Verticals Targeted: Critical Infrastructure, Defense
Regions Targeted: United States
Related Threat Actors: Volt Typhoon, QTFY, CyberAv3ngers, FSB Center 16, GRU Unit 29155, Cyber Army of Russia Reborn, NoName057(16), Z-Pentest, Sector16
Executive Summary
US critical infrastructure faces an increasingly consequential operational technology (OT) threat as state-sponsored and other cyber actors conduct activity ranging from long-term pre-positioning in critical infrastructure networks to direct exploitation of programmable logic controllers (PLCs) capable of affecting physical processes. Of particular national-security concern, military installations depend on civilian electricity, water, telecommunications, transportation, fuel, manufacturing, and logistics infrastructure located outside Department of War networks and installation boundaries. Disruption of these systems could therefore create military effects without direct compromise of a military installation.
Key Takeaways
- US military installations depend on civilian critical infrastructure beyond the installation perimeter, including electricity, water, telecommunications, transportation, fuel, logistics, and industrial suppliers, creating an extended attack surface capable of affecting military readiness and mission execution.
- PRC state-sponsored Volt Typhoon represents a strategic national-security concern because US agencies assess the actor is pre-positioning in critical infrastructure networks to enable OT disruption during a potential crisis or conflict, while Department of War reporting connects PRC cyber capabilities to potential disruption of US military mobilization.
- Recent OT incidents demonstrate that physical disruption does not necessarily require sophisticated ICS malware, with Iranian-affiliated PLC exploitation and the unattributed July 2026 water-sector attacks showing how exposed industrial controllers can contribute to operational disruption and physical-process effects.
- Civilian and military infrastructure risks are interconnected, making dependency mapping, identification of shared infrastructure and single points of failure, reduction of exposed OT, and earlier detection of enterprise-to-OT intrusion pathways important for both public-service resilience and military mission assurance.
Threat Overview
OT controls or monitors physical processes across US water systems, energy infrastructure, transportation, manufacturing, government facilities, and other critical sectors. Unlike compromise of conventional IT, intrusion into OT can extend cyber consequences into the physical environment through disruption of equipment, industrial processes, or essential services. Current reporting demonstrates activity across a continuum, ranging from strategic pre-positioning and capability development to direct OT exploitation, operational disruption, and ultimately physical-process effects.
PRC state-sponsored Volt Typhoon represents the strategic end of that spectrum. CISA, NSA, and FBI assess with high confidence that Volt Typhoon is pre-positioning within US critical infrastructure IT networks to enable disruption of OT functions during a potential crisis or conflict. Compromised organizations span communications, energy, transportation systems, and water and wastewater systems, with some smaller victims providing critical services to larger organizations or key geographic locations.
At the opposite end, attacks beginning July 27, 2026 against water and wastewater utilities in at least seven states produced observable physical consequences. Attackers targeted internet-facing Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs, changing passwords and IP addresses and disrupting operators' ability to monitor or control equipment. Reported physical effects included loss of water pressure and flooding. The FBI warned that sufficiently reduced pressure could potentially allow untreated groundwater to enter water pipes.
Between these extremes are direct exploitation and capability development. Iranian-affiliated actors have exploited internet-facing PLCs across US government, water, and energy organizations, causing operational disruption and financial loss. Separately, NSA reported in August 2026 that actors were conducting targeted reconnaissance and capability development against US-based Siemens S7 PLCs using AI-generated exploitation scripts disguised as legitimate monitoring tools. Targeted technologies are used across manufacturing, energy, water, chemical processing, food and agriculture, and commercial facilities.
The significance of these developments is not that every actor possesses sophisticated ICS malware. Exposed industrial devices, weak authentication, legitimate engineering functionality, insecure remote connectivity, and pathways between IT and OT can allow cyber access to become operational consequence.
Threat Actors and Current Campaigns
US critical infrastructure faces OT risk from several distinct categories of cyber actors. During the October 2023 to October 2026 period, US government reporting has documented direct PLC exploitation by Iranian-affiliated actors, strategic pre-positioning by PRC state-sponsored actors, OT intrusion activity by pro-Russian hacktivists, Russian state-sponsored reconnaissance against critical infrastructure environments, and unattributed campaigns targeting US industrial controllers.
The level of sophistication varies considerably. Some actors appear focused on establishing persistent access that could support disruptive operations during a future geopolitical crisis, while others opportunistically exploit exposed controllers and remote-access systems. The resulting threat ranges from strategic preparation for future conflict to comparatively unsophisticated intrusions capable of producing immediate physical-process effects.
Volt Typhoon
Volt Typhoon represents one of the most significant strategic threats to US critical infrastructure because its activity is explicitly oriented toward establishing access that could support future disruption. CISA, NSA, and FBI assess with high confidence that Volt Typhoon is pre-positioning within US critical infrastructure IT networks to enable disruption of OT functions. US agencies have primarily observed compromises in communications, energy, transportation systems, and water and wastewater systems organizations, including smaller organizations providing critical services to larger entities or strategically important geographic locations.
