CYBER-PHYSICAL THREAT INTELLIGENCE

Operational Technology & ICS Attacks

Forensic and architectural breakdown of landmark cyber operations designed to cause physical destruction, equipment damage, or electrical blackouts across industrial control and critical infrastructure networks.

Key Facts

  • Deep technical analysis of cyber-physical attacks targeting Operational Technology (OT) and SCADA systems.
  • Classified according to the Purdue Enterprise Reference Architecture (PERA Levels 0 through 4).
  • Analyzes direct physical sabotage of PLCs, Safety Instrumented Systems (SIS), and power distribution grids.
  • Highlights strict air-gap boundary enforcement, unidirectional data diodes, and out-of-band manual overrides.

Purdue Reference Architecture Segmentation Choke Points

Level 4: Enterprise Corporate ERP, email, and business networks. Typical initial ingress point.
Level 3: Operations Plant SCADA servers, engineering workstations, and historical databases.
Level 2: Supervisory HMI consoles, operator control panels, and alarm monitoring.
Level 1: Control Programmable Logic Controllers (PLCs), RTUs, and Safety Instrumented Systems (SIS).

Operation Olympic Games (Stuxnet)

2010 | Physical Centrifuge Destruction
Target: Uranium Enrichment Facility (Natanz, Iran) | Threat Actor: U.S. / Israeli Intelligence (Equation Group)
Targeted Purdue Level: Purdue Level 1 (Basic Sensing & Actuation) / Level 2 (Supervisory)
Perimeter Penetration:

Compromised USB drives exploiting Windows LNK zero-day CVE-2010-2568, jumping air-gap into Simatic Step 7 programming stations.

Physical Sabotage Mechanism:

Injected malicious ladder logic blocks into Siemens S7-300 PLCs, commanding variable-frequency drives to cycle rotor speeds from 1,410 Hz to 2 Hz to induce mechanical resonance stress, while transmitting spoofed normal telemetry to human operators.

TRITON / HatMan SIS Sabotage

2017 | Life-Safety System Manipulation & Potential Explosion
Target: Petrochemical Refining Complex (Saudi Arabia) | Threat Actor: Central Scientific Research Institute of Chemistry & Mechanics (TsNIIKhM)
Targeted Purdue Level: Purdue Level 1 (Safety Instrumented Systems - SIS)
Perimeter Penetration:

Traversed from corporate network through engineering workstation via hijacked TriStation protocol (UDP port 1502).

Physical Sabotage Mechanism:

Directly injected shellcode into Schneider Electric Triconex MP communication modules to override emergency fail-safe logic, aiming to disable shutdown systems during an intentional runaway chemical event.

BlackEnergy 3 & KillDisk Power Grid Blackout

2015 | Substation Breaker Disconnection & Citizen Blackout
Target: Electrical Transmission Substations (Western Ukraine) | Threat Actor: Sandworm (Russian GRU Unit 74455)
Targeted Purdue Level: Purdue Level 2 (Human-Machine Interface) / Level 1 (RTU Controllers)
Perimeter Penetration:

Spear-phishing emails containing malicious macros delivering BlackEnergy 3 trojan into regional power distribution utilities.

Physical Sabotage Mechanism:

Actors took remote manual control of SCADA HMI consoles to open 30 distribution substation circuit breakers, followed by deploying KillDisk to wipe master boot records and flashing corrupted firmware onto serial-to-Ethernet converters to block manual restoration.

AcidRain Viasat KA-SAT Satellite Wiper

2022 | Permanent Hardware Bricking of Satellite Modems
Target: Commercial Satellite Ground Terminals & European Wind Turbines | Threat Actor: Russian Military Intelligence (GRU)
Targeted Purdue Level: Purdue Level 3 (Site Operations) / Embedded Linux Flash Storage
Perimeter Penetration:

Exploitation of misconfigured VPN concentrators on Skylogic ground station network.

Physical Sabotage Mechanism:

Pushed destructive MTD flash wiper executable across network management channels to tens of thousands of SurfBeam 2 satellite modems, recursively overwriting raw NAND flash blocks to render modems unbootable.

Volt Typhoon Critical Infrastructure Pre-Positioning

2021-2026 | Pre-Positioned Sabotage Access for Geopolitical Crisis
Target: Water Utilities, Pipeline Pumping, Electric Grids (U.S. & Guam) | Threat Actor: Volt Typhoon (PRC State-Sponsored / Bronze Silhouette)
Targeted Purdue Level: Purdue Level 3 (Industrial DMZ / Operations Management)
Perimeter Penetration:

Compromised edge routers (KV-botnet) and perimeter firewalls using stolen administrator credentials.

Physical Sabotage Mechanism:

Stealthy living-off-the-land persistence in OT management enclaves without deploying malware, establishing remote operational control to disrupt power, water, and fuel flows to military installations during conflict.