Skip to content

Zscaler warns industrial operations face mounting risk as IoT, OT attacks surge across ...

Industrialcyber.Co November 11, 2025

Zscaler ThreatLabz reported a 67% surge in Android malware, with 40% of IoT attacks now targeting critical industries and hybrid work environments. Critical infrastructure in the energy sector experienced a 387% increase in attacks compared to the year. This comes as mobile, IoT, and OT (operational technology) systems have become the backbone of business operations today, enabling innovation and powering critical infrastructure across industries. While mobile devices dominate global connectivity, IoT and OT systems keep manufacturing, healthcare , transportation, and smart cities running.

“Cellular-connected IoT devices are central to this transformation, enabling expansive operational use cases, but simultaneously exposing organizations to new and evolving threats,” according to the ‘Zscaler ThreatLabz 2025 Mobile, IoT & OT Threat Report.’ “Threat actors are taking advantage of this expanding web of connectivity and interdependence, targeting vulnerabilities in mobile devices, IoT systems, and legacy OT environments. Over the past year, notable attacks ranged from sophisticated Android malware campaigns to nation-state operations like Volt Typhoon and Salt Typhoon, which exploit public-facing infrastructure for espionage, sabotage, and disruption. This threat activity is amplified by IoT botnets that automate attacks across unpatched or misconfigured devices.”

The report identified that as organizations across industries embrace IoT and OT technologies to drive efficiency, productivity, and automation, cyberthreat actors are adapting their approaches to exploit vulnerabilities in these increasingly interconnected systems.

Recent projections estimate that the number of IoT devices worldwide will double from 19.8 billion in 2025 to more than 40.6 billion by 2034, highlighting the critical role these devices play in modern infrastructure. From smart sensors optimizing manufacturing processes to connected cameras monitoring remote sites, IoT and OT ecosystems have become foundational to operations in sectors such as logistics, energy, healthcare , and automotive.

It recognized that the widespread integration of IoT and OT systems into essential workflows significantly raises the stakes for cybersecurity. “Many of these devices are embedded in environments with unique challenges, such as ruggedized ecosystems in harsh conditions or legacy systems dependent on outdated protocols. This creates fertile ground for attackers to exploit weaknesses, target unpatched vulnerabilities, and leverage IoT endpoints to breach corporate networks or disrupt operations. Just as Bring Your Own Device (BYOD) policies have expanded attack surfaces for mobile endpoints, IoT’s exponential growth and diverse applications have similarly transformed the threat landscape.”

Moreover, with malicious hackers employing tactics such as IoT botnets , command injection vulnerabilities, and SIM misuse, this report sheds light on how adversaries are increasingly targeting these systems. Understanding these evolving risks is crucial for organizations to strengthen defenses and protect the critical infrastructure built on IoT and OT technologies.

Year after year, ThreatLabz has observed that routers are a primary target for IoT exploitation. Threat actors use vulnerabilities to execute commands, propagate malware, and expand botnets. Netgear routers are an especially popular target for threat actors, with common exploitation methods observed, including command injection via API endpoint URLs and directory traversal techniques to access sensitive subdirectories. These attacks often exploit unauthenticated remote code execution (RCE) vulnerabilities that allow hackers to bypass authentication and execute scripts remotely.

Payloads like Mirai , the most popular malware targeting IoT devices, are frequently deployed to recruit compromised devices into botnets, which then enable network-wide control for DDoS (distributed denial of service) attacks or further propagation. Additional exploits, such as those targeting ‘Parks Fiberlike’ and D-Link routers, indicate that the ongoing trend of threat actors exploiting routers shows no signs of slowing down.

The report also noted that IoT-based botnets continue to exploit weak router configurations and firmware vulnerabilities to automate their propagation. Threat actors use shell commands to delete files, download malicious payloads with wget or curl, and set permissions. These vulnerabilities are exploited to further recruit more vulnerable devices into the botnet. Infected devices are often observed beaconing to C2 servers or sending out traffic containing exploits to further recruit devices, providing evidence of their activation as botnet nodes.

Zscaler identified that the manufacturing and transportation sectors continued to top the list of most-targeted verticals. “This year, both sectors accounted for an equal 20.2% of all observed IoT malware attacks, jointly making up over 40% of total incidents. This represents a shift from 2024, when Manufacturing alone bore the brunt with 36%, followed by Transportation at 14% and Food & Beverage at 11%. The current distribution suggests that while Manufacturing remains a critical target, threat actors are increasingly spreading their efforts across other high-dependency IoT industries.”

In an analysis of global IoT threats, the U.S. emerged as the primary target, absorbing a striking 54% of all detected IoT attacks. This substantial figure underscores the critical vulnerability of US-based IoT infrastructure. Following the US, Hong Kong experienced a notable 15% of these attacks, highlighting its position as a secondary, yet still significant, target for malicious IoT actors. Along with that, China, India, and Germany saw IoT malware activities as well.

