Russia-Linked Threats to Operational Technology
ID: 25b616f2-8763-5f2e-825f-70d8587bcacd
STIX ID: report--25b616f2-8763-5f2e-825f-70d8587bcacd
Feed Name: ReliaQuest Blog
This report analyzes Russia-linked threat activity against operational technology over the past 12 months, detailing coordinated campaigns (Sandworm, APT29), OT-targeted malware (Industroyer, Industroyer2, COSMICENERGY), ransomware incidents (DarkSide, Black Basta), exploited CVEs (including JetBrains TeamCity and Zyxel firewall flaws), and observed TTPs used to pivot from IT to OT. It provides detection rules, IoC integration guidance, and practical mitigation recommendations (network segregation, MFA, patching, access controls) aimed at reducing risk to OT environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
