
Deep investigation: Cyber compromise and data exfiltration at Air Traffic and Navigation Services (ATNS)


Prayukth K V
Recently the South African government-owned entity that provides air traffic control (ATC) and weather operations reported a ransomware-linked malware that had infected the operational technology (OT) network. This is as per documents made available by the company Air Traffic and Navigation Services (ATNS).
As per ATNS, the cyberattack was prevented from escalating and the operator is gearing up for a detailed investigation of the incident.
The available documentation accessed by Shieldworkz research team points to two significant security events within ATNS infrastructure: a malware incident involving an OT environment supporting aviation-weather services at FAPE, and a separate insider data-access/exfiltration matter at FAMM. Publicly available evidence does not yet establish whether the two events were operationally connected.
Core analytical verdict
Our central analytical Question is this. Was this simply a ransomware incident that happened to reach an aviation OT environment or does it reveal a more consequential weakness in the architecture, dependencies, and operational resilience of modern air traffic infrastructure?
The incident at Air Traffic and Navigation Services (ATNS) is certainly not a routine enterprise IT ransomware infection that spilled over into OT. Primary forensic evidence specifically ATNS Tender/RFQ ATNS/RFQ14/07/2026/27/IT-DIGITAL FORENSIC issued in September 2026 reveals a bifurcated critical infrastructure incident:
A targeted OT network compromise at Chief Dawid Stuurman International Airport (FAPE / Port Elizabeth) involving ransomware-associated tooling deployed within an Operational Technology environment supporting weather-related Air Traffic Services (ATS), accompanied by verified telemetry of data exfiltration to external IP addresses located in China.
A parallel insider-driven data theft campaign at Mafikeng International Airport (FAMM) involving unauthorized access, extraction, and exfiltration of personal and operational datasets by internal personnel.
This incident exposes a strategic vulnerability in global aviation: the unmonitored dependency of Air Traffic Control (ATC) on peripheral operational support networks—specifically Aviation Meteorological (Met) and Aeronautical Information Management (AIM) systems. Attackers do not need to penetrate safety-critical radar processing cores to degrade air navigation capacity; compromising peripheral meteorological OT feeds creates data integrity doubts that force air traffic managers into manual fallback, reduced airspace acceptance rates, and operational degradation.
Evidentiary reconstruction and classification
To establish an evidence-based foundation, every analytical finding is classified according to standard intelligence confidence protocols:
CONFIRMED: Directly substantiated by official ATNS documentation, procurement filings, or government disclosures.
REPORTED: Documented by credible journalism or established threat intelligence providers.
CLAIMED: Asserted by external threat actors or unverified third parties.
ASSESSED: Deducted through rigorous technical and operational reasoning based on available telemetry.
UNKNOWN: Telemetry or public evidence is insufficient to verify.
Summary of evidence
Analytical Item | Classification | Source / Telemetry Base | Operational Context |
Malware Intrusion at FAPE | CONFIRMED | ATNS RFQ ATNS/RFQ14/07/2026/27/IT-DIGITAL FORENSIC | Ransomware-linked malware/toolkit detected in OT environment supporting weather-related services to ATS at Chief Dawid Stuurman Int'l Airport (FAPE). |
Data Exfiltration to China-based IPs | CONFIRMED | ATNS RFQ Scope Document / Dark Reading | Log records showed outbound data exfiltration from FAPE systems to external IP addresses registered in China. |
Insider Data Theft at FAMM | CONFIRMED | ATNS RFQ ATNS/RFQ14/07/2026/27/IT-DIGITAL FORENSIC | Unlawful access, copying, and exfiltration of personal and operational data at Mafikeng Airport (FAMM) involving internal employees. |
Containment Action by ATNS | CONFIRMED | ATNS Official RFQ Statements | Internal technical teams isolated systems and removed malware prior to issuing the September 2026 forensic RFQ. |
En-Route Radar Processing Compromise | UNLIKELY | ATNS Scope & Operational Telemetry | No evidence indicates that primary En-Route radar processing cores (Flight Data Processing System / Radar Data Processing System) were compromised. |
Active Ransomware File Encryption | UNCONFIRMED | Forensic Scope & Technical Telemetry | Malware toolkit was present; public evidence does not confirm active .encrypted file payloads or operational ransom notes were triggered in the OT zone. |
Grounding / Flight Cancellation Direct Impact | ASSESSED | Operational ATS Analysis | Operational disruption was contained to degraded meteorological data workflows rather than total ground stops. |
Confirmed incident timeline
