Standards and regulatory framework mapping

Mapping required OT defenses against established international aviation and cybersecurity standards:

Control Domain

ICAO Doc 9985 / Aviation Security

NIST SP 800-82 Rev 3 / IEC 62443

Practical Aviation OT Implementation

Risk Management

Doc 9985 Sec 3.2 (Risk Assessment)

IEC 62443-2-1 Cl. 4.2

Conduct joint Cyber-Safety Risk Assessments (HAZOP + Cyber).

Asset Visibility

Doc 9985 Sec 4.1 (System Identification)

NIST SP 800-82 Sec 5.2

Passive OT network discovery; automated inventory of AWOS/CNS devices.

Network Segmentation

ICAO Cybersecurity Framework

IEC 62443-3-3 System Security Requirements (SR) 5.2

Enforce strict Purdue Model zoning; OT DMZ between IT and ATS networks.

Identity & Access

EASA Part-IS IS.D.005

NIST SP 800-82 Sec 6.2

Hardware MFA for all OT maintenance access; eliminate shared accounts.

Configuration Integrity

ICAO Doc 9985 App B

IEC 62443-4-2 SR 7.6

Automated baseline integrity monitoring for radar and weather servers.

Defensive architecture for aviation OT

A resilient aviation OT defense requires a multi-layered security model tailored to air traffic services:

 

Core architecture components

  1. One-Way Data Diodes: Deploy hardware data diodes to push meteorological and flight data from OT networks to enterprise/public consumers, preventing inbound network traversal.

  2. OT Passive Network Detection (NDR): Deploy non-intrusive network monitoring taps to profile native aviation protocols (e.g., ASTERIX radar data, AWOS serial-over-IP) without introducing latency or network risk.

  3. Immutable Golden Configurations: Maintain offline, cryptographically signed backups of all OT server configurations, PLC/RTU logic, and system images to enable rapid, trusted restoration.

Detection engineering use cases

Practical SOC and OT detection rules designed for aviation operational environments:

Detection Use Case 1: Unauthorized IT-to-OT Jump Host Access

  • Telemetry Source: Windows Event Logs (Event ID 4624 - Successful Logon) on OT DMZ Jump Servers.

  • Detection Logic: TargetServerName IN (OT_JUMP_SERVERS) AND LogonType = 10 (RemoteInteractive) AND UserNotInGroup ('APPROVED_OT_ENGINEERS')

  • Analyst Investigation: Verify whether an active maintenance ticket exists. Contact the OT operations desk to confirm the remote session.

  • OT-Safe Response: Terminate the jump host user session at the gateway layer. Do NOT power down or isolate the underlying OT server.

Detection Use Case 2: Unexpected Outbound Connection from Weather Data Server

  • Telemetry Source: Firewall Logs / NetFlow from OT DMZ.

  • Detection Logic: SourceIP IN (WEATHER_PROCESSING_SERVERS) AND DestinationIP NOT IN (APPROVED_MET_RECIPIENTS) AND DestinationPort IN (80, 443, 22, 53)

  • Analyst Investigation: Inspect process execution on the source weather server (Sysmon Event ID 1). Identify the binary initiating external sockets.

  • OT-Safe Response: Block the destination IP address at the perimeter firewall. Maintain local weather server execution while investigating process legitimacy.

Recommended KPIs and KRIs for aviation OT

Metrics designed to evaluate OT security posture and operational risk:

Metric Category

Key Performance / Risk Indicator

Recommended Target Range

Operational Rationale

Asset Exposure

% OT Assets Cataloged in Active Inventory

100%

Unmanaged OT endpoints represent unmonitored entry points.

Asset Exposure

Externally Reachable OT Interfaces

0

No direct Internet exposure for OT networks.

Identity & Access

% OT Administrative Sessions Using MFA

100%

Prevents single-factor credential compromise.

Remote Access

% Vendor Remote Access Sessions Monitored

100%

Ensures complete audit trail of third-party actions.

Resilience

OT Golden Image Restoration Test Frequency

Quarterly

Validates ability to recover from ransomware without paying.

Segmentation

Unauthorized Cross-Zone Traffic Violations

0 per month

High KRI indicating misconfigurations or lateral movement.

Incident-response playbook

Response actions organized into time-bound phases designed specifically for aviation OT environments.

1.0–4 Hours: Triage & Safety Validation:Immediate Priority: Maintain Air Traffic Safety & Isolate Intrusion.

  • Validate operational safety with Air Traffic Control watch supervisors. Confirm radar and radio voice channels remain fully operational.

  • Enforce manual fallback protocols for aviation weather feeds if automated system integrity is questioned.

