U.S. officials stepped up warnings and coordination with industry over potential Russian cyberattacks tied to the Ukraine crisis, urging organizations to report signs of reconnaissance, exploitation testing, malware development, and compromises involving industrial control systems. The FBI, CISA, DHS, NSA, Treasury, Energy Department, and allied partners increased intelligence sharing and defensive preparations as officials cited the risk that destructive activity already hitting Ukrainian entities could spill over to U.S. and foreign companies with operations in Ukraine, particularly across energy, healthcare, finance, and other critical infrastructure sectors.
The concern was grounded in a documented history of Russian operations against operational technology and the energy sector. Prior U.S. government reporting detailed campaigns targeting critical infrastructure, while Treasury sanctioned a Russian state research institution linked to the Triton/Trisis malware used against Schneider Electric safety systems. The Justice Department later charged four Russian government-linked individuals over the Triton/Trisis and Dragonfly/Havex campaigns, alleging long-running efforts to compromise SCADA and industrial control environments at hundreds of organizations in roughly 135 countries to enable future disruption or physical damage.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
On March 24, 2022, the Justice Department unsealed two indictments charging four Russian nationals linked to the Russian government for separate cyber campaigns targeting critical infrastructure and the global energy sector.
On 2022-03-01, CISA, the FBI, and the NSA issued a joint advisory warning critical infrastructure organizations about Russian state-sponsored cyber operations. The advisory detailed commonly exploited CVEs and TTPs, noted historical targeting of U.S. and international critical infrastructure including OT/ICS environments, and urged immediate defensive measures such as patching, MFA, logging, segmentation, and threat hunting.
A DHS intelligence bulletin dated January 23 assessed that Russia might consider cyberattacks on the U.S. homeland if Moscow believed a U.S. or NATO response over Ukraine threatened its long-term national security, while noting the threshold remained high.
On January 21, the FBI asked U.S. businesses to report any uptick in suspected Russian hacking threats, including testing of exploitation capabilities, malware development, and compromises involving industrial control systems or critical infrastructure.
The DOJ said an August 2021 indictment in the District of Kansas charged Pavel Akulov, Mikhail Gavrilov, and Marat Tyukov for Dragonfly intrusions targeting the global energy sector.
The DOJ said a June 2021 indictment in the District of Columbia charged Evgeny Viktorovich Gladkikh over the Triton-related conspiracy targeting critical infrastructure.
The U.S. Treasury sanctioned a Russian government research institution on October 23, 2020 for its alleged connection to the Triton malware used in the 2017 Saudi petrochemical plant incident.
The DOJ said that between February and July 2018, the Triton conspirators researched similar U.S. refineries and unsuccessfully attempted to compromise a U.S. company managing comparable critical infrastructure.
DHS publicly accused Russian government-backed hackers in 2018 of a multi-year effort to infiltrate U.S. energy, water, and manufacturing firms, including activity involving sensitive industrial control systems.
The DOJ alleged that between May and September 2017, Evgeny Gladkikh and co-conspirators hacked a foreign refinery and installed Triton/Trisis malware on Schneider Electric safety systems, causing two automatic emergency shutdowns.
The DOJ said the second Dragonfly phase ran from 2014 to 2017, focusing on specific energy-sector organizations and engineers through spearphishing and watering-hole attacks, including compromises affecting U.S. and international entities.
According to the DOJ, FSB-linked operators began the first Dragonfly/Havex phase in 2012, compromising ICS/SCADA manufacturers and software providers to distribute malware-laced updates and gain access to energy-sector networks.
The CNN report says Ukraine had faced a string of cyberattacks since mid-January, including destructive malware that wiped data from at least two Ukrainian government agencies.
Dragos' Robert M. Lee said a foreign hacking group identified as Xenotime/Temp.Veles conducted high-level reconnaissance against U.S. electric utilities operating liquefied natural gas facilities in December, without causing compromises.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
justice.gov
Open sourcecisa.gov
Open sourceedition.cnn.com
Open sourcehome.treasury.gov
Open sourcecisa.gov
Open sourcecrowdstrike.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.