Initial Intrusion and Operational Compromise (Estimated)
Q2–Q3 2026
Unidentified threat actor establishes initial access to peripheral networks supporting ATNS operational facilities. Data exfiltration channels initiated from FAPE operational infrastructure to external IP addresses located in China.
Malware Detection and Containment at FAPE
Late August 2026
Automated monitoring systems at Chief Dawid Stuurman International Airport (FAPE) detect suspicious activity and ransomware-associated binaries within the OT network supporting aviation weather data feeds for Air Traffic Services. ATNS internal IT/OT technical teams initiate emergency containment and malware remediation.
Parallel Discovery of Insider Data Theft at FAMM
Late August 2026
Internal audit and log monitoring at Mafikeng International Airport (FAMM) flag unauthorized access to personal and operational data repositories. Evidence indicates deliberate data exfiltration by internal employees.
Public Procurement and RFQ Issue
01 September 2026
ATNS issues official tender document ATNS/RFQ14/07/2026/27/IT-DIGITAL FORENSIC seeking an independent digital forensics firm to perform malware reverse engineering, log analysis, chain-of-custody evidence collection, and impact assessment.
RFQ Bidding Close and Escalation
08 September 2026
Formal tender closing date for forensic investigation proposals. Technical scope mandates determining infection vectors, data exfiltration scope, and POPIA/regulatory compliance impacts.
Public Intelligence Exposure
30 September 2026
Dark Reading discloses details of the ATNS procurement documents, confirming external exfiltration to Chinese IP addresses and highlighting vulnerabilities in aviation OT weather support systems.
2. Technical Attack Reconstruction
Reconstructing the kill chain based strictly on disclosed technical scope and standard OT attack patterns:
Observed
Malware identified → OT weather-support environment involved → investigation/containment → potential/identified outbound communications → forensic investigation
Hypotheses
Initial access → privilege escalation → lateral movement → persistence → data staging → exfiltration mechanism
Stage-by-stage reconstruction analysis
Initial Access
Confirmed Evidence: Public evidence is insufficient to determine the exact initial access vector.
Plausible Hypotheses:
Compromise of remote access / VPN infrastructure utilized by third-party maintenance contractors servicing airport meteorological sensor gateways.
Phishing against ATNS engineering/maintenance personnel leading to credential theft.
Evidence Supporting: ATNS relies heavily on vendor support for regional airport navigational aids and weather sensors.
Evidence Against: No public disclosure of specific vendor compromised.
Required for Confirmation: Ingress firewall logs, VPN authentication records, and endpoint artifacts from entry-point jump hosts.
Execution and persistence
Confirmed Evidence: Presence of "ransomware-linked malware/toolkit" on operational systems at FAPE.
Plausible Hypotheses: Execution via living-off-the-land binaries (built-in Windows tools or dual-use admin tools like PowerShell or PsExec) to stage ransomware binaries and establish scheduled tasks or service persistence.
Public evidence is insufficient to determine the specific malware family or MD5/SHA256 hashes.
Privilege escalation and discovery
Confirmed Evidence: Public evidence is insufficient to determine specific escalation mechanisms.
Plausible Hypotheses: Exploitation of unpatched Windows vulnerabilities on legacy engineering workstations or credential harvesting via LSASS dumping on weakly segmented IT/OT boundary hosts.
Lateral movement and OT access
Confirmed evidence: The intrusion crossed from initial entry points into an OT network supporting weather services for ATS. Malware was identified within an OT environment supporting weather-related ATS functions.
Plausible hypotheses: Traversal across dual-homed workstations bridging the enterprise network and the Meteorological Information System (MIS) network, or via shared Active Directory trust relationships.
Operational impact and exfiltration
Confirmed Evidence: Verified network logs indicating data exfiltration to external IP addresses located in China.
Plausible Hypotheses: Use of encrypted HTTP/S or custom C2 protocols to stream system configuration, weather database records, or operational network diagrams out of the FAPE environment prior to malware discovery.
Containment and recovery
Confirmed Evidence: ATNS technical teams executed containment and malware removal. Independent digital forensics engaged via RFQ to validate complete eradication, inspect memory artifacts, and conduct root-cause analysis.
Aviation OT Architecture Investigation
To understand the blast radius, the compromised system must be placed within a strict functional model of aviation technology. The diagram below illustrates the operational boundaries between ATNS Air Traffic Management OT, Airport Infrastructure OT, and Enterprise IT.

