Volt Typhoon and New Threat Groups Target US Critical Infrastructure
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
In its annual threat report, Dragos revealed that three new operational technology (OT) threat groups emerged in 2025, bringing the total to 26 globally, with 11 active. The well-known group Volt Typhoon, linked to Beijing, maintained its focus on compromising US electric, oil, and gas sectors. Their tactics included embedding malware within critical infrastructure to prepare for potential disruptive cyberattacks.
Dragos identified Voltzite, a group correlated with Volt Typhoon, as continuing its intrusion efforts by embedding malware in American utilities. This group aimed not at stealing intellectual property but at causing future disruptions. They compromised devices like Sierra Wireless AirLink to access pipeline operations, exfiltrating operational data and potentially manipulating control systems.
Among the new groups, Sylvanite serves as an initial access broker for Voltzite, exploiting vulnerabilities in products from F5, Ivanti, and SAP to facilitate deeper intrusions into critical sectors. Azurite, another new group, overlaps with China’s Flax Typhoon and focuses on gaining long-term access to OT engineering workstations.
The third new group, Pyroxene, is linked to the Islamic Revolutionary Guard Corps and has expanded its operations from the Middle East into North America and Western Europe. They have conducted supply chain attacks and used social engineering tactics to deliver malware.
Dragos also noted the ongoing threat from Russia, particularly through the group Electrum, which targeted Poland’s power grid in December 2025. This group is associated with Russia’s GRU and has been linked to previous cyberattacks against Ukraine.
Implications for Cybersecurity
The activities of these threat groups underscore the persistent vulnerabilities within critical infrastructure sectors. Organizations must remain vigilant against potential intrusions that could disrupt essential services. The collaboration between different state-sponsored groups highlights the need for enhanced cybersecurity measures and inter-agency cooperation.
As cyber threats evolve, organizations should prioritize monitoring for unusual network activity and ensure that their systems are updated against known vulnerabilities. The use of initial access brokers like Sylvanite indicates a trend towards more sophisticated attack strategies that require a proactive defense posture.
Key Takeaways
- Regularly update your systems and software to protect against known vulnerabilities exploited by threat groups.
- Monitor network activity for unusual behavior that may indicate a breach or intrusion.
- Implement strong access controls and limit exposure of critical systems to the internet.
- Conduct regular security assessments to identify and mitigate potential weaknesses in your infrastructure.
- Stay informed about emerging threats and collaborate with other organizations to share intelligence on cyber risks.
Key Terms & Concepts
- Volt Typhoon: In this article, Volt Typhoon refers to a Beijing-backed threat group targeting US critical infrastructure.
- Operational Technology (OT): Operational Technology refers to hardware and software that detects or causes changes through direct monitoring and control of physical devices, processes, and events.
- Initial Access Broker: An Initial Access Broker is a group that exploits vulnerabilities to gain access to networks, which they then sell to other cybercriminals.
- Azulite: Azulite is a newly identified threat group that focuses on gaining long-term access to operational technology engineering workstations.
- Electrum: Electrum is a threat group linked to Russia’s GRU that has targeted critical infrastructure, including Poland’s power grid.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.