Rather than relying primarily on distinctive malware, Volt Typhoon uses extensive reconnaissance, exploitation of public-facing infrastructure, valid credentials, and living-off-the-land techniques that can allow malicious activity to blend with legitimate administration. US agencies have identified indications of access persisting within some victim environments for years.
This activity is particularly relevant to military mission assurance. The Department of War's 2025 assessment connects PRC cyber capability development with potential disruption of US military mobilization during a future crisis or conflict. Volt Typhoon therefore illustrates how compromise of civilian infrastructure can provide an adversary with options for generating national-security effects without directly attacking a military installation.
QTFY
QTFY represents a separate China-linked threat to military and critical infrastructure networks. In August 2026, NSA, FBI, and US Cyber Command's Cyber National Mission Force warned that QTFY had developed distributed malicious infrastructure used to compromise US and foreign organizations. The group has targeted strategically significant systems, including the Defense Industrial Base and telecommunications infrastructure.
QTFY employs compromised devices and malicious distributed infrastructure to obscure activity and facilitate exploitation. Government reporting describes development and trading of malware and exploits, maintenance of obfuscation infrastructure, exploitation of zero-day and known vulnerabilities, and acquisition of legitimate credentials.
QTFY should nevertheless be distinguished from actors for which direct OT exploitation has been publicly documented. Available US government reporting establishes targeting of military and critical infrastructure networks but does not currently establish QTFY as a demonstrated US PLC-manipulation or OT-disruption campaign. Its inclusion is therefore based on its proximity to military-supporting and critical infrastructure environments rather than evidence that it has produced physical-process effects.
CyberAv3ngers
CyberAv3ngers provides one of the clearest recent examples of a named actor directly compromising US industrial controllers. Beginning in November 2023, IRGC-affiliated actors operating under the CyberAv3ngers persona targeted internet-connected Unitronics Vision Series PLCs and HMIs. Victims spanned multiple US states and critical infrastructure sectors. Between November 2023 and January 2024, the actors targeted US-based Unitronics devices in approximately four waves and compromised at least 75 devices, including at least 34 within the US Water and Wastewater Systems sector.
The campaign exploited a basic but consequential weakness: internet-accessible devices using default passwords or no passwords. CyberAv3ngers authenticated directly to exposed controllers and made changes intended to disrupt operation and interfere with remediation. Documented activity included erasing original ladder logic, downloading replacement ladder logic, renaming devices, altering software configurations, and changing ports.
The significance of CyberAv3ngers is therefore not primarily technical sophistication. The campaign demonstrates how weakly secured, directly accessible industrial controllers can allow a state-affiliated actor to reach equipment controlling physical processes without requiring highly sophisticated ICS-specific malware. It also demonstrates the risk created when geopolitical targeting criteria intersect with widely deployed industrial technology. The actors specifically targeted Israeli-manufactured Unitronics equipment, meaning US infrastructure became part of a broader geopolitical campaign because vulnerable devices matching the actors' targeting criteria were deployed within US facilities.
Iranian-Affiliated 2026 PLC Activity
A broader Iranian-affiliated OT campaign emerged in 2026. The activity shares historical context and TTP similarities with CyberAv3ngers activity, which the joint advisory specifically references as a similar earlier campaign. However, the US government has not publicly identified the 2026 Iranian-affiliated APT group as explicitly attributed to CyberAv3ngers. The campaigns should therefore remain analytically distinct. In April 2026, FBI, CISA, NSA, EPA, DOE, and US Cyber Command's Cyber National Mission Force warned of ongoing exploitation of internet-connected OT devices across US critical infrastructure. Affected sectors included government services and facilities, water and wastewater systems, and energy.
The actors targeted internet-facing PLCs, including Rockwell Automation/Allen-Bradley equipment, and maliciously interacted with PLC project files. Government reporting documents manipulation of information displayed through HMI and SCADA systems, disruption of PLC operations, operational disruption, and financial loss. Although confirmed victim activity involved Rockwell Automation/Allen-Bradley PLCs, observed targeting of ports associated with other OT protocols led the authoring agencies to assess that the actors may also be targeting other manufacturers' devices, including Siemens S7 PLCs.
The FBI assesses that the actors are targeting exposed PLCs with disruptive intent, while the authoring agencies assess that the broader activity is intended to create disruptive effects in the United States. Together with CyberAv3ngers, this campaign demonstrates persistent Iranian interest in directly accessible industrial controllers and an apparent willingness to interact with systems capable of affecting physical operations.
FSB Center 16 (aka Berserk Bear)
Russian state-sponsored activity remains relevant to US critical infrastructure and OT risk, although current public reporting requires a distinction between direct controller manipulation and reconnaissance or compromise of infrastructure that could facilitate later access. In August 2025, the FBI warned that actors attributed to the Russian Federal Security Service's Center 16 were broadly targeting US and global critical infrastructure. During the preceding year, the FBI observed the actors collecting configuration files from thousands of networking devices associated with US entities across critical infrastructure sectors. The campaign exploited SNMP and vulnerable or end-of-life networking equipment, including Cisco devices affected by CVE-2018-0171. Government reporting also identified reconnaissance indicating interest in industrial control related protocols and applications.