Key architectural distinctions
ATNS ATM/ATS OT vs. Airport OT: ATNS operates air navigation, radar, and weather data systems. Airports Company South Africa (ACSA) operates physical airport infrastructure (lighting, baggage, building systems). A compromise in ATNS weather OT does not grant access to ACSA physical building controllers.
Core Radar Processing vs. Weather Support OT: The En-Route radar processing system resides in a highly restricted, deterministic zone. The weather support environment at regional sites (FAPE) gathers data from Automated Weather Observing Systems (AWOS) and feeds METAR/TAF data to controllers and pilots. This peripheral network requires external connectivity for meteorological updates, creating an expanded attack surface.
Dimensions of the incident
Impact assessment across multiple operational dimensions:
[Cyber Intrusion] ──> [Loss of OT Integrity] ──> [Operational Fallback] ──> [Safety Management Action]
(FAPE Malware / (Corrupted/Untrusted (Manual Weather Inputs / (Increased Controller
FAMM Exfiltration) Weather Systems) Reduced Capacity) Workload / Spacing)
1. Operational Impact
Availability and Reliability: Operational availability of primary radar was maintained, but automatic weather data feeds were isolated, forcing air traffic controllers to rely on manual weather observations or voice-relayed meteorological updates.
Capacity and Workload: Manual weather relay increases controller workload per aircraft, reducing the hourly flight processing capacity (Acceptance Rate) at FAPE during instrument meteorological conditions (IMC).
2. Safety Impact
Situational Awareness: Loss of real-time automated weather updates (e.g., wind shear alerts, cloud base measurements) degrades situational awareness during precision approaches.
Separation Management: Controllers increase buffer distances between aircraft to compensate for manual workload, preventing safety incidents at the cost of flight efficiency.
3. Cyber and Physical Boundaries
Confidentiality: Breach confirmed via insider exfiltration at FAMM and external exfiltration to Chinese IP addresses at FAPE.
Integrity: Untrusted state introduced across weather OT endpoints, requiring complete forensic validation before restoring automated data pipelines.
Physical Boundary: The incident reached the OT layer and caused operational degradation, but safety controls prevented physical safety consequences or aircraft incidents.
Investigation of the Iran hypothesis and attribution assessment
A critical aspect of intelligence analysis is evaluating potential state-sponsored attribution without forcing conclusions.
Attribution Evaluation Matrix
Analytical Dimension | Observed ATNS Incident | Documented Iranian Threat Activity (e.g., CyberAv3ngers, Agrius, MuddyWater) |
Primary Target Class | Regional Air Navigation / Weather OT | Energy, Water, Transport, Israel/US/Gulf Infrastructure |
Technical Objective | Dual Malware Tooling + Silent Data Exfiltration | Rapid Operational Disruption, Pseudo-Ransomware, Wiper Deployment |
Tactical Execution | Covert, Long-term Exfiltration, Low Noise | Loud Defacements, Immediate Lockouts, Telegram Disclosures |
Observed Infrastructure | Exfiltration endpoints located in China | Infrastructure hosted in Russia, Middle East, VPS networks |

