Critical Infrastructure Security, Threat Intelligence, OT Security

Dragos report: New threat groups target critical infrastructure

A glowing red warning icon on a CPU within a critical infrastructure. System failure and cybersecurity threat alert. A vulnerability in the power grid or a computer hardware malfunction.

Three new threat groups emerged last year targeting critical infrastructure, while the well-known Beijing-backed group Volt Typhoon continued its intrusions into cellular gateways and routers, impacting US electric, oil, and gas companies, according to Dragos' annual threat report, as covered by The Register.

Dragos' report identified three new operational technology (OT)-focused threat groups, bringing the global total to 26, with 11 active in 2025. The group correlated with Volt Typhoon, also known as Voltzite, focused on long-term persistence within strategic American utilities, aiming to disrupt and cause destruction rather than steal intellectual property. Voltzite compromised Sierra Wireless AirLink devices to access OT networks of US pipeline operations, exfiltrating data and potentially manipulating control systems. Another campaign involved Voltzite using the JDY botnet to scan for public-facing IP addresses and VPN appliances across energy, oil, gas, and defense sectors.

New groups include Sylvanite, acting as an initial access broker for Voltzite by weaponizing vulnerabilities in F5, Ivanti, and SAP products. Azurite, overlapping with China's Flax Typhoon, targets OT engineering workstations for long-term access and data exfiltration. Pyroxene, linked to Iran's IRGC, conducts supply chain attacks using social engineering, deploying data-wiping malware against organizations in Israel.

Source: The Register

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds