Kamicite is a threat actor tracked in industrial-control-system and operational-technology intrusions, particularly against the European ICS/OT supply chain since late 2024. It has been observed operating in conjunction with Dragos-tracked Electrum, an activity cluster assessed to overlap with Sandworm. In that division of labor, Kamicite has been associated with gaining initial access and establishing persistence, while Electrum conducted subsequent destructive operations. Kamicite has also been linked to persistent scanning of industrial devices in the United States, indicating a focus on reconnaissance and access development against OT-relevant environments. In the late-2025 destructive campaign against Poland’s energy sector, including decentralized energy resources such as wind and solar facilities as well as other industrial targets, the broader operation used compromised Internet-facing edge devices and default credentials to pivot toward OT environments before wiper deployment. High-confidence reporting specifically attributes the initial-access and persistence portions of this collaborative activity to Kamicite. The actor’s observed tradecraft therefore centers on reconnaissance, scanning, initial compromise, and persistence in industrial environments, with activity aligned to destructive Russian-linked OT campaigns through its collaboration with Electrum/Sandworm-associated operations. Publicly available information does not support a distinct ransomware or extortion profile for Kamicite.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.