IT in Manufacturing


From Trojan takeovers to ransomware roulette

July 2025 IT in Manufacturing

Cisco’s Cyber Threat Trends Report offers a comprehensive and overview of the evolving cyber security landscape, leveraging its vast global reach through the analysis of DNS traffic. With visibility into over 715 billion DNS requests daily, Cisco provides a unique perspective into malicious activity across the internet. The report draws on eight months of DNS-layer data from August 2023 to March 2024 collected via Cisco Umbrella, and presents a detailed analysis of trends across various categories of threats.

The findings reveal that information stealers were the most frequently detected threat type throughout the reporting period. These are tools and malware designed to exfiltrate data such as documents, video and audio from compromised systems. Their activity was not constant but followed a wave-like pattern, with periods of intense detection followed by relative quiet. Cisco suggests that this lull may reflect operational pauses, during which attackers analyse and monetise stolen data before launching new campaigns.

In contrast, Trojan activity showed a notable decline over the same time span. Trojans, often used to gain an initial foothold in a network, started off strong but decreased significantly in later months. However, this did not signal an overall drop in cyber threats. Instead, ransomware activity surged dramatically in January 2024 and remained high into March. Cisco theorises that this shift reflects a tactical relationship between Trojans and ransomware. Frequently, threat actors deploy a Trojan first to establish access and later use that access to deliver ransomware payloads, encrypting data and extorting victims for payment.

The report also observed fluctuating activity in other threat categories, including remote access Trojans (RATs), advanced persistent threats (APTs), botnets, droppers and backdoors. Each showed distinct patterns of DNS behaviour and seasonal variation. RATs and APTs, in particular, represented more targeted and stealthy attack strategies that are harder to detect through traditional security tools but still leave traces at the DNS layer.

A central theme in the report is the critical role of DNS in modern cyber attacks. Almost all malware needs to make a DNS request to reach a command-and-control server, download payloads or exfiltrate data. By monitoring DNS queries, defenders can identify suspicious behaviours early, often before the actual attack fully unfolds. Cisco Umbrella, for example, blocks more than one million malicious domains every hour by detecting these behaviours in real time. DNS-layer protection can therefore act as a crucial frontline defense, stopping threats before they reach internal systems.

In addition to DNS protection, Cisco emphasises the importance of a layered security approach. This involves combining DNS-level filtering with endpoint security technologies such as antivirus, endpoint detection and response tools. A defense-in-depth strategy is essential because even if one control fails, others can catch the threat before it causes damage. Cisco compares this to having multiple bouncers at a club. If one misses an intruder, another can intervene. Their broader security stack, including Cisco Secure Access, integrates services such as secure web gateway (SWG), cloud access security broker (CASB), zero trust network access (ZTNA), remote browser isolation, data loss prevention (DLP) and malware detection to cover a range of attack vectors and user environments.

Cisco Talos, the company’s threat intelligence team, contributed further insight into the threat landscape. Their research highlighted identity-based attacks as the most common vector for breaches. Phishing, credential theft and misuse of legitimate accounts were involved in 60% of incident response cases, underscoring the need for strong identity protection such as multi-factor authentication (MFA) and Zero Trust architectures.

The report warns that threats are highly dynamic, often appearing in waves. For instance, when Trojan activity recedes, ransomware may rise. This ebb and flow suggests attackers regroup and shift tactics rapidly, sometimes even repurposing existing access or tools for new campaigns. This kind of fluidity requires defenders to remain agile, adapting their strategies based on threat intelligence and real-time visibility into network behaviour.

Organisations that deploy DNS-layer security in conjunction with endpoint and identity-based defenses are better positioned to detect and prevent threats. DNS filtering catches malicious domains before connections are made; endpoint tools stop payload execution and lateral movement; and identity safeguards limit attackers’ ability to exploit user accounts.

