IT in Manufacturing


From Trojan takeovers to ransomware roulette

July 2025 IT in Manufacturing

Cisco’s Cyber Threat Trends Report offers a comprehensive and overview of the evolving cyber security landscape, leveraging its vast global reach through the analysis of DNS traffic. With visibility into over 715 billion DNS requests daily, Cisco provides a unique perspective into malicious activity across the internet. The report draws on eight months of DNS-layer data from August 2023 to March 2024 collected via Cisco Umbrella, and presents a detailed analysis of trends across various categories of threats.

The findings reveal that information stealers were the most frequently detected threat type throughout the reporting period. These are tools and malware designed to exfiltrate data such as documents, video and audio from compromised systems. Their activity was not constant but followed a wave-like pattern, with periods of intense detection followed by relative quiet. Cisco suggests that this lull may reflect operational pauses, during which attackers analyse and monetise stolen data before launching new campaigns.

In contrast, Trojan activity showed a notable decline over the same time span. Trojans, often used to gain an initial foothold in a network, started off strong but decreased significantly in later months. However, this did not signal an overall drop in cyber threats. Instead, ransomware activity surged dramatically in January 2024 and remained high into March. Cisco theorises that this shift reflects a tactical relationship between Trojans and ransomware. Frequently, threat actors deploy a Trojan first to establish access and later use that access to deliver ransomware payloads, encrypting data and extorting victims for payment.

The report also observed fluctuating activity in other threat categories, including remote access Trojans (RATs), advanced persistent threats (APTs), botnets, droppers and backdoors. Each showed distinct patterns of DNS behaviour and seasonal variation. RATs and APTs, in particular, represented more targeted and stealthy attack strategies that are harder to detect through traditional security tools but still leave traces at the DNS layer.

A central theme in the report is the critical role of DNS in modern cyber attacks. Almost all malware needs to make a DNS request to reach a command-and-control server, download payloads or exfiltrate data. By monitoring DNS queries, defenders can identify suspicious behaviours early, often before the actual attack fully unfolds. Cisco Umbrella, for example, blocks more than one million malicious domains every hour by detecting these behaviours in real time. DNS-layer protection can therefore act as a crucial frontline defense, stopping threats before they reach internal systems.

In addition to DNS protection, Cisco emphasises the importance of a layered security approach. This involves combining DNS-level filtering with endpoint security technologies such as antivirus, endpoint detection and response tools. A defense-in-depth strategy is essential because even if one control fails, others can catch the threat before it causes damage. Cisco compares this to having multiple bouncers at a club. If one misses an intruder, another can intervene. Their broader security stack, including Cisco Secure Access, integrates services such as secure web gateway (SWG), cloud access security broker (CASB), zero trust network access (ZTNA), remote browser isolation, data loss prevention (DLP) and malware detection to cover a range of attack vectors and user environments.

Cisco Talos, the company’s threat intelligence team, contributed further insight into the threat landscape. Their research highlighted identity-based attacks as the most common vector for breaches. Phishing, credential theft and misuse of legitimate accounts were involved in 60% of incident response cases, underscoring the need for strong identity protection such as multi-factor authentication (MFA) and Zero Trust architectures.

The report warns that threats are highly dynamic, often appearing in waves. For instance, when Trojan activity recedes, ransomware may rise. This ebb and flow suggests attackers regroup and shift tactics rapidly, sometimes even repurposing existing access or tools for new campaigns. This kind of fluidity requires defenders to remain agile, adapting their strategies based on threat intelligence and real-time visibility into network behaviour.

Organisations that deploy DNS-layer security in conjunction with endpoint and identity-based defenses are better positioned to detect and prevent threats. DNS filtering catches malicious domains before connections are made; endpoint tools stop payload execution and lateral movement; and identity safeguards limit attackers’ ability to exploit user accounts.