Analytical Attribution Assessment
Evidence Supporting Iranian Involvement: None. There is no technical telemetry, YARA hit, or C2 overlap linking the ATNS intrusion to Iranian threat groups.
Evidence Contradicting Iranian Involvement: Iranian OT campaigns typically emphasize rapid disruption, overt extortion, or destructive wipers accompanied by public claims. The ATNS incident exhibits covert data exfiltration to Chinese network infrastructure and a localized insider data theft campaign.
Alternative Explanations:
Chinese-Nexus Espionage Group: Supported by verified exfiltration logs to China-based IPs, aiming to gather intelligence on African transportation infrastructure, flight movements, or VIP transport logs.
Financial Ransomware / Access Broker Group: Opportunistic deployment of commercial ransomware toolkits, utilizing proxy infrastructure in Asia for exfiltration.
Disgruntled Insider / Commercial Data Theft: At FAMM, employee-driven data exfiltration operating independently or in collusion with external actors.
Iran Attribution: Not Established
· “The available evidence does not currently provide a technical basis for attributing the ATNS incident to an Iranian state or state-aligned actor. The reported targeting of critical infrastructure and OT environments is consistent with activity previously documented from multiple state-linked and criminal actors, including Iranian-linked groups, but those characteristics are not unique to Iran.”
· “The location of observed or suspected exfiltration infrastructure is also insufficient to establish or exclude attribution. Infrastructure geography should be treated as a technical indicator requiring correlation with malware, tooling, victimology, operational timing, authentication artifacts, infrastructure reuse and other forensic evidence.”
· “At present, Iranian involvement should therefore remain an attribution hypothesis rather than an intelligence conclusion.”
Comparison with recent critical infrastructure attacks
Dimension | ATNS Incident (2026) | Eurocontrol Attack (2023) | DP World Cyber Attack (2023) | Colonial Pipeline (2021) |
Threat Actor | Undisclosed / Insider + External | Hacktivist (Killnet) | Financial / Ransomware | Financial (DarkSide) |
Primary Objective | Espionage & Data Exfiltration | Service Disruption (DDoS) | Extortion & Disruption | Extortion |
Initial Access Vector | Vendor / Remote / Insider | Public Web Layer | Unpatched Gateway | Stolen VPN Credentials |
IT → OT Traversal | Yes (Reached Weather OT) | No (Web/IT only) | Partial (IT system halt) | No (Proactive OT Shutdown) |
OT Systems Affected | Weather Support for ATS | None | Logistics DB / Terminals | Pipeline Operational IT |
Operational Consequence | Degraded Weather Feeds | Website Down / Manual Ops | Port Operations Halted | Pipeline Suspended 5 Days |
Safety Consequence | Zero (Workload Absorbed) | Zero | Zero | Zero |
Data Exfiltration | Confirmed (China IPs & Insider) | No | Confirmed | Confirmed |
Unique and under-discussed analytical observations
Standard reporting focused heavily on the word "ransomware." Deep technical analysis reveals ten critical insights overlooked by mainstream coverage:
Weather Infrastructure is an Asymmetric Attack Vector: Modern Air Traffic Management relies on automated, digitized meteorological feeds (AWOS, METAR, TAF) for automated flight profile calculations. Compromising the integrity of weather data forces controllers into manual verification, instantly cutting airspace capacity without needing to touch radar systems.
Pre-Impact Reconnaissance vs. Immediate Extortion: The presence of ransomware toolkits alongside silent exfiltration indicates the attacker was in a "pre-impact" phase—mapping operational topology and exfiltrating data before executing destructive encryption.
