Threat Actors

Profiles of threat groups known to target industrial control systems, OT networks, and critical infrastructure.

Nation-State 2026

Sandworm Team

Russian GRU unit (APT44) behind the 2015 and 2016 Ukraine power grid attacks, NotPetya, and Olympic Destroyer.

Read profile →
Nation-State 2026

Xenotime

Group behind TRISIS/TRITON, the first malware built to target a safety instrumented system rather than the process it protects.

Read profile →
Nation-State 2026

Chernovite

Assessed state-sponsored group behind PIPEDREAM, the most capable publicly documented ICS attack toolkit found before it was ever deployed.

Read profile →