Skip to content

Dragos’s 8th Annual OT Cyber Security Year in Review

19 June 20252 min read
Guest Insights
Dragos’s 8th Annual OT Cyber Security Year in Review

Dragos Inc.

We’re proud to announce the release of our 8th Annual OT Cybersecurity Year in Review report, offering a comprehensive look at the evolving threats facing operational technology (OT) and industrial control systems (ICS). This year’s report highlights how adversaries are escalating their tactics and how defenders can respond effectively.

Escalating Threats and Evolving Adversaries

Driven by geopolitical tensions, threat actors are increasingly targeting OT networks. Dragos currently tracks 23 threat groups, including two new ones:

  • BAUXITE: Active in the U.S., Europe, and the Middle East, this group targets oil & gas and chemical sectors, compromising PLCs and deploying custom backdoors.

  • GRAPHITE: Operating in Eastern Europe and the Middle East, GRAPHITE uses spear-phishing and malware to infiltrate energy and logistics networks.

Other notable groups include:

  • VOLTZITE: Known for stealthy operations in U.S. critical infrastructure.

  • KAMACITE: Provides initial access for ICS attacks, now targeting third-party vendors.

  • ELECTRUM: A long-standing threat, linked to the AcidPour wiper and major disruptions in Ukraine.

ICS Malware on the Rise

Two new ICS-specific malware families emerged in 2024:

  • Fuxnet: Disabled thousands of monitoring devices in Moscow by overwriting firmware and exploiting weak credentials.

  • FrostyGoop: Caused heating outages in Ukraine by exploiting Modbus TCP, bypassing antivirus tools, and highlighting the risks of unmonitored ICS protocols.

Ransomware’s Expanding Impact

Ransomware attacks surged by 87% in 2024, with 1,693 incidents targeting industrial organizations. Manufacturing remains the most affected, but energy and critical infrastructure are increasingly at risk. Alarmingly, 75% of these attacks led to partial OT shutdowns, and 25% caused full shutdowns.

Prioritizing Vulnerabilities with “Now, Next, Never”

Dragos promotes a risk-based vulnerability management framework:

  • Now (6%): Critical issues needing immediate action.

  • Next (63%): High-priority issues to address soon.

  • Never (31%): Low-risk issues that can be deferred.

Persistent Security Gaps

Despite progress, many organizations still struggle with:

  • Incident Response: Few have OT-specific plans or trained personnel.

  • Network Segmentation: Flat networks and misconfigured firewalls remain common.

  • Visibility: Many lack real-time OT monitoring and protocol oversight.

  • Remote Access: Insecure setups and third-party risks persist.

  • Vulnerability Management: Often reactive, with perimeter-facing risks overlooked.

The Path Forward

This year’s report underscores the urgent need for proactive OT cybersecurity. With eight years of insights, Dragos continues to support defenders in strengthening their operations and protecting critical infrastructure.

Download the full report to prepare your organization for the challenges ahead.