Compromise and reconnaissance of network infrastructure associated with critical infrastructure organizations may create opportunities for subsequent access to environments supporting industrial operations. However, the publicly documented 2025 Center 16 activity should not be characterized as confirmed manipulation of US PLCs or physical processes. Its relevance lies in state-sponsored compromise and reconnaissance of critical infrastructure environments that may contain or support OT.
GRU Unit 29155 (aka Cadet Blizzard)
Russian GRU Unit 29155 represents another state-sponsored critical infrastructure threat, although public reporting similarly supports a more cautious OT characterization. In September 2024, NSA, FBI, CISA, and international partners attributed malicious activity targeting US and global critical infrastructure to actors affiliated with the Russian General Staff Main Intelligence Directorate's 161st Specialist Training Center, Unit 29155. The activity, conducted since at least 2020, has supported espionage, sabotage, and reputational-harm objectives.
The actor's targeting of critical infrastructure and sabotage missions makes it relevant to the broader OT threat environment. However, current public US government reporting does not establish Unit 29155 as responsible for the recent US PLC manipulation campaigns described elsewhere in this bulletin.
Unit 29155 should therefore be understood as a strategic critical infrastructure threat with potential relevance to OT, rather than presented as a demonstrated recent US PLC-disruption actor.
Cyber Army of Russia Reborn
The Cyber Army of Russia Reborn (CARR) represents a substantially more direct Russian-linked OT threat. US and allied agencies assess that actors suspected to be associated with Russian GRU Unit 74455 likely supported CARR's creation in 2022 and funded tools used by the group through at least September 2024. By late 2023, CARR had expanded from DDoS activity into industrial-control-system targeting.
In November 2023, CARR targeted HMI devices and claimed intrusions involving two US dairy farms. The group subsequently collaborated with other pro-Russian actors on OT-focused activity. CARR and related actors typically target inadequately protected, internet-accessible remote management interfaces, particularly VNC-connected HMIs. This lowers the technical barrier to interacting with industrial processes and allows relatively unsophisticated actors to reach systems that can produce real-world consequences. Importantly, US and allied agencies warn that although these actors frequently exaggerate their capabilities and impact, authorities have observed pro-Russian hacktivists willfully causing actual harm to vulnerable critical infrastructure.
NoName057(16)
NoName057(16) has historically been associated primarily with DDoS operations targeting governments and organizations in NATO countries and other states perceived as hostile to Russian interests. Its relevance to OT increased substantially through collaboration with CARR. By mid-2024, NoName057(16) and CARR were operating a joint communication channel. In July 2024, the two groups jointly claimed responsibility for an alleged intrusion against OT assets in the US. Their cooperation subsequently contributed to the formation of the more explicitly OT-focused Z-Pentest group. NoName057(16) should therefore not be portrayed primarily as an OT actor in the same category as Z-Pentest. Its significance is instead its participation in a broader pro-Russian ecosystem in which techniques, personnel, infrastructure, publicity, and targeting knowledge can move between traditional hacktivist operations and groups increasingly focused on industrial systems.
Z-Pentest
Z-Pentest is one of the most important emerging pro-Russian groups for OT defenders. Established in September 2024 from members and administrators associated with CARR and NoName057(16), Z-Pentest specializes in OT intrusion operations against critical infrastructure organizations. Unlike many pro-Russian hacktivist groups that focus heavily on DDoS, Z-Pentest emphasizes claimed OT intrusions, hack-and-leak operations, and defacement activity. The group has posted evidence purporting to show OT device compromises and HMI manipulation and has continued forming relationships with other pro-Russian groups, contributing to propagation of OT intrusion techniques across the ecosystem.
This development is important because it suggests a degree of specialization within the hacktivist environment. Techniques for identifying exposed industrial interfaces and interacting with OT devices no longer remain confined to sophisticated state-sponsored organizations. Z-Pentest demonstrates how relatively accessible methods can be institutionalized within smaller actor communities and repeatedly applied against geographically dispersed infrastructure.
Sector16
Sector16 emerged in January 2025 through collaboration with Z-Pentest and represents another expansion of the pro-Russian OT ecosystem. US and allied government reporting characterizes Sector16 as a relatively novice group that maintains a public presence through which it publishes videos, statements, and claims of compromising US energy infrastructure. The group has aligned itself with pro-Russian narratives and collaborated with more established OT-focused actors.
Government reporting further states that Sector16 members may have received indirect Russian government support in exchange for cyber operations furthering Russian strategic objectives, although the degree of state direction remains less certain than for formal Russian intelligence services. Sector16 illustrates an important characteristic of the current OT threat, in that capability can propagate between groups. Collaboration with more experienced actors can expose relatively inexperienced organizations to techniques and targeting methodologies that increase their ability to interact with vulnerable industrial systems.
Broader Pro-Russian Hacktivist Activity Targeting OT
CARR, NoName057(16), Z-Pentest, Sector16, and affiliated actors should also be understood collectively rather than solely as independent groups. Although individual hacktivist claims should be treated cautiously, US and allied agencies have independently confirmed that this broader actor ecosystem has successfully accessed OT and SCADA environments and caused varying levels of impact, including physical damage. Government reporting also warns that these actors regularly make false or exaggerated claims regarding their activity.