Cisco’s report aligns with broader industry trends. Other analysts, such as those from Deloitte and Gartner, have identified ransomware, social engineering and increasingly sophisticated threat actors as top challenges. Gartner, in particular, recommends a layered, AI-augmented defense model, echoing Cisco’s approach to integrating DNS intelligence with other security technologies.

The report delivers a clear message: defenders must combine deep visibility with multi-layered defenses to keep pace with rapidly evolving threats. DNS-layer protection offers a unique early-warning capability but it is most effective when part of a broader strategy that includes endpoint protection, cloud security, identity management and robust incident response. As attackers continue to shift tactics from data theft to ransomware to stealthy persistence, defenders must stay informed, proactive and flexible in their security architecture. The digital threat landscape is constantly changing and only by integrating intelligence, technology and strategy can organisations stay one step ahead.

To read the full report visit www.instrumentation.co.za/ex/cisco_cyberthreat_trends.pdf




Share this article:
Share via emailShare via LinkedInPrint this page

Further reading:

Sustainable energy management
Siemens South Africa IT in Manufacturing
Utilising its innovative ONE approach technology, Siemens provides complete transparency on resource consumption and offers data-driven optimisation recommendations for sustainable energy management.

Read more...
Paving the way for a carbon-neutral future in South Africa
IT in Manufacturing
At ABB Electrification, we believe the infrastructure of the future must do more than support daily operations, it must anticipate them. We are committed to building intelligent systems that connect and optimise infrastructure across sectors.

Read more...
Africa’s hidden AI advantage
IT in Manufacturing
Through my work implementing AI systems across three continents, I’ve become convinced that Africa’s unique context demands urgent AI adoption. Successful implementation requires local expertise to understand resource constraints as design parameters to create the innovations that make technology truly work under real-world conditions.

Read more...
Siemens Xcelerator empowers space-tech pioneer, Skyroot Aerospace
Siemens South Africa IT in Manufacturing
Siemens Digital Industries Software has announced that Skyroot Aerospace, a leading private space launch service company in India, has adopted Polarion software from the Siemens Xcelerator portfolio to digitally transform its software development processes and enhance efficiency as it aims to accelerate access to space for its customers worldwide.

Read more...
Water is running out, is your ESG strategy ready?
IT in Manufacturing
Water is one of the most critical yet undervalued resources in modern business. Water stewardship asks businesses to understand their water footprint across the entire value chain and to engage with others who share the same water resources.

Read more...
Cybersecurity in 2025: Six trends to watch
Rockwell Automation IT in Manufacturing
Rockwell Automation’s 10th State of Smart Manufacturing report finds that cybersecurity risks are a major, ever-present obstacle, and are now the third-largest impediment to growth in the next 12 months.

Read more...
The state of the smart buildings market in 2025
IT in Manufacturing
Smart buildings are entering a transformative phase, driven by sustainability goals, technological innovation and evolving user expectations. According to ABI Research’s latest whitepaper, the sector is undergoing a strategic overhaul across key areas like retrofitting, energy efficiency, data-driven operations and smart campus development.

Read more...
Digital twin for Bavaria’s National Theatre
Siemens South Africa IT in Manufacturing
Siemens and the Bavarian State Opera are digitalising the acoustics in Bavaria’s National Theatre in Munich, Germany. The result is a digital twin that simulates sound effects, orchestral setups and venue configurations in a realistic 3D acoustic model so that musicians, the director and conductors can assess a concert hall’s acoustics even before the first rehearsal.

Read more...
How AI can help solve South Africa’s water crisis
IT in Manufacturing
Climate change, ageing infrastructure, pollution and unequal access are putting intense pressure on the country’s water systems. A powerful question arises: “Can artificial intelligence help us change course?”

Read more...
Backup has evolved, but has your strategy?
IT in Manufacturing
With cyber threats rising and compliance standards tightening, South African organisations are under growing pressure to revisit their data protection strategies. The era of treating backups as a box-ticking exercise is over.

Read more...









While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd | All Rights Reserved