Nation-state groups
These campaigns are the most sophisticated against industrial infrastructure.
Nation-state activity often starts with long reconnaissance against exposed ICS protocols — the same probes our honeypots record.
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
Nation-state groups, hacktivists, and ransomware operators targeting industrial infrastructure.
| Actor (public naming) | Notable focus |
|---|---|
| Sandworm (Russia) | Ukraine power grid; Industroyer / Crashoverride |
| XENOTIME (Russia) | Triton/TRISIS — safety instrumented systems |
| APT33 (Iran) | Energy and petrochemical |
| Volt Typhoon (China) | Pre-positioning in critical infrastructure |