In December 2025, US and allied agencies warned that these actors were exploiting minimally secured, internet-facing VNC connections to access OT control devices. Documented targeted sectors include water and wastewater systems, food and agriculture, and energy, with incidents producing varying levels of consequence.
These groups generally possess less sophisticated capabilities than state-sponsored APTs and may misunderstand the industrial processes they attempt to disrupt. That limitation does not eliminate the threat. In some circumstances, a poor understanding of the physical process may make consequences less predictable, particularly when attackers manipulate equipment without understanding downstream effects. US and allied agencies report that these actors have intentionally attempted to cause physical damage and have willfully caused actual harm to vulnerable critical infrastructure. Their activity reinforces a central theme of the current OT environment: the sophistication of the attacker does not necessarily correspond to the potential consequence of the system being accessed.
Unattributed July 2026 US Water Sector Actors
The July 2026 water sector campaign represents one of the most consequential recent examples of direct cyber interaction with US OT because the activity produced observable physical-process effects.
Beginning July 27, water and wastewater utilities in at least seven states reported incidents involving internet-facing Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs. Attackers changed passwords and network configurations, disrupting operators' ability to monitor or control equipment. At least one affected organization identified modified PLC project files and ladder-logic discrepancies.
Reported operational consequences included loss of water pressure and flooding. The FBI further warned that sufficiently reduced water pressure could allow untreated groundwater to enter distribution systems. Despite similarities to other PLC-focused activity, the US government has not publicly attributed this campaign to Iran, Russia, or another named threat actor. It should therefore remain analytically separate from the Iranian-affiliated 2026 campaign. The activity is particularly significant because it demonstrates the complete progression from an internet-exposed PLC to unauthorized controller access, process manipulation, degraded operations, and ultimately physical effects.
Unattributed Siemens S7 Targeting
A separate 2026 campaign demonstrates continuing adversary development of capabilities against industrial controllers deployed throughout US critical infrastructure. In August 2026, NSA and partner agencies warned that cyber actors were conducting targeted reconnaissance and capability development against US-based Siemens PLCs using AI generated exploitation scripts disguised as legitimate monitoring tools. Targeted technologies are deployed across critical manufacturing, energy generation and distribution, water and wastewater treatment, chemical processing, food and agriculture, and commercial facilities.
NSA warns that successful exploitation of poorly protected controllers could result in industrial-process disruption, safety incidents, equipment damage or downtime, compromise of sensitive information, and cascading effects across interconnected systems. The activity has not been publicly attributed to a specific country or named threat group. It also represents reconnaissance and capability development rather than a publicly confirmed disruptive US campaign. Nevertheless, its targeting of US-based PLC installations and the use of AI-generated exploitation code makes it important as an indicator of how the OT threat landscape is evolving.
Threat Actor Assessment
Taken together, activity observed during the past three years demonstrates that the US OT threat cannot be reduced to a single adversary model. PRC state-sponsored activity presents the clearest strategic pre-positioning threat, particularly where civilian infrastructure supports military mobilization or other national-security missions. Iranian-affiliated actors have demonstrated willingness to directly compromise exposed US PLCs, including activity that interfered with controller logic and operations. Russian and pro-Russian actors span both state-sponsored critical infrastructure reconnaissance and a growing ecosystem of hacktivist groups conducting direct OT intrusions. Meanwhile, the unattributed July 2026 water attacks demonstrate that significant physical-process effects can occur even when the responsible actor and strategic objectives remain unknown.
The principal commonality is therefore not actor identity but access opportunity. Across multiple campaigns, internet-exposed industrial devices, default or weak credentials, insecure remote-management interfaces, vulnerable network infrastructure, and inadequate separation between enterprise and operational environments repeatedly provide paths toward systems capable of affecting physical processes.
Military Mission Assurance and Installation Resilience
Military installations depend on infrastructure extending well beyond Department of War networks and installation boundaries. Commercial electricity, water and wastewater services, telecommunications, transportation networks, fuel distribution, logistics providers, and Defense Industrial Base suppliers can all support mission-essential operations. Department of War guidance specifically identifies energy, communications, transportation, water, and Defense Industrial Base services among the critical infrastructure upon which the department depends. Collectively, these external dependencies create what PolySwarm assesses as an extended installation attack surface. An adversary seeking to degrade military operations may not need to penetrate a military network or compromise installation-owned OT if disruption of civilian infrastructure outside the perimeter can produce a comparable operational effect.
The appropriate military planning question is therefore not limited to whether installation networks and OT systems are adequately defended. Planners should also determine which external infrastructure must remain operational for the installation to accomplish its mission, where that infrastructure is located, who operates it, how it could be disrupted, and how long the installation can continue operating without it.
Identify Mission-Critical External Dependencies
Installations should map external infrastructure dependencies to mission-essential functions rather than treating electricity, water, communications, transportation, and other services as generic dependencies. For each mission-essential function, planners should identify the external services required to sustain it and determine whether alternative providers, routes, systems, or operating methods exist. Particular attention should be given to dependencies whose failure could immediately degrade readiness, command and control, force protection, maintenance, logistics, mobilization, or other operational capabilities.
