Adversaries operating in extended operational technology (xOT) environments need access and an understanding of how operations work. Which systems matter? How are they connected? What does normal look like? Where could an action create an operational impact?
Over the years, Dragos has investigated environments across industries, tracked long-running threat groups, and observed how sophisticated adversaries prepare for operations that may not occur for months or even years. The more sophisticated the adversary, the more important this process of reducing uncertainty becomes.
One advantage of spending years investigating OT attacks is that you eventually stop looking at environments the way most security people do. When an incident is over, one of the questions worth asking isn’t just how an adversary got in, but also what they spent their time trying to understand once inside. It raises the question: Do you understand your own xOT environment the same way an adversary does?
The uncertainty adversaries are trying to eliminate is how the operation functions. To maintain long-term access, they need to understand what normal looks like so they can blend in effectively. If they’re collecting intelligence, they need to understand which systems provide meaningful operational context. If their objective is disruption, they need to understand where they can create the greatest operational effect with the least amount of effort.
Whether the eventual objective is disruption, manipulation, intelligence collection, or persistent access, adversaries benefit from building an accurate model of the operation. That’s what makes reconnaissance in operational environments different from simply collecting an asset inventory. An asset inventory tells you what is there. An operational model tells you why it matters.
Take VOLTZITE. Dragos has tracked VOLTZITE, which overlaps with Volt Typhoon, collecting information that reveals how critical infrastructure operates: GIS data, OT network diagrams, SCADA configurations, operating instructions, and details about operational processes. More recently, Dragos observed this threat group accessing engineering workstations and extracting configuration and alarm data while investigating the conditions that would trigger process shutdowns. What we are seeing is an adversary developing an increasingly detailed understanding of how operations work and where operational consequences could occur.
One thing that stands out when reconstructing sophisticated intrusions is how patient that process can be. Adversaries don’t necessarily begin by searching for the “most important asset.” They learn the environment and identify trusted relationships. They observe how engineers access systems, which hosts communicate across boundaries, where credentials provide access, which systems exchange operational data, and which technologies sit between business decisions and physical processes.
A system does not need to directly control a physical process to create a path toward operational impact. Its significance may come from where it sits, what it can reach, or the trust it inherits from other systems in the environment.
Akira provides a useful example. Since the beginning of 2025, Dragos has tracked 628 Akira incidents, and the group has remained one of the most consistently active ransomware operations through the first half of 2026. Its affiliates have repeatedly targeted manufacturing and industrial services, using compromised VPN infrastructure, credential abuse, and other internet-facing systems to gain access and move through victim environments.
One 2025 incident illustrates why the systems surrounding the traditional OT environment matter. After endpoint detection and response (EDR) blocked attempts to deploy ransomware on Windows systems, the adversary identified a vulnerable internet-connected webcam on the network. The Linux-based IoT device was outside EDR coverage, giving the adversary another system from which to deploy ransomware to network shares.
Operational significance depends on context. The webcam did not control the manufacturing process, but its connectivity and position in the environment gave the adversary another path to systems the organization depended on. Understanding that relationship is part of understanding operational risk across the xOT environment. The webcam also reflects how opportunistic adversaries are, seeking the easiest available path into the network. Many of the systems running in xOT environments cannot run traditional IT security controls such as EDR agents, and because these systems are so diverse, many sit outside central management. Basic controls like changing default credentials, updating firmware, replacing expired or self-signed certificates, retiring end-of-life hardware, and correcting risky configurations then fall to manual effort. Doing that consistently across a large, varied fleet is hard, and every gap it leaves is a low-effort way in that adversaries count on.
Understanding the environment gives an adversary more than options for access and movement. It can also reveal the dependencies that determine how the physical process behaves.
In the 2024 FrostyGoop malware attack against a Ukrainian municipal energy company, the adversary manipulated ENCO controllers to report false temperature readings. The district heating system depended on those readings to make operational decisions. Operators with visibility only into controllers would still miss the operational dependency: the system fails when the data flowing through it becomes unreliable.
The attack highlights an important problem for xOT security. The controllers were only part of the system that determined the physical outcome. The meters and their values mattered because the heating process depended on that information. Visibility limited to the controllers would therefore provide only part of the operational picture. Understanding the process requires visibility into the devices providing operational data, the values being communicated, and the relationships between those systems.
For security teams, understanding those dependencies helps establish what normal operation looks like and where changes warrant investigation. This is a broader question than whether a device directly controls the process; it is about whether operations depend on the information or function it provides.
Adversaries are already looking beyond traditional OT boundaries to understand how operations work, where access can take them, and which dependencies are consequential. They are also counting on these systems having weaker security hygiene than IT, which makes initial access easier and quieter. Security teams need that same understanding of the xOT environment to recognize where risk exists and where an intrusion could have operational consequences.
To learn more about xOT, why it matters, and the foundational concepts behind operationalizing it, watch our on-demand xOT webinar.