The Danger of Peripheral OT Misclassification: Organizations often classify weather data receivers as "Low-Criticality IT" because they do not control physical aircraft. However, because they directly feed ATS decision-making, their failure degrades safety-critical operations.
Insider Convergence with Cyber Intrusion: The simultaneous occurrence of insider data theft at FAMM and external OT malware at FAPE highlights how physical/internal security gaps compound cyber vulnerabilities during critical incidents.
Configuration Integrity Blind Spots: Once malware touches an OT environment, the primary challenge is not merely removing the binary, but proving the absolute integrity of controller configuration files, sensor calibrations, and system baselines.
Legacy Sensor Protocols Lack Authentication: Serial-to-Ethernet converters and legacy meteorological sensor gateways lack cryptographic authentication, enabling man-in-the-middle data manipulation once the local OT segment is breached.
The Hidden Cost of Vendor Remote Management: Regional airports rely on third-party vendors for navigational aid and weather sensor maintenance. These persistent vendor remote-access tunnels are rarely subjected to zero-trust inspection.
Asymmetric Disruption via Data Integrity Doubt: Attackers do not need to alter weather values; simply creating doubt regarding data validity forces air traffic safety managers to suspend automated operations.
Manual Fallback Exercises Scalability Gap: While air traffic controllers train for manual operations, manual processing cannot sustain peak modern traffic density, creating cascading flight delays.
Siloed Cyber and Aviation Safety Governance: Incident response in aviation often treats IT security and Flight Safety Management Systems (SMS) as separate domains, delaying joint risk-based operational decisions.
Potential attack paths into aviation OT
The following analytical hypotheses map plausible entry routes into the ATNS operational environment:
[HYPOTHETICAL / NOT CONFIRMED IN THIS INCIDENT]
Path 1: Enterprise Network -> IT/OT DMZ -> Weather OT Workstation
Internet --> Phishing / Credential Theft --> Enterprise Active Directory --> Dual-Homed Jump Host --> FAPE Weather OT
Path 2: Third-Party Vendor Access -> Remote Maintenance Gateway -> Sensor Network
Vendor Laptop --> Compromised VPN / AnyDesk --> Remote Access Server --> Regional Airport AWOS OT Network
Path 3: Direct Exposure of Edge Meteorological Gateways
Internet --> Unpatched Edge Router / Serial Gateway --> Meteorological Data Server --> ATS Display Terminal
Path 4: Insider-Facilitated Lateral Movement
Local Employee Physical Access --> USB / Local Maintenance Port --> OT Workstation / Exfiltration Channel
Evaluation of Attack Path Hypotheses
Path 1: Enterprise IT to OT Traversal via Jump Host
Technically Plausible: High. Common path for IT-born ransomware toolkits moving into operational zones.
Telemetry Required: Active Directory Kerberos ticket requests, RDP/SSH logs between IT and OT DMZ, Sysmon event IDs 1 (Process Creation) and 3 (Network Connection).
Defensive Controls: Micro-segmentation, multi-factor authentication on all jump hosts, disablement of cross-domain trust.
Path 2: Compromised Third-Party Remote Maintenance Gateway
Technically Plausible: Very High. Navigational aids and weather stations are frequently maintained remotely by overseas or regional contractors.
Telemetry Required: VPN session logs, vendor authentication timestamps, unexpected outbound C2 traffic from vendor jump servers.
Defensive Controls: Just-In-Time (JIT) access approval, session recording, strict IP whitelisting.
Global aviation sector impact and dependency chains
The ATNS incident serves as a critical case study for global Air Navigation Service Providers (ANSPs) and airport operators.