This analysis should extend beyond first-order dependencies. A military installation may have redundant communications, for example, while both providers depend on the same commercial power infrastructure. Backup generation may sustain installation operations while remaining dependent on external fuel delivery. Water systems may depend on telecommunications for remote monitoring or electricity for pumping. The objective should be to identify dependency chains, not merely individual suppliers.
Evaluate Energy and Installation Power Resilience
Commercial electricity supports communications, security systems, computing, maintenance operations, water and wastewater functions, refrigeration, fuel handling, housing, and numerous other installation activities. Backup generators, microgrids, and other resilient-energy systems can reduce exposure but should not automatically be treated as complete substitutes for commercial power. Their effectiveness depends on available generation capacity, fuel supply, maintenance, control systems, operating duration, and the specific loads they are designed to support.
Installations should determine which mission-essential functions remain operational during an extended commercial power outage, how long those functions can be sustained, and which external dependencies are required to maintain backup generation. Civilian substations, transmission infrastructure, distribution systems, and utilities may therefore be relevant to military mission assurance even when none of those assets are owned or operated by the Department of War.
Assess Water and Wastewater Dependencies
Military installations require reliable water for personnel, sanitation, firefighting, medical operations, cooling, maintenance, food service, and other essential functions. Depending on the installation, these requirements may be supported by installation-owned systems, municipal utilities, regional providers, or a combination of systems. Recent US water-sector incidents demonstrate that cyber access to internet-facing PLCs can contribute to loss of monitoring and control, pressure disruption, flooding, and other physical-process effects. Although the July 2026 attacks noted above have not been linked to military targeting, they demonstrate the type of operational consequence that can result when exposed industrial controllers supporting essential services are compromised.
Military resilience planning should therefore account for both installation-owned water infrastructure and external treatment, pumping, distribution, and wastewater systems upon which the installation depends. Planners should determine how long critical functions can continue following loss or degradation of those services and identify alternatives for the highest-priority requirements.
Account for Communications Dependencies
Commercial fiber, cellular networks, internet services, and other telecommunications infrastructure support personnel, contractors, logistics operations, business functions, remote facilities, and coordination with organizations outside the installation. Communications dependencies can also produce cascading effects. Electric, water, transportation, and fuel providers may themselves rely on telecommunications for remote monitoring, dispatch, maintenance, and restoration activities. A communications disruption can therefore affect military operations both directly and indirectly by degrading other infrastructure upon which the installation depends. Installation dependency assessments should identify common telecommunications infrastructure, shared providers, and other circumstances in which apparently redundant services may ultimately rely on the same underlying systems.
Account for Air Traffic Control and Aviation Infrastructure
Military aviation depends on a broader National Airspace System that integrates civilian and military operations and relies on extensive communications, navigation, surveillance, automation, weather, and supporting infrastructure. FAA systems provide the primary automation used to monitor and guide aircraft through US en-route airspace, while the wider NAS includes hundreds of air traffic control towers, radar and communications facilities, and thousands of geographically distributed sites and systems. This infrastructure has direct national-security significance. FAA communications programs provide infrastructure and enterprise services supporting both the National Airspace System and the Department of War, while FAA NAS Defense Programs provide flight data, surveillance, and communications services supporting military activities, homeland security operations, and national-security events.
Disruption of aviation-related OT and supporting systems could therefore create consequences extending beyond civilian flight operations. Degradation of surveillance, communications, navigation, air traffic automation, weather systems, or supporting power and telecommunications could affect the ability to safely and efficiently manage airspace used for military movement and other national-security missions.
The cyber threat to this environment is also evolving. Recent government assessments identify cyber risks to aviation communications and air traffic systems, including spoofing and jamming, while FAA maintains dedicated cybersecurity incident-detection, reporting, and response requirements for National Airspace System infrastructure.
Military dependency assessments should therefore consider the aviation systems and facilities required to support mission-essential flight operations, including dependencies outside installation boundaries and outside direct Department of War control. Planning should identify the air traffic, communications, navigation, surveillance, power, telecommunications, and other external services required for military aviation operations and evaluate how degradation or loss of those services could affect mission execution. For installations supporting significant aviation missions, the National Airspace System should be considered part of the external infrastructure upon which mission assurance depends.
Protect Transportation, Fuel, and Logistics Continuity
Military operations depend on civilian roads, rail networks, ports, airports, bridges, freight systems, fuel infrastructure, and logistics providers to move personnel, equipment, munitions, replacement parts, fuel, and other materiel. These dependencies become particularly significant during mobilization and sustained operations. The Department of War's 2025 China Military Power Report states that Volt Typhoon demonstrated PRC development of cyber capabilities that could be used during a future crisis or conflict, including capabilities intended to disrupt the US military's ability to mobilize.
Transportation and logistics nodes should therefore be evaluated according to their operational importance even when they are geographically distant from the installation. A port, rail junction, fuel terminal, pipeline facility, bridge, distribution center, or other civilian asset may become militarily significant because of the mission it supports.
