> ## Documentation Index
> Fetch the complete documentation index at: https://docs.reyhford.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Who Attacks ICS/OT

> Nation-state groups, hacktivists, and ransomware operators targeting industrial infrastructure.

ICS/OT adversaries fall into overlapping camps. Attribution is rarely perfect; SOC teams should prioritize **capability and intent** over labels.

## Nation-state groups

These campaigns are the most sophisticated against industrial infrastructure.

| Actor (public naming)    | Notable focus                                   |
| ------------------------ | ----------------------------------------------- |
| **Sandworm** (Russia)    | Ukraine power grid; Industroyer / Crashoverride |
| **XENOTIME** (Russia)    | Triton/TRISIS — safety instrumented systems     |
| **APT33** (Iran)         | Energy and petrochemical                        |
| **Volt Typhoon** (China) | Pre-positioning in critical infrastructure      |

Nation-state activity often starts with long reconnaissance against exposed ICS protocols — the same probes our honeypots record.

## Hacktivists

Hacktivist groups increasingly claim OT-adjacent disruptions (defacements of industrial portals, DDoS against energy operators). Capability varies widely; the operational risk is opportunistic access to poorly segmented OT.

## Ransomware operators

Ransomware groups target OT-adjacent IT first. **Colonial Pipeline (2021)** showed that encrypting business systems can force physical shutdowns even when PLCs are untouched. Double-extortion and “OT-aware” affiliates make industrial verticals a priority.

## Opportunistic scanners

Automated internet-wide scanning of ports 502, 102, 47808, 2404, 44818, and 10001 is constant. Most traffic Reyhford sees is reconnaissance — fingerprinting, function-code enumeration, and write probes — not a finished kill chain. That reconnaissance is still actionable for CERTs and MSSPs.

## Next

* [Real incidents](/threat-landscape/real-incidents)
* [Threat actor profiles (regional)](/regional/threat-actor-profiles)