Cisco’s report aligns with broader industry trends. Other analysts, such as those from Deloitte and Gartner, have identified ransomware, social engineering and increasingly sophisticated threat actors as top challenges. Gartner, in particular, recommends a layered, AI-augmented defense model, echoing Cisco’s approach to integrating DNS intelligence with other security technologies.

The report delivers a clear message: defenders must combine deep visibility with multi-layered defenses to keep pace with rapidly evolving threats. DNS-layer protection offers a unique early-warning capability but it is most effective when part of a broader strategy that includes endpoint protection, cloud security, identity management and robust incident response. As attackers continue to shift tactics from data theft to ransomware to stealthy persistence, defenders must stay informed, proactive and flexible in their security architecture. The digital threat landscape is constantly changing and only by integrating intelligence, technology and strategy can organisations stay one step ahead.

To read the full report visit www.instrumentation.co.za/ex/cisco_cyberthreat_trends.pdf




Share this article:
Share via emailShare via LinkedInPrint this page

Further reading:

Siemens democratises AI-driven PCB design for small and medium electronics teams
Siemens South Africa IT in Manufacturing
Siemens Digital Industries Software is making its AI-enhanced electronic systems design technology more accessible to small and mid-sized businesses with PADS Pro Essentials software and Xpedition Standard software.

Read more...
Siemens’ PAVE360 to support new Arm Zena Compute Subsystems
IT in Manufacturing
Siemens Digital Industries Software is expanding its longstanding relationship with Arm and adding support for the newly launched Arm Zena Compute Subsystems in its PAVE360 software, designed for software-defined vehicles

Read more...
Empowering OEMs in industrial automation
Schneider Electric South Africa IT in Manufacturing
Organisations are increasingly focusing on empowering OEMs within the industrial automation sector

Read more...
Fortifying the state in a time of cyber siege
IT in Manufacturing
In an era where borders are no longer physical, South Africa is being drawn into a new kind of conflict, one fought not with tanks and missiles, but with lines of code and silent intrusions. The digital battlefield is here, and cyber space has become the next frontier of conflict.

Read more...
Levelling up workplace safety - how gamification is changing the rules of training
IT in Manufacturing
Despite the best intentions, traditional safety training often falls short, with curricula either being too generic, too passive, or ultimately unmemorable. Enter gamification, a shift in training that is redefining how businesses train for safety and live by those principles.

Read more...
Reinventing data centre design: critical changes to meet surging
Schneider Electric South Africa IT in Manufacturing
AI technologies are pushing the boundaries of what is possible which, in turn, is presenting data centres with a whole new set of challenges. Fortunately, several options are emerging which include optimising design and infrastructure for efficiency, cooling and management systems

Read more...
Watts next - can IT save the planet
IT in Manufacturing
The digital age’s insatiable demand for computing power has collided with an urgent and pressing need for sustainability. As data centres and AI workloads consume unprecedented energy, IT providers are pivotal in redefining how technology intersects with environmental stewardship.

Read more...
South Africa’s digital revolution:
IT in Manufacturing
South Africa stands at a pivotal moment in its technological evolution, poised to redefine itself as Africa’s leading digital powerhouse. Over the past two years, political leaders and media narratives have painted a picture of rapid digital transformation, underscoring the government’s ambition to position South Africa at the forefront of innovation.

Read more...
Smart manufacturing, APC and the SA marketplace
Schneider Electric South Africa IT in Manufacturing
Manufacturers are prioritising the integration of smart technologies into their daily operations to stay one step ahead of the competition. In South Africa, some experts believe the country has the potential to leapfrog its global peers through the creation of smart factories.

Read more...
Schneider Electric’s Five-Pillar Strategy takes the guesswork out of equip
Schneider Electric South Africa IT in Manufacturing
Schneider Electric’s Field Service Cycle, otherwise known as the Five-Pillar Strategy, is a structured approach to managing the lifecycle of equipment to prolong asset lifespan while reducing the total cost of ownership for customers.

Read more...









While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd | All Rights Reserved