Incorporate the Defense Industrial Base and Critical Manufacturing
Military mission assurance also depends on manufacturers, suppliers, technology providers, repair facilities, and specialized industrial organizations throughout the Defense Industrial Base. Cyber disruption affecting these organizations can create military effects without directly targeting an installation. The significance of a supplier should therefore be evaluated according to the military function it supports, availability of substitutes, replacement timelines, and potential downstream effects rather than solely according to the organization's size.
NSA's August 2026 PLC advisory specifically identifies critical manufacturing among targeted sectors and particularly urges PLC owners and operators of National Security Systems throughout the Defense Industrial Base and Department of War to implement recommended protections. This reinforces the need to consider industrial cybersecurity and supply-chain resilience together. A specialized supplier with limited substitutes may represent a nationally significant dependency even if the organization itself would not ordinarily appear to constitute a major strategic target.
Identify Shared Dependencies and Concentration Risk
Particular attention should be given to civilian infrastructure supporting multiple military or national security facilities. A single utility, substation, telecommunications provider, water system, fuel terminal, port, rail junction, transportation corridor, or specialized supplier may support several installations or mission-essential organizations. Disruption of a strategically selected civilian asset supporting multiple defense facilities could potentially affect multiple downstream military functions. Identifying these concentration points allows military planners to prioritize contingency planning according to operational consequence rather than organizational ownership. The physical perimeter of a military installation should therefore not be treated as the perimeter of cyber-enabled mission risk.
Integrate Civilian Infrastructure Disruption Into Mission Planning
Cyber enabled disruption of external infrastructure should be incorporated into continuity planning, exercises, and mission-assurance assessments. Scenarios should consider simultaneous or cascading failures rather than evaluating individual utilities in isolation. Exercises could include combinations such as commercial power loss accompanied by telecommunications disruption, degraded water pressure during a prolonged outage, transportation interruption affecting generator fuel deliveries, or compromise of a critical supplier during mobilization. The objective is not to assume that every external service will fail simultaneously, but to determine where mission execution depends on assumptions about civilian infrastructure availability that have not been adequately tested.
For military planners, the central question is: What does the mission depend on, and how does the mission continue when that dependency is disrupted?
Critical Infrastructure Protection and Cross-Sector Resilience
The same OT threats create a different planning requirement for organizations responsible for protecting US critical infrastructure. Rather than beginning with a military installation and identifying its external dependencies, critical infrastructure defenders should evaluate the downstream consequences associated with the infrastructure they protect.
A utility, telecommunications provider, transportation node, water system, fuel facility, or industrial supplier may serve residential and commercial customers while simultaneously supporting hospitals, emergency services, government facilities, Defense Industrial Base organizations, or military installations.
This creates an important distinction between the cyber victim and the operational victim. The organization whose PLC, HMI, network, or remote-access system is compromised may be only the first affected entity. Operational consequences can propagate to organizations and communities that were never directly targeted. For this reason, critical infrastructure risk should be evaluated not only according to the likelihood of compromise, but also according to what depends on the affected system remaining operational.
Identify National-Security Dependencies on Civilian Infrastructure
Critical infrastructure operators and government partners should identify civilian assets whose disruption could affect military installations, Defense Industrial Base organizations, emergency services, government operations, or other nationally significant functions. This does not require treating every civilian infrastructure asset as a military asset. It requires recognizing that some civilian systems have downstream national-security significance disproportionate to their apparent organizational size or ownership. A small water provider, regional telecommunications facility, electrical substation, specialized manufacturer, fuel distributor, or transportation node may become strategically important because of the organizations it supports. Understanding these relationships can help prioritize limited cybersecurity and resilience resources toward infrastructure whose disruption would produce the greatest downstream consequence.
Prioritize Reduction of Exposed OT
Recent campaigns repeatedly demonstrate the risk associated with internet-accessible industrial controllers and remote-management interfaces. CyberAv3ngers compromised exposed Unitronics PLCs beginning in 2023. Iranian-affiliated actors subsequently targeted internet-facing PLCs across US critical infrastructure in 2026. Pro-Russian actors have exploited minimally secured remote-access interfaces to reach OT environments, while the unattributed July 2026 water-sector campaign affected internet-facing Rockwell Automation/Allen-Bradley MicroLogix controllers and produced physical-process effects.
Reducing unnecessary internet exposure should therefore remain a high priority. Where remote connectivity is operationally necessary, organizations should implement strong authentication, restrict access to authorized systems and users, monitor remote sessions, eliminate default credentials, and ensure that exposed services are not providing broader access than required. Particular attention should be given to systems supporting infrastructure with military, emergency-service, public-health, or other high-consequence downstream dependencies.
Maintain Known Good OT Configurations and Recovery Capability
Recent PLC-focused activity demonstrates that defenders should be prepared not only to detect unauthorized access but also to determine what changed. Organizations should maintain known good controller configurations, PLC project files, ladder logic, firmware information, network settings, and other engineering baselines necessary to identify unauthorized modifications and restore systems. Recovery procedures should account for circumstances in which digital monitoring or remote control is unavailable or untrusted. Operators should understand which critical processes can be operated manually, how long manual operation can be sustained, and which personnel possess the necessary knowledge to do so. These capabilities can reduce the duration and consequence of an intrusion even when initial access cannot be prevented.