Transferable vulnerabilities for global operators
Shared Technology Stacks: ANSPs globally utilize standardized ATM systems and standardized weather integration protocols (ICAO IWXXM, TAC). Vulnerabilities in support integrations are systemic across the industry.
Transboundary Data Dependencies: Flight Information Regions (FIRs) continuously exchange flight plans, radar tracks, and meteorological forecasts. A compromised data feed in one FIR impacts adjacent international airspace management.
Aviation OT attack-surface analysis
Attack Surface / Asset | Primary Threat | Technical Exposure | Operational Consequence | Preventive Control | Detection Opportunity |
Automated Weather Systems (AWOS) | Data Spoofing / Malware | Unauthenticated serial/Ethernet converters | Corrupted wind/visibility data forcing manual ops | Cryptographic payload signing; network isolation | Anomaly detection on sensor data bounds |
Vendor Remote VPN Gateways | Credential Theft / Exploitation | Always-on, unmonitored third-party tunnels | Direct bridge into OT subnet | MFA + Just-In-Time access approval | Unexpected connection hours or volume |
Engineering Workstations (EWS) | Ransomware / RAT Deployment | Dual-homed interfaces, unpatched OS | Loss of OT configuration capabilities | Application whitelisting; disable USB ports | Process creation monitoring (Sysmon/EDR) |
Aeronautical Info Systems (AIM) | Insider Data Theft / Tampering | Over-privileged internal user access | Exfiltration of flight routing & sensitive logs | Least privilege; PAM; DLP controls | Excessive database export queries |
Voice Communication Systems (VCS) | Denial of Service | Unsegmented IP-based VoIP / RoIP networks | Loss of air-to-ground controller communications | Dedicated physical/VLAN separation | Network traffic volume anomaly alerts |
Standards and regulatory framework mapping
Mapping required OT defenses against established international aviation and cybersecurity standards:
Control Domain | ICAO Doc 9985 / Aviation Security | NIST SP 800-82 Rev 3 / IEC 62443 | Practical Aviation OT Implementation |
Risk Management | Doc 9985 Sec 3.2 (Risk Assessment) | IEC 62443-2-1 Cl. 4.2 | Conduct joint Cyber-Safety Risk Assessments (HAZOP + Cyber). |
Asset Visibility | Doc 9985 Sec 4.1 (System Identification) | NIST SP 800-82 Sec 5.2 | Passive OT network discovery; automated inventory of AWOS/CNS devices. |
Network Segmentation | ICAO Cybersecurity Framework | IEC 62443-3-3 System Security Requirements (SR) 5.2 | Enforce strict Purdue Model zoning; OT DMZ between IT and ATS networks. |
Identity & Access | EASA Part-IS IS.D.005 | NIST SP 800-82 Sec 6.2 | Hardware MFA for all OT maintenance access; eliminate shared accounts. |
Configuration Integrity | ICAO Doc 9985 App B | IEC 62443-4-2 SR 7.6 | Automated baseline integrity monitoring for radar and weather servers. |
Defensive architecture for aviation OT
A resilient aviation OT defense requires a multi-layered security model tailored to air traffic services:

