Critical Infrastructure — Cyber Threat Activity

Critical infrastructure as a cross-cutting label holds a single recorded incident in our log, because operators are classified under their specific sector instead: energy, water, transportation, healthcare and communications each carry their own page and their own volume. Use this page for the actors rather than the count. 39 groups carry a researched association with critical-infrastructure targeting, including Volt Typhoon, Dragonfly, Cyber Av3ngers, RansomHub, Black Basta, BlackSuit, Conti and DarkSide, with 62 malware families linked through those actors. That list mixes two populations that behave nothing alike. Criminal crews reach infrastructure operators through ordinary enterprise IT and extort them; the operational consequences, when they occur, are usually a side effect of shutting down business systems as a precaution rather than of any control-system intrusion. State operators are the more serious case. CISA, NSA and FBI assess that Chinese actors have pre-positioned inside US critical networks specifically to enable disruptive or destructive attacks in a future crisis, using built-in administrative tools rather than malware so that ordinary monitoring sees nothing unusual, and in confirmed cases holding that access for years. Iranian-affiliated operators and pro-Russia hacktivists have taken a cruder route, reaching internet-exposed programmable logic controllers and human-machine interfaces left on default or absent credentials, then changing setpoints and locking out operators. CISA assesses that the hacktivist groups cannot reliably predict the physical consequences of what they alter, which makes them unpredictable rather than harmless. Read the actor associations here as published research, not as incidents attributed in our own corpus.

All sectors

Threat actors targeting Critical Infrastructure

Malware used against Critical Infrastructure

Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.

Where these victims are

Recent incidents

Coverage. 94.7% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.

Read the full analysis on IntelFusions