  • Perform network-level isolation of compromised OT segments (FAPE) at the switch/firewall layer. WARNING: Do NOT reboot or power-cycle OT servers to preserve volatile RAM evidence.

  • Notify national aviation safety regulators and national cyber security incident response teams.

2.4–24 Hours: Forensic Preservation & Containment: Focus: Volatile Memory Capture & Perimeter Hardening.

  • Capture full volatile memory (RAM) and disk images from affected weather servers and EWS endpoints using OT-validated forensic tools.

  • Freeze all active Active Directory accounts associated with regional site maintenance. Rotate all privileged credentials across enterprise and OT domains.

  • Terminate all third-party vendor VPN and remote-access sessions globally pending security review.

  • Conduct deep log analysis on egress firewalls to identify all external exfiltration IP addresses.

3.24–72 Hours: Root-Cause Analysis & Malware Engineering:Focus: Vector Identification & Scope Determination.

  • Perform reverse engineering on isolated malware binaries to identify persistence mechanisms, lateral movement capabilities, and C2 profiles.

  • Inspect internal AIM database query logs (FAMM) to quantify exfiltrated personal and operational data sets.

  • Execute forensic sweeps across all adjacent regional airport OT networks using Indicators of Compromise (IoCs) derived from FAPE artifacts.

4.3–7 Days: Configuration Validation & Clean Restoration: Focus: System Rebuilds from Trusted Baselines.

  • Rebuild compromised weather OT servers from cryptographic golden images. Do NOT attempt to "clean" infected OS instances.

  • Validate the integrity of sensor calibration baselines and data translation software prior to re-connecting AWOS networks.

  • Reintroduce affected data feeds in a controlled and monitored manner after integrity validation, with independent comparison against trusted meteorological sources where operationally appropriate.

5.30 Days: Post-Incident Review & Resilience Hardening:Focus: Lessons Learned & Architectural Upgrades.

  • Finalize legal, regulatory (POPIA), and forensic reports.

  • Deploy hardware data diodes between meteorological processing subnets and enterprise distribution networks.

  • Conduct joint cyber-safety incident response exercises involving ATC controllers, OT engineers, and executive leadership.

Executive risk and propagation model

This model illustrates how a peripheral cyber intrusion propagates through system layers to create operational capacity degradation:


Unanswered questions  

Independent investigators and ATNS security teams must address these critical unanswered questions:

Initial access and intrusion vector

  1. What specific entry point was utilized to gain initial access to the FAPE operational network?

  2. Was an unpatched edge routing device or remote access gateway exposed directly to the Internet at FAPE?

  3. Did the intrusion originate from a compromised third-party contractor environment?

Malware and technical execution

  1. What specific malware family or framework was present in the FAPE OT environment?

  2. Did the malware payload contain destructive wiping capabilities, or was it restricted to espionage/ransomware staging?

  3. Was the malware executed with SYSTEM/Administrator privileges on OT hosts?

Data theft and insider activity at FAMM

  1. What specific operational and personal data sets were exfiltrated from the FAMM facility?

  2. Was the insider activity at FAMM technically connected to the external C2 exfiltration observed at FAPE, or were they parallel, independent incidents?

  3. What credentials or physical access methods were utilized by internal personnel at FAMM?

Network Architecture and Lateral Movement

  1. How did traffic pass between the enterprise IT network and the weather OT network at FAPE?

  2. Were Active Directory domain trusts shared between enterprise systems and OT workstations?

  3. Was network segmentation between the weather support zone and primary radar/ATC processing strictly enforced by firewalls?

Exfiltration & C2 Telemetry

  1. What total volume of data was exfiltrated to the China-based IP addresses?

  2. Over what specific timeframe did outbound exfiltration occur prior to detection?

  3. Were encrypted protocol tunnels (e.g., DNS tunneling, HTTPS POST) utilized to bypass perimeter monitoring?

Recovery and Long-Term Integrity

  1. How did ATNS forensic teams verify that malware was completely eradicated from OT endpoints?

  2. What cryptographic validation was performed to confirm OT configuration files were not altered?

  3. Are manual fallback procedures at regional airports regularly exercised under full traffic load conditions?

  4. Have all third-party vendor connections undergone comprehensive forensic audits post-incident?

  5. What technical controls have been implemented to prevent insider data exfiltration across regional airfields?

Final Shieldworkz assessment

Addressing the core investigative questions directly:

  • What do we know? ATNS experienced a dual-site critical infrastructure incident involving a malware intrusion on an OT network supporting weather services at FAPE (with confirmed exfiltration to China-based IPs) and a parallel insider data theft incident at FAMM.