The U.S. remains the leading destination for IoT device traffic, handling 62.97% of overall transactions, reaffirming its critical role in global IoT infrastructure and communications. This dominant position highlights the U.S. as both a hub for IoT activity and a primary target for malware attacks. The U.K. follows at 9.60%, with Australia (6.99%) and France (6.87%) contributing notable shares. While countries like Thailand (0.99%), Germany (0.92%), and Switzerland (0.91%) account for smaller portions, their presence underscores the growing geographical distribution of IoT activity. This diversification reflects an expanding IoT ecosystem worldwide, presenting both opportunities and risks across global markets.

Zscaler reported that federal agencies and the public sector face mounting cybersecurity risks as interconnected mobile, IoT, and OT systems become vital to delivering essential services. The government sector recorded a 370% surge in IoT malware attacks and a 147% rise in mobile-related incidents, largely fueled by the spread of Android malware targeting devices critical to public operations. The energy sector saw an unprecedented 387% jump in attacks, highlighting the relentless targeting of critical infrastructure, while healthcare experienced a nearly 225% increase in mobile attacks, driven by the value of sensitive patient data and the need for uninterrupted public health services.

The report also mentioned that legacy IoT and OT systems often lack modern security controls, making them prime targets for ransomware and state- threats. Nation-state actors such as Volt Typhoon deploy stealthy techniques to infiltrate government networks and maintain persistence, while Salt Typhoon uses weaponized IoT devices, including public routers and cellular-connected sensors, to gain access and facilitate lateral movement through critical infrastructures. In parallel, botnet families like Mirai, Mozi, and Gafgyt exploit IoT vulnerabilities, amplifying risks across increasingly integrated systems.

Meanwhile, attacks targeting critical infrastructure sectors, including water treatment facilities, energy grids, and transportation networks, highlight the need for securing ruggedized IoT and cellular-connected devices to ensure continuity even in situations.

Supply chain vulnerabilities further complicate the security landscape, as compromised hardware, firmware, or third-party dependencies introduce new entry points for attackers. Securing cellular-connected devices with SIM-level traffic inspection mitigates unauthorized access and reduces the attack surface associated with insecure IoT adoption. Mobile endpoints, widely used in government applications, face escalating risks from phishing, smishing, and exploitation of telecom stacks.

The report observed that enforcing zero trust policies for device connections and applying anomaly detection for network traffic are critical steps to manage these risks. To address these challenges, federal agencies must apply zero trust architectures, advanced segmentation for IoT/OT devices, and proactive monitoring to counter rising threats. Embedding security across cellular networks, legacy systems, and public-facing devices is essential to securing sensitive information, maintaining operational resilience, and ensuring compliance with federal cybersecurity standards.

As part of its 2026 predictions, Zscaler reported that AI-driven exploits will continue to expand, with AI tools accelerating the creation of hyper-targeted phishing campaigns. Smishing and vishing attacks will increasingly leverage AI models to mimic real people and trusted brands in order to compromise mobile devices. Enterprises will need AI-driven defenses to identify and stop these highly advanced threats.

Public and private 5G networks will remain vulnerable without strong zero trust models. As cellular IoT and mobile networks continue to grow, they will require zero trust frameworks to protect these ecosystems at the core. Security will need to be embedded at the SIM or eSIM level, enabling precise, context-aware controls based on identity, location, behavior, or risk. For instance, SIMs can be restricted to operate only within specific countries or regions, preventing unauthorized roaming or data exfiltration. Anomaly detection can flag or block suspicious activity, such as attempts to access disallowed resources or connect from unexpected locations, ensuring consistent protection across the globe without operational overhead.

Mobile applications will increasingly serve as supply chain attack vectors, with attackers compromising third-party mobile app development pipelines to inject malicious code into widely trusted apps. Continuous analysis of all app permissions and behaviors will become a security standard to detect and prevent such compromises.

IoT and OT ransomware attacks targeting critical sectors will persist, particularly in industries such as manufacturing, energy, and healthcare, which are heavily reliant on interconnected environments. These sectors will remain high-priority targets for ransomware campaigns that exploit network interdependencies and disrupt essential services.

It also noted that zero trust segmentation will become increasingly integrated into IoT and OT environments as enterprises isolate devices into granular layers using zero trust frameworks. Each device or group of devices will have its own validation requirements, helping to block lateral movement when systems are compromised while maintaining continuous compliance.

Enterprises will also move toward consolidating IoT, OT, and mobile device security into unified platforms. These integrated systems will deliver end-to-end zero trust enforcement, device microsegmentation, AI-based anomaly detection, and enhanced visibility across edge, cloud, and 5G networks.

Organizations will expand the adoption of zero trust frameworks for routers and edge devices to prevent botnet propagation and defend against persistent attacks. Public-facing devices such as routers and gateways will be segmented into isolated operational zones and authenticated before any communication with broader enterprise networks, with continuous behavioral analysis used to validate their security posture.