logo

Russia-Linked Threats to Operational Technology

ID: 25b616f2-8763-5f2e-825f-70d8587bcacd

STIX ID: report--25b616f2-8763-5f2e-825f-70d8587bcacd

Feed Name: ReliaQuest Blog

Threat Score
88/100

Date Published: 2024-05-14

Date Updated: 2026-04-29

...
...

This report analyzes Russia-linked threat activity against operational technology over the past 12 months, detailing coordinated campaigns (Sandworm, APT29), OT-targeted malware (Industroyer, Industroyer2, COSMICENERGY), ransomware incidents (DarkSide, Black Basta), exploited CVEs (including JetBrains TeamCity and Zyxel firewall flaws), and observed TTPs used to pivot from IT to OT. It provides detection rules, IoC integration guidance, and practical mitigation recommendations (network segregation, MFA, patching, access controls) aimed at reducing risk to OT environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.