The FBI, CISA, and the NSA have warned critical infrastructure network defenders to be ready to detect and block incoming attacks from Russian-backed hacking groups. Russian state-sponsored APT actors have demonstrated sophisticated tradecraft and cyber capabilities by compromising third-party infrastructure, or developing and deploying custom malware. The three federal agencies highlight the following attacks where Russian APT groups including APT29, APT28 and the Sandworm Team have used destructive malware to specifically target industrial control systems (ICS) and operational technology (OT) networks.”]

