ATNS Malware Attack Hits South Africa Air Traffic Network
Malware Found in a Weather Services Network
Malware has entered the operational technology (OT) network of Air Traffic and Navigation Services (ATNS), the South African operator. That network supports weather services for air traffic control.
A preliminary analysis tied the malware to the early stages of ransomware attacks. Monitoring tools also recorded possible data transfers to external IP addresses in China. ATNS says it has contained the incident and removed the malware. However, it now seeks independent specialists to establish the true scale of the compromise.
The Details Came From a Tender
The details did not come from an attack press release. They came from a tender notice that ATNS published for digital forensics work. The tender document is dated September 18, 2026.
The exact date of the intrusion remains undisclosed. So do the malware family and the suspected group.
No Confirmed Impact on Flights
No confirmed takeover of systems that directly control aircraft movement has surfaced. ATNS found suspicious activity in the OT environment that serves weather services for Air Traffic Services.
No public evidence shows canceled flights, halted air traffic control, or a flight safety threat from the incident.
What Forensic Experts Must Establish
The specialists must answer several questions. How did the attackers get in? Which systems did the intrusion touch, directly or indirectly? How long did the attackers stay inside the network? Did data actually leak?
The terms of reference also require an assessment of the possible effect on business continuity. They cover services tied to flight safety as well.
The China Connection
The link to China needs special care. The ATNS documents speak only of possible data transfers to external IP addresses located in China.
The company does not tie the attack to Chinese authorities, intelligence services, or a specific hacking group. In any case, the location of destination servers alone cannot identify the attackers.
Which Airports Are Involved
The main episode concerns the site coded FAPE. That is the ICAO code of Chief Dawid Stuurman International Airport in Gqeberha. However, the forensic terms cover the OT systems of both FAPE and FAEL. Therefore, specialists must also check the infrastructure of King Phalo Airport in East London. The document itself does not confirm that both sites were compromised.
A Separate Insider Probe at FAMM
In parallel, ATNS is investigating a separate episode at FAMM. According to internal reports, staff may have accessed personal data without permission. They may also have moved information out of company systems. An initial check could not confirm the claims.
Independent experts will study activity logs and the computers of the employees tied to the episode. They must establish whether copying, transfer, or theft of data took place.
A note on sources: Dark Reading’s original article named FAMM as Maputo airport in Mozambique. Yet the code does not belong to Maputo International Airport. By ATNS’s official directory, FAMM means Mafikeng in South Africa. Thus, both episodes in the published ATNS documents involve South African infrastructure.
Why the Scale Matters
The operator’s size makes an OT intrusion notable, even without confirmed impact on flights. ATNS serves air traffic and navigation systems at 21 South African aerodromes. It also supports aviation satellite networks in dozens of countries across Africa and the Middle East.
Ransomware Interest in Aviation Is Rising
The attack comes as ransomware gangs show growing interest in aviation. According to Thales, ransomware attacks on aviation organizations rose about sixfold in 2025 over the prior year. The firm counted 27 major ransomware incidents in the 16 months to April 2025.
The ATNS case cannot yet count as a completed ransomware attack with encrypted systems. Public data confirm the discovery of malware typical of an early stage in such operations. Final conclusions must come from the digital forensics experts.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.