Identify Cross-Sector and Shared Dependencies
Critical infrastructure protection should account for dependencies between sectors rather than treating each sector as an isolated environment. Electricity supports telecommunications, water pumping, transportation systems, fuel operations, industrial facilities, aviation infrastructure, and government services. Telecommunications supports remote monitoring, dispatch, logistics, maintenance, restoration, and operational coordination across other sectors. Transportation enables fuel delivery and movement of personnel, replacement equipment, and other critical resources. Water supports healthcare, firefighting, industrial operations, military facilities, and other essential services.
Aviation and air traffic infrastructure present a particularly important cross-sector dependency. National Airspace System operations rely on communications, navigation, surveillance, automation, weather, power, and telecommunications infrastructure, while the system itself supports civilian transportation, military aviation, homeland security, and other national security activities. FAA infrastructure and services also directly support the Department of War and military operations, making degradation of supporting civilian systems potentially relevant to military mission assurance.
Cyber or physical disruption affecting one supporting sector can therefore create operational effects across several others. Loss of commercial power can affect telecommunications and aviation systems. Telecommunications disruption can interfere with remote monitoring and coordination across utilities and transportation networks. Transportation disruption can impede delivery of fuel, replacement equipment, and personnel required to restore affected infrastructure.
Improve Visibility Into OT-Focused Threat Activity
The expanding range of actors targeting OT makes timely information sharing increasingly important.
Current threats include sophisticated state-sponsored actors conducting long term pre-positioning, Iranian-affiliated actors directly exploiting exposed PLCs, Russian and pro-Russian groups interacting with OT and SCADA environments, and unattributed actors developing or deploying capabilities against US industrial controllers.
Information sharing should therefore include more than malware indicators. Where appropriate, defenders should exchange information concerning targeted industrial products, exposed services, remote access methods, affected protocols, malicious infrastructure, observed controller changes, engineering artifacts, and operational effects. The objective should be to allow organizations using similar technology to recognize when an incident affecting one operator may indicate exposure across a much larger population of systems.
Plan for Operational Consequences, Not Only Cyber Incidents
The July 2026 water-sector attacks demonstrate why OT incidents should be evaluated according to physical and operational consequences rather than solely technical indicators. Loss of monitoring, altered controller configurations, changed credentials, or inaccessible PLCs may ultimately manifest as pressure loss, flooding, service interruption, equipment damage, or other physical effects.
Incident-response planning should therefore connect cybersecurity personnel with engineering, operations, emergency management, and organizational leadership before an incident occurs. For infrastructure supporting military or other national-security missions, coordination should also account for downstream organizations that may need to activate contingency plans if service degradation becomes prolonged. The key question should not end with “Was the system compromised?” It should extend to “What stops working if this system becomes unavailable or untrustworthy?”
Use Consequence to Inform Prioritization
The volume of US critical infrastructure makes uniform treatment of every OT environment impractical. Risk prioritization should therefore incorporate the potential consequences of disruption and the significance of downstream dependencies.
Internet-accessible controllers supporting a small isolated process do not necessarily present the same strategic risk as similarly exposed controllers supporting a water system serving a military installation, a substation supporting multiple government facilities, a telecommunications node serving emergency responders, or an industrial supplier producing components with few substitutes. This consequence-based approach can help direct technical assistance, vulnerability reduction, information sharing, exercises, and other defensive resources toward systems where successful compromise could produce the greatest public-service or national-security effects.
For critical infrastructure defenders, the central question is: Who depends on the infrastructure we protect, and what happens to them when that infrastructure is disrupted?
Analyst Commentary
The current US OT threat environment demonstrates that sophisticated strategic activity and comparatively simple exploitation can create significant risk simultaneously. Volt Typhoon represents deliberate pre-positioning intended to provide disruptive options during a potential future crisis or conflict, while recent PLC-focused campaigns demonstrate that exposed controllers, weak authentication, insecure remote access, and legitimate engineering functionality can provide much shorter paths to operational disruption.
For military organizations, the relevant attack surface extends well beyond the installation perimeter. A well-defended military network does not eliminate mission risk if the civilian electricity, water, telecommunications, transportation, fuel, logistics, or industrial infrastructure supporting the installation can be disrupted. An adversary does not necessarily need cyber access to the base if cyber access to infrastructure supporting the base can achieve the desired operational effect.
The inverse is equally important for critical infrastructure defenders. The strategic significance of an asset cannot always be determined by its ownership, size, or immediate customer base. A civilian utility, telecommunications provider, transportation node, fuel facility, or industrial supplier may support military installations, government facilities, emergency services, or other nationally significant functions. Understanding who depends on an infrastructure asset is therefore increasingly important to understanding the consequence of its compromise.
Taken together, the military and critical infrastructure perspectives are complementary. Military planners need to understand what they depend on, while critical infrastructure defenders need to understand who depends on what they protect. Closing that visibility gap is essential to reducing the ability of cyber actors to translate the compromise of civilian OT into broader public-service or national-security consequences.
