South African Air Traffic Operator Investigates Ransomware-Linked Malware in OT Network

South Africa's air traffic operator is investigating ransomware-linked malware discovered in an operational technology environment supporting aviation weather services.
South African airport control tower at sunset with Table Mountain in the background and red cybersecurity alert markers highlighting the tower.

South Africa’s state-owned Air Traffic and Navigation Services is investigating a cybersecurity incident involving ransomware-linked malware discovered inside an operational technology environment supporting weather-related services used by air traffic operations.

The incident was disclosed through procurement documents published by Air Traffic and Navigation Services, known as ATNS, as the organization sought an independent digital forensics provider to determine how the malware entered its environment, establish the extent of the compromise and investigate whether information was exfiltrated.

The affected environment is associated with FAPE, the aviation identifier for Chief Dawid Stuurman International Airport in Gqeberha, formerly Port Elizabeth.

ATNS said its internal team contained the incident and removed the identified malware. However, questions remain about the initial access vector, full scope of the intrusion and whether additional risks remain within the environment.

Malware reached operational technology environment

According to ATNS procurement documents, suspicious activity was detected within operational technology systems supporting weather-related services provided to Air Traffic Services.

Investigators identified malware associated with early-stage ransomware activity inside the environment.

The available information does not establish that ransomware encryption occurred or that air traffic control systems were encrypted. ATNS instead describes malware linked to the early stages of ransomware activity, making the distinction important when assessing the operational impact.

The organization’s internal security team contained the activity and removed the malware, but ATNS determined that an independent forensic investigation was needed to establish the root cause and extent of the compromise.

The investigation is expected to examine affected systems, determine the attack vector, reconstruct the incident timeline, analyze the malware and identify any remaining indicators of compromise.

Possible data exfiltration to IP addresses in China

ATNS documentation also identifies possible data exfiltration to external IP addresses located in China as an issue requiring further investigation.

That finding does not establish that a Chinese threat actor conducted the intrusion. The geographic location of an IP address alone cannot reliably determine who controlled the infrastructure or where an attacker was physically located.

The forensic investigation is intended to determine whether data actually left ATNS systems, identify the affected information if exfiltration occurred and establish the infrastructure involved.

ATNS has not publicly attributed the malware incident to a ransomware operation, cybercriminal group or nation-state actor.

Aviation weather systems create operational concerns

The presence of ransomware-linked malware within an operational technology environment is particularly significant because the affected systems support weather-related services used by Air Traffic Services.

Aviation weather information contributes to flight planning and safe air traffic operations by providing information about conditions that can affect aircraft and airport operations.

The available ATNS documents do not indicate that the malware disrupted flights, air traffic control or safety-critical radar systems. They also do not establish that an attacker manipulated weather information.

However, the incident demonstrates how cyber threats reaching supporting operational technology can create risks beyond traditional corporate IT environments, particularly when those systems contribute information used for critical infrastructure operations.

ATNS sought investigators capable of handling operational technology malware forensics, reverse engineering malicious software, preserving evidence and producing findings suitable for legal, disciplinary and regulatory proceedings.

Separate alleged data theft also under investigation

The same ATNS procurement process covers a second cybersecurity matter involving alleged unauthorized access and data theft at FAMM, the aviation identifier associated with Mahikeng Airport.

ATNS said it received reports that employees may have unlawfully accessed and exfiltrated personal information.

Initial investigations did not conclusively establish what occurred, leading the organization to seek an independent examination of user activity, endpoints and potential data exfiltration.

The investigation is expected to determine whether unauthorized access occurred, identify information that may have been removed and assess whether internal policies or data protection requirements were violated.

Publicly available information does not establish that the alleged FAMM insider activity is connected to the ransomware-linked malware discovered in the FAPE operational technology environment.

ATNS seeks independent forensic findings

ATNS formally sought a digital forensics provider in September to investigate both incidents. The procurement was subsequently re-advertised, with the latest tender closing on Sept. 25.

The requested work includes digital evidence collection and preservation, malware analysis, forensic examination, data exfiltration analysis and the production of legally defensible reports.

The investigation is also expected to provide recommendations for remediation and measures intended to reduce the likelihood of similar incidents.

ATNS has not publicly disclosed the ransomware family associated with the malware, the suspected initial access method, when attackers first entered the environment or what information may have been accessed.

No threat actor has been publicly attributed to the incident, and the available evidence does not establish that ransomware was successfully deployed beyond the early-stage activity identified by ATNS.

The forensic investigation should provide a clearer picture of whether the incident remained limited to the detected malware or whether attackers established broader access to the aviation technology environment.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site →