Security2 publishers2 min readPublished
Ransomware tooling turns up in weather OT at South Africa's air traffic operator
South Africa's ATNS, which runs air traffic control for about 10% of the world's airspace, found early-stage ransomware tooling in a weather OT network. The state operator says its team stopped the attack yet is seeking outside forensics to learn how the attackers got in.
The Watch · Security desk

What happened
- The OT intrusion was at Port Elizabeth Airport, and a possible insider theft of data at Maputo International Airport in Mozambique is part of the same investigation request.
- The service request is unclear on whether East London Airport was also affected by the OT compromise.
- ATNS technical teams found signs of data exfiltration to external IP addresses located in China, according to the request.
- ATNS wants forensic services to begin Sept. 18, and the documents do not make clear when the intrusion itself took place.
- Thales counted a sixfold rise in ransomware attacks on aviation in 2025 and 27 major attacks on aviation firms in the 16 months to April 2025.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Air navigation providers now have a documented case of ransomware tooling in OT that serves controllers. Weather and support networks belong in the same threat model as business IT.
- contradiction ATNS says the attack was stopped, but its own tender lists the extent of compromise as undetermined. Until the forensic report, any public statement about scope stays provisional.
- constraint Operators checking for the same intruder have only the tender documents to work from, because ATNS did not answer Dark Reading's questions.
ATNS described the affected systems as operational technology "supporting weather-related services to Air Traffic Services" [6]. Controllers depend on that data. The request, as Dark Reading reported it, places the tooling in that weather environment [6]. Attackers reached operational systems at an air navigation provider, on the support side of air traffic control [2].
ATNS wrote: "Preliminary investigations identified malware commonly associated with the early stages of ransomware attacks." [7] I'd read that as a foothold staged for encryption. At that stage the responder's open question is dwell time: how long the attacker sat in the network and what else they touched. ATNS believes its technical team stopped the attack [3].
ATNS's own word for the China-located exfiltration evidence is "suggestions" [8].
"Internal technical teams have implemented containment measures and malware removal," ATNS wrote in the request [11]. "[H]owever, a comprehensive forensic investigation is required to determine the root cause, extent of compromise, and any remaining risks." [12]
Two outside voices speak to the wider pattern, though neither ties ATNS to a named group or campaign. "Since the start of 2024, at least eight national government departments and public entities have suffered confirmed cyber incidents, and aviation-related organizations are now part of that pattern," said Hendrik de Bruin, head of security consulting for Africa at Check Point [17]. Avinash Singh, a lecturer in computer science at the University of Pretoria, said aviation systems are popular targets because the impact is often impossible to hide, adding that "grounded flights and stranded passengers cannot be hidden." [19]
Check Point's weekly count puts South African organizations at an average of 2,086 attacks a week against a global average of 2,422 [16], about 14% lower [1]. That figure has little bearing on how tooling reached an ATC operator's weather network. De Bruin's more relevant point is that compliance checks prove controls exist on paper, while attackers test whether they work in practice [18].
What to watch
- Whether the forensic investigation links the possible insider data theft at Maputo to the Port Elizabeth OT intrusion.
- A ransomware group posting ATNS data on a leak site would confirm the exfiltration and put a name to the actor.
- Whether the root-cause finding shows the attackers entered through ATNS business IT or directly into the weather OT.