The growing pro-Russian OT ecosystem further demonstrates that physical-process risk is no longer confined to highly sophisticated state-sponsored ICS operators. Knowledge of exposed industrial systems, remote-management interfaces, and OT intrusion techniques is increasingly available to smaller groups whose technical capabilities may be substantially less sophisticated than the infrastructure they are capable of affecting. The technical sophistication required to cause disruption may therefore be considerably lower than the strategic importance of the system being disrupted.
This creates an important detection problem. Defenders cannot assume that the first observable indication of an OT threat will occur inside the industrial environment itself. Adversaries may first establish access through enterprise systems, exposed infrastructure, compromised credentials, malicious files, remote access tooling, command-and-control infrastructure, or other artifacts encountered before they reach the physical process.
PolySwarm provides an additional intelligence and detection layer at these earlier stages of the attack chain. Its multi-engine malware analysis and threat-intelligence ecosystem can help organizations identify and enrich suspicious files, URLs, domains, IP addresses, and related indicators associated with malicious infrastructure and intrusion activity. This allows defenders to evaluate suspicious artifacts against multiple independent detection sources rather than relying on a single vendor's assessment. For government agencies, the Defense Industrial Base, critical infrastructure operators, and organizations supporting military installations, this capability can provide additional context around activity associated with initial access, persistence, command and control, lateral movement, and potential enterprise-to-OT progression. The objective is to identify and disrupt malicious activity while it remains a cyber intrusion, not after it becomes an operational event.
PolySwarm does not replace industrial network monitoring, PLC hardening, segmentation, secure remote access, engineering change controls, or process-safety systems. Instead, it complements those controls by strengthening visibility into the malicious artifacts and infrastructure that can precede OT compromise. In environments where the consequence of successful intrusion may include loss of public services, physical damage, degraded military readiness, or disruption of mission essential operations, earlier identification provides defenders with more opportunity to intervene before an adversary reaches systems capable of producing physical effects.
The strategic progression is straightforward. Cyber access can lead to a persistent foothold, provide a pathway into OT environments, enable manipulation of physical processes, and ultimately produce operational consequences. PolySwarm's value is concentrated in the earlier stages of that progression, where defenders retain the greatest opportunity to detect, investigate, correlate, and disrupt malicious activity before cyber access develops into physical or operational consequences.
For senior government and military stakeholders, this should inform how critical infrastructure visibility and prioritization are conceptualized. Protecting mission-essential operations requires visibility not only into government-owned systems, but also into threat activity affecting the commercial and civilian infrastructure upon which those missions depend. Conversely, protecting civilian critical infrastructure requires understanding the government, military, emergency service, and other essential functions that may depend upon it. PolySwarm can provide additional visibility into malicious activity before compromise of either environment develops into a broader operational consequence. In this environment, earlier detection can turn threat intelligence from a retrospective explanation of an outage into an opportunity to prevent one.
IOCs
PolySwarm has multiple samples of malware associated with threat actors featured in this report.
Volt Typhoon
e453e6efc5a002709057d8648dbe9998a49b9a12291dee390bb61c98a58b6e95
6036390a2c81301a23c9452288e39cb34e577483d121711b6ba6230b29a3c9ff
8fa3e8fdbaa6ab5a9c44720de4514f19182adc0c9c6001c19cf159b79c0ae9c2
3e9fc13fab3f8d8120bd01604ee50ff65a40121955a4150a6d2c007d34807642
f4dd44bc19c19056794d29151a5b1bb76afd502388622e24c863a8494af147dd
eaef901b31b5835035b75302f94fee27288ce46971c6db6221ecbea9ba7ff9d0
CyberAv3ngers
9e5f9dcb5f17efdca727b7b13a5f9ecd3296d28ac10e3675259b660d62739b87
1b39f9b2b96a6586c4a11ab2fdbff8fdf16ba5a0ac7603149023d73f33b84498
GRU Unit 29155
3e4bb8089657fef9b8e84d9e17fd0d7740853c4c0487081dacc4f22359bade5c
20215acd064c02e5aa6ae3996b53f5313c3f13625a63da1d3795c992ea730191
3fe9214b33ead5c7d1f80af469593638b9e1e5f5730a7d3ba2f96b6b555514d4
NoName057(16)
761075da6b30bb2bcbb5727420e86895b79f7f6f5cebdf90ec6ca85feb78e926
fae9b6df2987b25d52a95d3e2572ea578f3599be88920c64fd2de09d1703890a
8e1769763253594e32f2ade0f1c7bd139205275054c9f5e57fefd8142c75441f
9a1f1c491274cf5e1ecce2f77c1273aafc43440c9a27ec17d63fa21a89e91715
726c2c2b35cb1adbe59039193030f23e552a28226ecf0b175ec5eba9dbcd336e
7e12ec75f0f2324464d473128ae04d447d497c2da46c1ae699d8163080817d38
Don’t have a PolySwarm account? Go here to sign up for a free Community plan or subscribe.
Contact us at hivemind@polyswarm.io | Check out our blog | Subscribe to our reports.