Operational Technology & ICS Attacks
Forensic and architectural breakdown of landmark cyber operations designed to cause physical destruction, equipment damage, or electrical blackouts across industrial control and critical infrastructure networks.
Key Facts
- Deep technical analysis of cyber-physical attacks targeting Operational Technology (OT) and SCADA systems.
- Classified according to the Purdue Enterprise Reference Architecture (PERA Levels 0 through 4).
- Analyzes direct physical sabotage of PLCs, Safety Instrumented Systems (SIS), and power distribution grids.
- Highlights strict air-gap boundary enforcement, unidirectional data diodes, and out-of-band manual overrides.
Purdue Reference Architecture Segmentation Choke Points
Operation Olympic Games (Stuxnet)
2010 | Physical Centrifuge DestructionCompromised USB drives exploiting Windows LNK zero-day CVE-2010-2568, jumping air-gap into Simatic Step 7 programming stations.
Injected malicious ladder logic blocks into Siemens S7-300 PLCs, commanding variable-frequency drives to cycle rotor speeds from 1,410 Hz to 2 Hz to induce mechanical resonance stress, while transmitting spoofed normal telemetry to human operators.
TRITON / HatMan SIS Sabotage
2017 | Life-Safety System Manipulation & Potential ExplosionTraversed from corporate network through engineering workstation via hijacked TriStation protocol (UDP port 1502).
Directly injected shellcode into Schneider Electric Triconex MP communication modules to override emergency fail-safe logic, aiming to disable shutdown systems during an intentional runaway chemical event.
BlackEnergy 3 & KillDisk Power Grid Blackout
2015 | Substation Breaker Disconnection & Citizen BlackoutSpear-phishing emails containing malicious macros delivering BlackEnergy 3 trojan into regional power distribution utilities.
Actors took remote manual control of SCADA HMI consoles to open 30 distribution substation circuit breakers, followed by deploying KillDisk to wipe master boot records and flashing corrupted firmware onto serial-to-Ethernet converters to block manual restoration.
AcidRain Viasat KA-SAT Satellite Wiper
2022 | Permanent Hardware Bricking of Satellite ModemsExploitation of misconfigured VPN concentrators on Skylogic ground station network.
Pushed destructive MTD flash wiper executable across network management channels to tens of thousands of SurfBeam 2 satellite modems, recursively overwriting raw NAND flash blocks to render modems unbootable.
Volt Typhoon Critical Infrastructure Pre-Positioning
2021-2026 | Pre-Positioned Sabotage Access for Geopolitical CrisisCompromised edge routers (KV-botnet) and perimeter firewalls using stolen administrator credentials.
Stealthy living-off-the-land persistence in OT management enclaves without deploying malware, establishing remote operational control to disrupt power, water, and fuel flows to military installations during conflict.