Core architecture components
One-Way Data Diodes: Deploy hardware data diodes to push meteorological and flight data from OT networks to enterprise/public consumers, preventing inbound network traversal.
OT Passive Network Detection (NDR): Deploy non-intrusive network monitoring taps to profile native aviation protocols (e.g., ASTERIX radar data, AWOS serial-over-IP) without introducing latency or network risk.
Immutable Golden Configurations: Maintain offline, cryptographically signed backups of all OT server configurations, PLC/RTU logic, and system images to enable rapid, trusted restoration.
Detection engineering use cases
Practical SOC and OT detection rules designed for aviation operational environments:
Detection Use Case 1: Unauthorized IT-to-OT Jump Host Access
Telemetry Source: Windows Event Logs (Event ID 4624 - Successful Logon) on OT DMZ Jump Servers.
Detection Logic: TargetServerName IN (OT_JUMP_SERVERS) AND LogonType = 10 (RemoteInteractive) AND UserNotInGroup ('APPROVED_OT_ENGINEERS')
Analyst Investigation: Verify whether an active maintenance ticket exists. Contact the OT operations desk to confirm the remote session.
OT-Safe Response: Terminate the jump host user session at the gateway layer. Do NOT power down or isolate the underlying OT server.
Detection Use Case 2: Unexpected Outbound Connection from Weather Data Server
Telemetry Source: Firewall Logs / NetFlow from OT DMZ.
Detection Logic: SourceIP IN (WEATHER_PROCESSING_SERVERS) AND DestinationIP NOT IN (APPROVED_MET_RECIPIENTS) AND DestinationPort IN (80, 443, 22, 53)
Analyst Investigation: Inspect process execution on the source weather server (Sysmon Event ID 1). Identify the binary initiating external sockets.
OT-Safe Response: Block the destination IP address at the perimeter firewall. Maintain local weather server execution while investigating process legitimacy.
Recommended KPIs and KRIs for aviation OT
Metrics designed to evaluate OT security posture and operational risk:
Metric Category | Key Performance / Risk Indicator | Recommended Target Range | Operational Rationale |
Asset Exposure | % OT Assets Cataloged in Active Inventory | 100% | Unmanaged OT endpoints represent unmonitored entry points. |
Asset Exposure | Externally Reachable OT Interfaces | 0 | No direct Internet exposure for OT networks. |
Identity & Access | % OT Administrative Sessions Using MFA | 100% | Prevents single-factor credential compromise. |
Remote Access | % Vendor Remote Access Sessions Monitored | 100% | Ensures complete audit trail of third-party actions. |
Resilience | OT Golden Image Restoration Test Frequency | Quarterly | Validates ability to recover from ransomware without paying. |
Segmentation | Unauthorized Cross-Zone Traffic Violations | 0 per month | High KRI indicating misconfigurations or lateral movement. |
Incident-response playbook
Response actions organized into time-bound phases designed specifically for aviation OT environments.
1.0–4 Hours: Triage & Safety Validation:Immediate Priority: Maintain Air Traffic Safety & Isolate Intrusion.
Validate operational safety with Air Traffic Control watch supervisors. Confirm radar and radio voice channels remain fully operational.
Enforce manual fallback protocols for aviation weather feeds if automated system integrity is questioned.
Perform network-level isolation of compromised OT segments (FAPE) at the switch/firewall layer. WARNING: Do NOT reboot or power-cycle OT servers to preserve volatile RAM evidence.
Notify national aviation safety regulators and national cyber security incident response teams.
2.4–24 Hours: Forensic Preservation & Containment: Focus: Volatile Memory Capture & Perimeter Hardening.
Capture full volatile memory (RAM) and disk images from affected weather servers and EWS endpoints using OT-validated forensic tools.
Freeze all active Active Directory accounts associated with regional site maintenance. Rotate all privileged credentials across enterprise and OT domains.
Terminate all third-party vendor VPN and remote-access sessions globally pending security review.
Conduct deep log analysis on egress firewalls to identify all external exfiltration IP addresses.
3.24–72 Hours: Root-Cause Analysis & Malware Engineering:Focus: Vector Identification & Scope Determination.
Perform reverse engineering on isolated malware binaries to identify persistence mechanisms, lateral movement capabilities, and C2 profiles.
Inspect internal AIM database query logs (FAMM) to quantify exfiltrated personal and operational data sets.
Execute forensic sweeps across all adjacent regional airport OT networks using Indicators of Compromise (IoCs) derived from FAPE artifacts.
4.3–7 Days: Configuration Validation & Clean Restoration: Focus: System Rebuilds from Trusted Baselines.
Rebuild compromised weather OT servers from cryptographic golden images. Do NOT attempt to "clean" infected OS instances.
Validate the integrity of sensor calibration baselines and data translation software prior to re-connecting AWOS networks.
Reintroduce affected data feeds in a controlled and monitored manner after integrity validation, with independent comparison against trusted meteorological sources where operationally appropriate.
5.30 Days: Post-Incident Review & Resilience Hardening:Focus: Lessons Learned & Architectural Upgrades.
Finalize legal, regulatory (POPIA), and forensic reports.
Deploy hardware data diodes between meteorological processing subnets and enterprise distribution networks.
Conduct joint cyber-safety incident response exercises involving ATC controllers, OT engineers, and executive leadership.
Executive risk and propagation model
This model illustrates how a peripheral cyber intrusion propagates through system layers to create operational capacity degradation:

