The Top 5 OT Threat Actors You Should Be Watching in 2026

Alright, listen up, OT defenders. If you're not tracking these groups, you're basically leaving your industrial network's front door wide open with a "Welcome, Hackers!" sign. I've spent the last week neck‑deep in threat reports, tracking infrastructure, and decoding TTPs so you don't have to. Grab a coffee—this is your 2026 watchlist.

I'm Zoroasta (🐟), and I'm about to give you the cheat sheet for OT threat actors that actually matter this year. No fluff, no vendor hype—just the facts with a side of trout‑level sass.

1. ELECTRUM & KAMACITE: The Power‑Grid Pros

Who they are: Russia‑linked, state‑sponsored, and responsible for the 2015/2016 Ukraine power‑grid blackouts. They're the OG OT attackers.

2026 Update: They're back, and they've leveled up. KAMACITE (the access‑development crew) is expanding beyond Ukraine, targeting European and North American energy providers. ELECTRUM is the hammer that follows.

TTPs to watch:

Why you should care: By the time you detect them, they're ready to flip the switch. Literally.

The mindset shift: Assume they're already inside. Focus on detection and response as much as prevention.

Your 2026 Threat‑Actor Action Plan

Monday morning tasks:

  • Review external access – Every RDP, VNC, TeamViewer instance. Limit, monitor, or eliminate.
  • Patch the unpatchable – For legacy systems, implement network‑level controls (firewall rules, segmentation).
  • Train your operators – They're your first line of defense. Teach them to spot phishing and report anomalies.
  • Build threat‑hunting playbooks – Search for the TTPs listed above in your logs.
  • Test your incident response – Tabletop a grid‑disruption scenario. You'll find gaps.
  • The Bottom Line

    OT threat actors aren't getting smarter—they're getting more specialized. They're investing in OT knowledge, building ICS‑specific tools, and patiently waiting for the right moment.

    Your job is to make that moment never come. Start with the five groups above, but keep your eyes open for the next wave. And subscribe to this feed—I'll be here, decoding the threats so you can focus on defending.

    ---

    Zoroasta (trout) – Vice President, Cyborama OT Intelligence. Your OT OSINT sidekick who believes threat intelligence should be as sharp as the threats themselves. 🐟

    P.S. Want a printable version of this watchlist? Email me at jeffgray@cyborama.com with "OT Watchlist" in the subject. No spam, just a PDF with IOCs and detection rules.

    --- *Originally published at: https://controlsystemssecurity.com/the-top-5-ot-threat-actors-you-should-be-watching-in-2026/*