Skip to main content
ICS/OT adversaries fall into overlapping camps. Attribution is rarely perfect; SOC teams should prioritize capability and intent over labels.

Nation-state groups

These campaigns are the most sophisticated against industrial infrastructure. Nation-state activity often starts with long reconnaissance against exposed ICS protocols — the same probes our honeypots record.

Hacktivists

Hacktivist groups increasingly claim OT-adjacent disruptions (defacements of industrial portals, DDoS against energy operators). Capability varies widely; the operational risk is opportunistic access to poorly segmented OT.

Ransomware operators

Ransomware groups target OT-adjacent IT first. Colonial Pipeline (2021) showed that encrypting business systems can force physical shutdowns even when PLCs are untouched. Double-extortion and “OT-aware” affiliates make industrial verticals a priority.

Opportunistic scanners

Automated internet-wide scanning of ports 502, 102, 47808, 2404, 44818, and 10001 is constant. Most traffic Reyhford sees is reconnaissance — fingerprinting, function-code enumeration, and write probes — not a finished kill chain. That reconnaissance is still actionable for CERTs and MSSPs.

Next