← Back to OT / ICS Track

XUTS LABS / OT THREAT INTEL

OT Threat Groups & ICS Malware

Learn the threat actors, malware families, safety lessons, sector targeting, and operational takeaways that matter for OT security work.

Threat Groups

Operator Threat Knowledge

XENOTIME

Also known as: TEMP.Veles

OT Threat

Safety-system targeting and high-consequence ICS operations.

Oil and gasPetrochemicalCritical infrastructure

Known For

  • Associated with TRITON/TRISIS activity.
  • Interest in safety instrumented systems.
  • High-risk tradecraft with potential physical safety implications.

Defensive Lessons

  • Separate safety systems from control and business networks.
  • Monitor engineering workstation access to SIS environments.
  • Validate vendor remote access paths.
  • Harden and monitor SIS engineering tools.

Operator Notes

  • When discussing XENOTIME, emphasize that SIS targeting changes the risk conversation completely.
  • Safety systems are not normal IT assets; they exist to protect life, equipment, and environment.
  • A mature OT assessment should identify SIS boundaries and explicitly avoid unsafe interaction unless separately scoped.

ELECTRUM

Also known as: Sandworm-linked activity

OT Threat

Electric-sector disruption and ICS-specific attack operations.

Electric utilitiesTransmissionDistribution

Known For

  • Associated with CRASHOVERRIDE/Industroyer.
  • Electric grid operational targeting.
  • ICS protocol-aware disruptive capability.

Defensive Lessons

  • Monitor control-center-to-field-device communication.
  • Restrict protocol paths to known masters and outstations.
  • Prepare manual operations and recovery procedures.
  • Detect abnormal switching/control behavior.

Operator Notes

  • ELECTRUM is useful for explaining that ICS attacks can be protocol-aware and process-aware.
  • Electric-sector assessments require strict care around substations, SCADA, telecontrol, and operator visibility.
  • Passive telemetry review and segmentation validation matter more than exploit chasing.

CHERNOVITE

Also known as: PIPEDREAM, INCONTROLLER-related operator

OT Threat

Modular ICS capability targeting multiple industrial vendors and protocols.

EnergyManufacturingCritical infrastructure

Known For

  • Associated with PIPEDREAM/INCONTROLLER tooling.
  • Multi-vendor industrial protocol capability.
  • Interest in controllers, engineering workflows, and industrial manipulation.

Defensive Lessons

  • Inventory controllers and exposed industrial services.
  • Restrict engineering workstation access.
  • Monitor unusual protocol actions.
  • Build detections around controller discovery and engineering activity.

Operator Notes

  • CHERNOVITE is a strong example of adversaries building reusable OT tradecraft.
  • This reinforces why asset inventory, vendor identification, and protocol mapping matter.
  • Protocol-aware tooling makes segmentation and engineering workstation hardening critical.

KAMACITE

Also known as: Sandworm intrusion-support activity

OT Threat

Initial access, enterprise compromise, and enablement of OT-impacting operations.

EnergyGovernmentCritical infrastructure

Known For

  • Enterprise intrusion activity that can support later OT operations.
  • Credential access and staging toward critical environments.
  • IT-to-OT pathway relevance.

Defensive Lessons

  • Harden VPN and remote access.
  • Monitor identity paths into OT.
  • Enforce jump host controls.
  • Separate enterprise compromise from OT access.

Operator Notes

  • KAMACITE is useful for explaining why OT security starts in enterprise IT.
  • Many OT incidents begin with identity, VPN, email, exposed services, or weak segmentation.
  • A good OT pentest evaluates IT-to-OT pathways, not just PLCs.

VOLTZITE / Volt Typhoon-style tradecraft

Also known as: Living-off-the-land critical infrastructure intrusion

OT Threat

Stealthy access, persistence, and pre-positioning in critical infrastructure.

CommunicationsEnergyWaterTransportationCritical infrastructure

Known For

  • Living-off-the-land behavior.
  • Stealthy persistence.
  • Critical infrastructure pre-positioning concerns.

Defensive Lessons

  • Monitor administrative access patterns.
  • Harden edge devices.
  • Centralize logs from remote access infrastructure.
  • Validate segmentation and least privilege.

Operator Notes

  • This is useful when discussing identity, remote access, edge devices, and quiet persistence.
  • Not every OT threat starts with malware; many start with legitimate tools and valid credentials.
  • Detection engineering should include identity, administrative tooling, and remote-access telemetry.

ICS Malware

Malware That Changed OT Security

Stuxnet

Associated with: Natanz centrifuge sabotage

Target: Siemens PLC environments

Why it matters: Demonstrated that cyber operations can manipulate physical industrial processes while hiding operator-visible effects.

Operator Notes

  • Stuxnet is the classic example of process-aware malware.
  • It highlights the importance of engineering workstation security and project-file integrity.
  • It also shows that attacker goals may be physical process manipulation, not data theft.

Lessons

  • Protect engineering workflows.
  • Monitor logic changes.
  • Validate controller integrity.
  • Do not assume HMI visibility reflects ground truth.

TRITON / TRISIS

Associated with: XENOTIME

Target: Schneider Triconex safety systems

Why it matters: Targeted safety instrumented systems, making it one of the most serious ICS malware cases.

Operator Notes

  • TRITON is a safety conversation, not just a malware conversation.
  • It shows why SIS networks and SIS engineering stations require special protection.
  • Any pentest near SIS assets needs strict scope and operational control.

Lessons

  • Separate SIS from basic process control.
  • Monitor SIS engineering activity.
  • Limit and review vendor access.
  • Treat safety networks as high-consequence environments.

Industroyer / CRASHOVERRIDE

Associated with: ELECTRUM / Sandworm-linked operations

Target: Electric utility operations

Why it matters: Showed protocol-aware disruptive capability against electric grid environments.

Operator Notes

  • Industroyer is important because it used ICS protocol knowledge.
  • It reinforces the importance of control-center-to-substation communication monitoring.
  • It helps explain why industrial protocol paths need strict allowlisting.

Lessons

  • Monitor telecontrol protocols.
  • Restrict masters and outstations.
  • Prepare manual operation procedures.
  • Detect abnormal command patterns.

PIPEDREAM / INCONTROLLER

Associated with: CHERNOVITE

Target: Multiple industrial vendors and protocols

Why it matters: Represents modular OT capability designed around industrial devices and protocols.

Operator Notes

  • PIPEDREAM is a modern example of reusable OT attack tooling.
  • It makes vendor inventory and protocol exposure extremely important.
  • It validates why engineering workstations and controller access paths are crown jewels.

Lessons

  • Inventory industrial assets.
  • Detect protocol discovery.
  • Restrict engineering access.
  • Monitor controller interaction from unexpected hosts.