The U.S. government has identified a significant and growing threat to its critical infrastructure from nation-state adversaries, as highlighted in the March 2025 Annual Threat Assessment by the Office of the Director of National Intelligence. China is described as the most active and persistent cyber threat, targeting government, private-sector, and critical infrastructure networks through campaigns such as Volt Typhoon and Salt Typhoon. These campaigns have compromised organizations in the energy, transportation, and water sectors, with attackers moving laterally within operational technology environments to potentially disrupt essential services. Russia is noted for its integration of cyberattacks with military operations, exemplified by its ongoing assaults on Ukrainian networks and attempts to gain access to U.S. critical infrastructure assets. Iran has expanded its cyber capabilities, posing major threats to U.S. networks, while North Korea is being monitored for its targeting of defense industrial base companies, particularly those involved in advanced technologies like aerospace and hypersonic systems. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recognizes 16 critical infrastructure sectors, all of which are potential targets for these nation-state actors. In response to these threats, there is a growing emphasis on the importance of threat intelligence sharing among organizations, especially those operating within the same industry or supply chain. Sharing threat information enables companies to enhance their security posture, providing early warnings about emerging tactics, techniques, and procedures used by adversaries. This collaborative approach not only strengthens cyber resilience but also helps CISOs manage the stress associated with defending against frequent and sophisticated attacks. By leveraging a network of like-minded security leaders, organizations can proactively address critical issues and improve their ability to prevent, detect, and respond to cyber threats. The increasing frequency and sophistication of cyberattacks underscore the necessity for a united front, where information sharing becomes a key component of national and organizational defense strategies. Such collaboration is vital for early detection of threats, rapid dissemination of actionable intelligence, and coordinated responses to incidents. The integration of threat intelligence sharing into cybersecurity programs is seen as a force multiplier, enabling organizations to stay ahead of adversaries and protect critical infrastructure more effectively. As the threat landscape evolves, both government and private sector entities are urged to prioritize information sharing and collective defense measures to safeguard essential services and national interests.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Initial story creation
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.