Three new threat groups emerged last year targeting critical infrastructure, while the well-known Beijing-backed group Volt Typhoon continued its intrusions into cellular gateways and routers, impacting US electric, oil, and gas companies, according to Dragos' annual threat report, as covered by The Register.Dragos' report identified three new operational technology (OT)-focused threat groups, bringing the global total to 26, with 11 active in 2025. The group correlated with Volt Typhoon, also known as Voltzite, focused on long-term persistence within strategic American utilities, aiming to disrupt and cause destruction rather than steal intellectual property. Voltzite compromised Sierra Wireless AirLink devices to access OT networks of US pipeline operations, exfiltrating data and potentially manipulating control systems. Another campaign involved Voltzite using the JDY botnet to scan for public-facing IP addresses and VPN appliances across energy, oil, gas, and defense sectors.New groups include Sylvanite, acting as an initial access broker for Voltzite by weaponizing vulnerabilities in F5, Ivanti, and SAP products. Azurite, overlapping with China's Flax Typhoon, targets OT engineering workstations for long-term access and data exfiltration. Pyroxene, linked to Iran's IRGC, conducts supply chain attacks using social engineering, deploying data-wiping malware against organizations in Israel.Source: The Register
Critical Infrastructure Security, Threat Intelligence, OT Security
Dragos report: New threat groups target critical infrastructure

(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