Unanswered questions
Independent investigators and ATNS security teams must address these critical unanswered questions:
Initial access and intrusion vector
What specific entry point was utilized to gain initial access to the FAPE operational network?
Was an unpatched edge routing device or remote access gateway exposed directly to the Internet at FAPE?
Did the intrusion originate from a compromised third-party contractor environment?
Malware and technical execution
What specific malware family or framework was present in the FAPE OT environment?
Did the malware payload contain destructive wiping capabilities, or was it restricted to espionage/ransomware staging?
Was the malware executed with SYSTEM/Administrator privileges on OT hosts?
Data theft and insider activity at FAMM
What specific operational and personal data sets were exfiltrated from the FAMM facility?
Was the insider activity at FAMM technically connected to the external C2 exfiltration observed at FAPE, or were they parallel, independent incidents?
What credentials or physical access methods were utilized by internal personnel at FAMM?
Network Architecture and Lateral Movement
How did traffic pass between the enterprise IT network and the weather OT network at FAPE?
Were Active Directory domain trusts shared between enterprise systems and OT workstations?
Was network segmentation between the weather support zone and primary radar/ATC processing strictly enforced by firewalls?
Exfiltration & C2 Telemetry
What total volume of data was exfiltrated to the China-based IP addresses?
Over what specific timeframe did outbound exfiltration occur prior to detection?
Were encrypted protocol tunnels (e.g., DNS tunneling, HTTPS POST) utilized to bypass perimeter monitoring?
Recovery and Long-Term Integrity
How did ATNS forensic teams verify that malware was completely eradicated from OT endpoints?
What cryptographic validation was performed to confirm OT configuration files were not altered?
Are manual fallback procedures at regional airports regularly exercised under full traffic load conditions?
Have all third-party vendor connections undergone comprehensive forensic audits post-incident?
What technical controls have been implemented to prevent insider data exfiltration across regional airfields?
Final Shieldworkz assessment
Addressing the core investigative questions directly:
What do we know? ATNS experienced a dual-site critical infrastructure incident involving a malware intrusion on an OT network supporting weather services at FAPE (with confirmed exfiltration to China-based IPs) and a parallel insider data theft incident at FAMM.
What do we not know? Public evidence is insufficient to determine the exact initial access vector, specific malware hashes, or whether the insider at FAMM acted in collusion with external threat actors.
What is the most technically significant aspect of the incident? The intrusion successfully reached an Operational Technology (OT) network supporting air traffic services, demonstrating that peripheral aviation support networks are exposed to lateral traversal.
What does the incident reveal about aviation OT attack surfaces? Aviation weather infrastructure represents an under-monitored attack surface that directly impacts ATC operational capacity when compromised.
Is there credible evidence connecting it to Iran? No. Technical telemetry (China-based exfiltration, covert data theft) contradicts documented Iranian operational patterns.
What alternative explanations remain? Chinese-nexus cyber espionage targeting transportation infrastructure, commercial ransomware access brokers, or opportunistic insider exfiltration.
An attacker with sufficient privileges could potentially attempt to alter, suppress or disrupt meteorological information. Depending on the affected system, redundancy and operational procedures, such manipulation could degrade decision-support integrity or trigger fallback procedures.
What controls would most effectively break the attack chain? Unidirectional data diodes for weather data outbound transfers, strict IT/OT micro-segmentation, and hardware MFA for all administrative access.
What should aviation operators test immediately? The security isolation of regional airport OT connections and the integrity of manual fallback procedures under peak traffic conditions.
What should aviation CISOs and OT teams monitor differently? Monitor non-radar operational support networks (weather, AIM, flight scheduling) with the same rigor as primary radar data streams.
The ATNS case illustrates a potentially important aviation OT security problem: operationally consequential cyber risk can exist in systems that sit outside the traditional definition of “core ATC,” particularly where those systems supply information or services that controllers depend upon. The critical security question is therefore not simply whether an attacker can reach the radar or flight-data-processing core, but whether they can compromise the integrity, availability or trustworthiness of a dependency on which safe and efficient air navigation relies.
Conduct an IEC 62443-based OT risk assessment for your airport in under 48 hours with OThello.
Source methodology and hierarchy
This report was constructed using a strict intelligence source hierarchy:
Tier 1 (Primary / Authoritative): ATNS Official Procurement & RFQ Documentation (ATNS/RFQ14/07/2026/27/IT-DIGITAL FORENSIC), official ATNS public disclosures, and ICAO/EASA aviation safety frameworks.
Tier 2 (High-Quality Secondary): Dark Reading investigative technical reporting, established defense/aviation threat intelligence analysis, and verified cybersecurity disclosures.
Tier 3 (Supplementary): Shieldworkz research. Vendor attribution claims are treated as unconfirmed hypotheses unless backed by technical telemetry.
Finding | Evidence | Confidence | Why |
Malware affected FAPE OT environment | ATNS documentation | High, if explicitly stated | Primary source |
Weather-support function involved | ATNS documentation | High, if explicitly stated | Primary source |
Data was exfiltrated | Forensic/log evidence | Verify | Depends on source wording |
China-based destination | Technical evidence | Verify | IP geography ≠ actor attribution |
IT→OT lateral movement | Not established | Low/Unknown | No public attack path |
Ransomware encryption | Not established | Unknown | Malware presence ≠ encryption |
Iran involvement | No technical attribution evidence | Unconfirmed | Hypothesis only |
China-linked actor | Not established | Unknown | Destination geography insufficient |
FAMM/FAPE connection | Not established | Unknown | Could be parallel incidents |
Primary ATC/radar compromise | No evidence identified | Unknown | Requires forensic confirmation |
Suggested reading
A investigative report on the Manchester Airports Group incident
OT Security for the entire aviation ecosystem
Wöchentlich erhalten
Ressourcen & Nachrichten
Erfahren Sie, wie unsere branchenführenden OT-Security-Lösungen kritische Sicherheitsherausforderungen gemäß KRITIS-Anforderungen bewältigen
Dies könnte Ihnen auch gefallen.

Anatomy of the Adif and Renfe Cyber Breach: AI-Assisted Intrusion and Impact

Team Shieldworkz

Fresenius medical care cyber incident: Investigating trusted access, third-party exposure and enterprise blast radius

Team Shieldworkz

OT Removable Media Security: Close the USB Risk Gap Before It Reaches Production

Team Shieldworkz

The Canva breach and the hidden risk of third-party trust

Prayukth K V

NERC CIP Compliance Assessment: Find Gaps Before Auditors Do

Team Shieldworkz

Beyond substitution: Strategic takeaways from India’s SCADA indigenisation

Team Shieldworkz

