Critical Infrastructure — Cyber Threat Activity
Critical infrastructure as a cross-cutting label holds a single recorded incident in our log, because operators are classified under their specific sector instead: energy, water, transportation, healthcare and communications each carry their own page and their own volume. Use this page for the actors rather than the count. 39 groups carry a researched association with critical-infrastructure targeting, including Volt Typhoon, Dragonfly, Cyber Av3ngers, RansomHub, Black Basta, BlackSuit, Conti and DarkSide, with 62 malware families linked through those actors. That list mixes two populations that behave nothing alike. Criminal crews reach infrastructure operators through ordinary enterprise IT and extort them; the operational consequences, when they occur, are usually a side effect of shutting down business systems as a precaution rather than of any control-system intrusion. State operators are the more serious case. CISA, NSA and FBI assess that Chinese actors have pre-positioned inside US critical networks specifically to enable disruptive or destructive attacks in a future crisis, using built-in administrative tools rather than malware so that ordinary monitoring sees nothing unusual, and in confirmed cases holding that access for years. Iranian-affiliated operators and pro-Russia hacktivists have taken a cruder route, reaching internet-exposed programmable logic controllers and human-machine interfaces left on default or absent credentials, then changing setpoints and locking out operators. CISA assesses that the hacktivist groups cannot reliably predict the physical consequences of what they alter, which makes them unpredictable rather than harmless. Read the actor associations here as published research, not as incidents attributed in our own corpus.
- Recorded incidents: 4
- Incidents, trailing 180 days: 1
- Tracked threat actors: 42
- Malware families: 88
Threat actors targeting Critical Infrastructure
- SafePay 2 incidents
- Volt Typhoon 1 incident
- M3rx 1 incident
- RansomHub researched targeting
- Black Basta researched targeting
- BlackSuit researched targeting
- Conti researched targeting
- Cyber Av3ngers researched targeting
- DarkSide researched targeting
- Dragonfly researched targeting
- Sandworm Team researched targeting
- Qilin researched targeting
- DragonForce researched targeting
- MedusaLocker researched targeting
- Brain Cipher researched targeting
- Interlock researched targeting
- NoName057(16) researched targeting
- BlackJack researched targeting
- Cardinal researched targeting
- Cyber Army of Russia Reborn researched targeting
- Cyber Islamic Resistance researched targeting
- Cyber Support Front researched targeting
- Dark Angels researched targeting
- Dark Storm Team researched targeting
Malware used against Critical Infrastructure
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- BlackCat Malware
- Cobalt Strike Malware
- Conti Malware
- Emotet Malware
- Impacket Tool
- Lumma Stealer Malware
- Metasploit Tool
- Mimikatz Tool
- NotPetya Malware
- PsExec Tool
- QakBot Malware
- Ryuk Malware
Where these victims are
- Germany 2
- Canada 1
- United States 1
Recent incidents
- pvdd.ca 2026-05-06
- eu-rec.de 2025-05-06
- foerster-schwanau.de 2025-04-16
- US Critical Infrastructure (multiple sectors) 2024-01-31
Coverage. 94.7% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.