The 2025 OT/ICS Cybersecurity Report from Dragos, Inc. reveals increasing cyber threats facing industrial organizations. This year’s report identifies two new operational technology (OT) cyber threat groups, escalating ransomware activity, and the emergence of malware specifically targeting OT environments. Ransomware incidents rose by over 87% compared to the previous year, marking a concerning trend for critical infrastructure.
Robert M. Lee, Co-founder and CEO of Dragos, noted, “This year’s report demonstrates two important trends; that OT has become a mainstream target, and that even advanced cyber operations are employing unsophisticated tactics to compromise and disrupt critical infrastructure.” He emphasized the ongoing challenges from both state-sponsored and hacktivist groups, which increasingly exploit known vulnerabilities and weak configurations to gain entry into industrial environments. Lee also highlighted positive developments, stating that organizations have improved network segmentation and incident response capabilities, which are vital for boosting cybersecurity resilience.
Among the newly identified threat groups, BAUXITE has been linked to multiple global campaigns targeting critical industrial sectors and infrastructure. Dragos has observed four campaigns associated with BAUXITE since late 2023, confirming the group’s presence in the United States, Europe, Australia, and the Middle East across various industries including energy, water, food, and chemicals. The other group, GRAPHITE, targets sectors relevant to the military situation in Ukraine.
New malware strains have also emerged, including Fuxnet, attributed to a pro-Ukraine hacktivist group, and FrostyGoop, which manipulates industrial system communications, posing risks to operational integrity. FrostyGoop was noted for its effect on heating systems in Ukraine, impacting over 600 apartment buildings.
Dragos has highlighted VOLTZITE as a significant threat group to monitor, focusing on operational technology data and employing traditional techniques to compromise industrial environments. Other groups such as KAMACITE and ELECTRUM also continue to pose risks through phishing and wiper campaigns.
The report underlines the need for industries to adopt proactive security measures, such as threat hunting, to stay ahead of evolving threats. As industrial organizations face increasingly sophisticated attack methods, proactive identification and mitigation strategies are essential to reduce operational disruptions.
Comments