IT in Manufacturing


From Trojan takeovers to ransomware roulette

July 2025 IT in Manufacturing

Cisco’s Cyber Threat Trends Report offers a comprehensive and overview of the evolving cyber security landscape, leveraging its vast global reach through the analysis of DNS traffic. With visibility into over 715 billion DNS requests daily, Cisco provides a unique perspective into malicious activity across the internet. The report draws on eight months of DNS-layer data from August 2023 to March 2024 collected via Cisco Umbrella, and presents a detailed analysis of trends across various categories of threats.

The findings reveal that information stealers were the most frequently detected threat type throughout the reporting period. These are tools and malware designed to exfiltrate data such as documents, video and audio from compromised systems. Their activity was not constant but followed a wave-like pattern, with periods of intense detection followed by relative quiet. Cisco suggests that this lull may reflect operational pauses, during which attackers analyse and monetise stolen data before launching new campaigns.

In contrast, Trojan activity showed a notable decline over the same time span. Trojans, often used to gain an initial foothold in a network, started off strong but decreased significantly in later months. However, this did not signal an overall drop in cyber threats. Instead, ransomware activity surged dramatically in January 2024 and remained high into March. Cisco theorises that this shift reflects a tactical relationship between Trojans and ransomware. Frequently, threat actors deploy a Trojan first to establish access and later use that access to deliver ransomware payloads, encrypting data and extorting victims for payment.

The report also observed fluctuating activity in other threat categories, including remote access Trojans (RATs), advanced persistent threats (APTs), botnets, droppers and backdoors. Each showed distinct patterns of DNS behaviour and seasonal variation. RATs and APTs, in particular, represented more targeted and stealthy attack strategies that are harder to detect through traditional security tools but still leave traces at the DNS layer.

A central theme in the report is the critical role of DNS in modern cyber attacks. Almost all malware needs to make a DNS request to reach a command-and-control server, download payloads or exfiltrate data. By monitoring DNS queries, defenders can identify suspicious behaviours early, often before the actual attack fully unfolds. Cisco Umbrella, for example, blocks more than one million malicious domains every hour by detecting these behaviours in real time. DNS-layer protection can therefore act as a crucial frontline defense, stopping threats before they reach internal systems.

In addition to DNS protection, Cisco emphasises the importance of a layered security approach. This involves combining DNS-level filtering with endpoint security technologies such as antivirus, endpoint detection and response tools. A defense-in-depth strategy is essential because even if one control fails, others can catch the threat before it causes damage. Cisco compares this to having multiple bouncers at a club. If one misses an intruder, another can intervene. Their broader security stack, including Cisco Secure Access, integrates services such as secure web gateway (SWG), cloud access security broker (CASB), zero trust network access (ZTNA), remote browser isolation, data loss prevention (DLP) and malware detection to cover a range of attack vectors and user environments.

Cisco Talos, the company’s threat intelligence team, contributed further insight into the threat landscape. Their research highlighted identity-based attacks as the most common vector for breaches. Phishing, credential theft and misuse of legitimate accounts were involved in 60% of incident response cases, underscoring the need for strong identity protection such as multi-factor authentication (MFA) and Zero Trust architectures.

The report warns that threats are highly dynamic, often appearing in waves. For instance, when Trojan activity recedes, ransomware may rise. This ebb and flow suggests attackers regroup and shift tactics rapidly, sometimes even repurposing existing access or tools for new campaigns. This kind of fluidity requires defenders to remain agile, adapting their strategies based on threat intelligence and real-time visibility into network behaviour.

Organisations that deploy DNS-layer security in conjunction with endpoint and identity-based defenses are better positioned to detect and prevent threats. DNS filtering catches malicious domains before connections are made; endpoint tools stop payload execution and lateral movement; and identity safeguards limit attackers’ ability to exploit user accounts.

Cisco’s report aligns with broader industry trends. Other analysts, such as those from Deloitte and Gartner, have identified ransomware, social engineering and increasingly sophisticated threat actors as top challenges. Gartner, in particular, recommends a layered, AI-augmented defense model, echoing Cisco’s approach to integrating DNS intelligence with other security technologies.

The report delivers a clear message: defenders must combine deep visibility with multi-layered defenses to keep pace with rapidly evolving threats. DNS-layer protection offers a unique early-warning capability but it is most effective when part of a broader strategy that includes endpoint protection, cloud security, identity management and robust incident response. As attackers continue to shift tactics from data theft to ransomware to stealthy persistence, defenders must stay informed, proactive and flexible in their security architecture. The digital threat landscape is constantly changing and only by integrating intelligence, technology and strategy can organisations stay one step ahead.

To read the full report visit www.instrumentation.co.za/ex/cisco_cyberthreat_trends.pdf




Share this article:
Share via emailShare via LinkedInPrint this page

Further reading:

Why choose between Capex and Opex if you can Totex?
Schneider Electric South Africa IT in Manufacturing
In a sector marked by cyclical demand, high capital intensity, and increasing regulatory and sustainability pressures, mining, minerals and metals (MMM) companies are re-evaluating how they approach procurement and investment.

Read more...
AI and the smart factory
Schneider Electric South Africa IT in Manufacturing
Imagine walking into a factory where machines can think ahead, predict problems before they happen and automatically make adjustments to realise peak performance. This isn’t science fiction, it’s happening right now as AI continues to transform how we run industrial operations.

Read more...
Why your supply chain should be a competitive advantage
Schneider Electric South Africa IT in Manufacturing
The last five years have placed unprecedented strain on global supply chains. Leading companies are turning the challenge into an opportunity to transform their supply chains into a competitive advantage.

Read more...
Why AI will never truly understand machines
Wearcheck IT in Manufacturing
Cutting-edge technology and solutions powered by AI are embraced by specialist condition monitoring company, WearCheck, where the extreme accuracy of data used to assess and diagnose machine health is paramount.

Read more...
Buildings and microgrids for a greener future
Schneider Electric South Africa IT in Manufacturing
Buildings are no longer passive consumers of power. Structures of almost every size are evolving into dynamic energy ecosystems capable of generating, storing and distributing their own electricity. Forming part of this exciting transformation are microgrids.

Read more...
Traditional data centres are not fit for purpose
IT in Manufacturing
Traditional data centre designs are falling short, with nearly half of IT leaders admitting their current infrastructure does not support energy or carbon-reduction goals. New research commissioned by Lenovo reveals that data centre design must evolve to future-proof businesses.

Read more...
AI agents for digital environment management in SA
IT in Manufacturing
The conversation about artificial intelligence in South Africa has shifted rapidly over the past year. Among the technologies changing the pace of business are AI agents - autonomous, task-driven systems designed to operate with limited human input.

Read more...
AI-powered maintenance in future-ready data centres
Schneider Electric South Africa IT in Manufacturing
The data centre marketplace often still relies on outdated maintenance methods to manage mission-critical equipment. Condition-Based Maintenance (CBM) is powered by AI and is fast becoming a necessity in ensuring both competitiveness and resilience.

Read more...
Powering up data centre mega development
IT in Manufacturing
Parker Hannifin has secured a major contract to supply key equipment for nearly 30 aeroderivative gas turbines powering a new hyperscale data centre in Texas.

Read more...
Building resilient supply chains through smarter e-procurement
RS South Africa IT in Manufacturing
In a time of constant disruption, from supply chain uncertainty to rising operational costs, businesses that embrace digital procurement are better positioned to stay competitive and resilient.

Read more...









While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd | All Rights Reserved