  • What do we not know? Public evidence is insufficient to determine the exact initial access vector, specific malware hashes, or whether the insider at FAMM acted in collusion with external threat actors.

  • What is the most technically significant aspect of the incident? The intrusion successfully reached an Operational Technology (OT) network supporting air traffic services, demonstrating that peripheral aviation support networks are exposed to lateral traversal.

  • What does the incident reveal about aviation OT attack surfaces? Aviation weather infrastructure represents an under-monitored attack surface that directly impacts ATC operational capacity when compromised.

  • Is there credible evidence connecting it to Iran? No. Technical telemetry (China-based exfiltration, covert data theft) contradicts documented Iranian operational patterns.

  • What alternative explanations remain? Chinese-nexus cyber espionage targeting transportation infrastructure, commercial ransomware access brokers, or opportunistic insider exfiltration.

  • An attacker with sufficient privileges could potentially attempt to alter, suppress or disrupt meteorological information. Depending on the affected system, redundancy and operational procedures, such manipulation could degrade decision-support integrity or trigger fallback procedures.

  • What controls would most effectively break the attack chain? Unidirectional data diodes for weather data outbound transfers, strict IT/OT micro-segmentation, and hardware MFA for all administrative access.

  • What should aviation operators test immediately? The security isolation of regional airport OT connections and the integrity of manual fallback procedures under peak traffic conditions.

  • What should aviation CISOs and OT teams monitor differently? Monitor non-radar operational support networks (weather, AIM, flight scheduling) with the same rigor as primary radar data streams.

The ATNS case illustrates a potentially important aviation OT security problem: operationally consequential cyber risk can exist in systems that sit outside the traditional definition of “core ATC,” particularly where those systems supply information or services that controllers depend upon. The critical security question is therefore not simply whether an attacker can reach the radar or flight-data-processing core, but whether they can compromise the integrity, availability or trustworthiness of a dependency on which safe and efficient air navigation relies.

Conduct an IEC 62443-based OT risk assessment for your airport in under 48 hours with OThello.

Source methodology and hierarchy

This report was constructed using a strict intelligence source hierarchy:

  • Tier 1 (Primary / Authoritative): ATNS Official Procurement & RFQ Documentation (ATNS/RFQ14/07/2026/27/IT-DIGITAL FORENSIC), official ATNS public disclosures, and ICAO/EASA aviation safety frameworks.

  • Tier 2 (High-Quality Secondary): Dark Reading investigative technical reporting, established defense/aviation threat intelligence analysis, and verified cybersecurity disclosures.

  • Tier 3 (Supplementary): Shieldworkz research. Vendor attribution claims are treated as unconfirmed hypotheses unless backed by technical telemetry.

Finding

Evidence

Confidence

Why

Malware affected FAPE OT environment

ATNS documentation

High, if explicitly stated

Primary source

Weather-support function involved

ATNS documentation

High, if explicitly stated

Primary source

Data was exfiltrated

Forensic/log evidence

Verify

Depends on source wording

China-based destination

Technical evidence

Verify

IP geography ≠ actor attribution

IT→OT lateral movement

Not established

Low/Unknown

No public attack path

Ransomware encryption

Not established

Unknown

Malware presence ≠ encryption

Iran involvement

No technical attribution evidence

Unconfirmed

Hypothesis only

China-linked actor

Not established

Unknown

Destination geography insufficient

FAMM/FAPE connection

Not established

Unknown

Could be parallel incidents

Primary ATC/radar compromise

No evidence identified

Unknown

Requires forensic confirmation

 

Suggested reading

A investigative report on the Manchester Airports Group incident

OT Security for the entire aviation ecosystem  

 

Wöchentlich erhalten

Ressourcen & Nachrichten

Erfahren Sie, wie unsere branchenführenden OT-Security-Lösungen kritische Sicherheitsherausforderungen gemäß KRITIS-Anforderungen bewältigen

Dies könnte Ihnen auch gefallen.

BG image

Jetzt anfangen

Skalieren Sie Ihre CPS-Sicherheitslage

Nehmen Sie Kontakt mit unseren CPS-Sicherheitsexperten für eine kostenlose Beratung auf.

BG image

Jetzt anfangen

Skalieren Sie Ihre CPS-Sicherheitslage

Nehmen Sie Kontakt mit unseren CPS-Sicherheitsexperten für eine kostenlose Beratung auf.

BG image

Jetzt anfangen

Skalieren Sie Ihre CPS-Sicherheitslage

Nehmen Sie Kontakt mit unseren CPS-Sicherheitsexperten für eine kostenlose Beratung auf.