← Blog

When Nation-States Don't Need Zero-Days: The New Shape of OT Targeting

10 July 2026 · Maigadi Networks

NDRICS SecurityNation-State ThreatsBehavioral DetectionLiving-Off-the-LandExposed ICSOT Threat LandscapeCritical Infrastructure

Last week, the Polish Internal Security Agency (ABW) issued a stark warning: cyberattacks are shifting from espionage and data theft toward physical disruption of critical infrastructure. That same week, researchers identified nearly 4,000 internet-exposed industrial control devices vulnerable to an Iran-linked hacking campaign that had already compromised water systems, energy facilities, and manufacturing plants across the United States.

Neither story is about a novel zero-day. Neither involves malware that antivirus vendors haven’t seen. The attackers aren’t burning expensive exploits — they’re walking through open doors.


The Zero-Day Myth in OT

In IT security, the most feared attack is the one nobody has seen before: the zero-day exploit that slides past every signature, every detect-and-block rule, every hardened perimeter. Defenders spend billions chasing the unknown, building detection engineering pipelines around the assumption that the next breach will come through something new.

OT networks invert this assumption.

When the FBI, CISA, and the EPA issued a joint advisory in late 2025 about Iranian state-sponsored actors targeting US water and wastewater systems, the attack vector wasn’t a sophisticated exploit chain. It was default credentials on internet-facing programmable logic controllers. When Sandworm, Russia’s most capable OT threat group, escalated from detection to full compromise in Ukrainian industrial environments, they didn’t drop a zero-day into the engineering workstation. They used pre-compromised OT environments — systems that had already been accessed through legitimate remote-management tools, VPN appliances, and jump hosts that operators relied on every day.

This is the new shape of nation-state OT targeting. The attacker arrives through the same door the vendor’s support engineer uses. They authenticate with credentials the shift supervisor typed in three years ago and never rotated. They move laterally through protocols — Modbus, DNP3, S7comm — that were designed for openness, not authentication, because the engineers who wrote those protocol specifications in the 1970s and 1980s assumed the network itself was physically secure.

When the network is the threat vector and the protocol is the attack surface, zero-days become an expensive luxury. The attacker doesn’t need to break the lock when the door was never installed.


The Three Open Doors

The current wave of nation-state OT targeting exploits three structural weaknesses that signature-based detection tools are fundamentally ill-suited to address.

1. Internet-facing ICS devices. The 4,000-device Iranian campaign wasn’t discovered through a novel intrusion detection signature. It was discovered through internet-wide scanning — the same technique that Shodan and Censys have offered for over a decade. Programmable logic controllers, human-machine interfaces, and engineering workstations are sitting on public IP addresses with weak or default authentication. These aren’t misconfigurations in the traditional IT sense; they’re devices that were deployed before “air-gapped” became industry doctrine, often by system integrators who prioritized remote access for maintenance over network segmentation. A firewall rule change won’t fix the underlying problem when the protocol itself — Modbus TCP, for instance — has no authentication mechanism at all.

2. Pre-compromised remote access pathways. Sandworm’s shift from zero-days to pre-compromised environments is instructive. OT remote access has exploded in the last five years — driven by pandemic-era remote engineering, vendor support contracts that require always-on VPN tunnels, and the simple reality that a water treatment plant in rural Kansas can’t afford a full-time controls engineer on site. Each of those remote access pathways is a trust relationship, and each trust relationship is a potential entry point. When the attacker compromises the vendor’s jump host — not the operator’s — they inherit the legitimate credentials, the approved VPN tunnel, and the scheduled maintenance window. No exploit required.

3. Living-off-the-land in OT. In IT environments, “living off the land” means using PowerShell, WMI, or PsExec — tools already present on the system — to move laterally and evade detection. In OT, living off the land means using the engineering software itself: the same configuration tool the operator uses to upload ladder logic to a PLC, the same HMI scripting interface the integrator uses to adjust alarm thresholds, the same OPC-UA client the data historian uses to poll process values. These are not malware. They will never appear in a signature database. A write to a holding register that changes a pump’s setpoint looks identical, at the protocol level, to a write from the legitimate engineering workstation — because the protocol was designed that way.


What Detection Has to Look Like

If the attacker enters through legitimate credentials, moves through protocols without authentication, and executes actions using the operator’s own engineering tools, what is left for a detection system to detect?

The answer isn’t signatures. The answer is behavioral drift — the gap between what your network normally does and what it’s doing right now.

This is the fundamental premise behind passive, behavioral network detection and response (NDR) in OT environments. Rather than cataloguing every known attack pattern — an approach that, by definition, misses the novel, the credential-abusing, and the living-off-the-land — a behavioral NDR learns the network’s normal communication patterns and flags deviations. Which devices talk to which controllers? At what times? Using which function codes? What are the typical read/write ratios, polling intervals, and connection durations?

When an Iranian threat actor logs into an internet-facing PLC using stolen credentials and begins enumerating the device’s register map at 3 AM local time, that’s detectable — not because the individual Modbus reads are malicious (they’re perfectly valid protocol operations), but because the pattern deviates from normal. The PLC in that facility has never been queried at 3 AM. The function codes being issued don’t match the engineering workstation’s typical polling profile. The source IP is from a segment that has never communicated with the process network.

None of those signals requires a signature. All of them require a baseline.


The Polish Warning in Context

The ABW’s warning about a shift toward physical disruption is not speculative. The 2025 Volt Typhoon campaign against US water utilities demonstrated that nation-state actors are willing to cross the threshold from reconnaissance to operational impact. The Iranian campaign targeting 4,000 devices — while still primarily in the access-and-enumeration phase — represents the reconnaissance that precedes disruption. Nation-state OT campaigns follow a predictable arc: scan for exposed devices, establish persistence through legitimate credentials, map the process network, and wait. The waiting is the hardest signal to detect — because during the waiting, nothing looks like an attack.

This is where the persistent clone — an exact replica of a compromised device running in isolation, fed the same network traffic as the original — becomes a detection instrument rather than a forensic afterthought. If the attacker modifies a PLC’s logic while the clone continues running the known-good configuration, the behavioral delta is immediate and unambiguous. The baseline is a living reference, not a static snapshot.


The Takeaway for OT Operators

The nation-state threat to OT is real, evolving, and increasingly focused on physical consequences. But the attackers’ shift toward credential abuse, pre-compromised environments, and living-off-the-land techniques carries an important implication for defenders: the signals exist. They’re in the network traffic, the protocol-level behavior, and the subtle deviations from normal that no signature will ever catch — but that a network that knows itself will flag every time.

The question isn’t whether your OT network will be targeted. It’s whether you’ll notice when it is.


Maigadi — the OT/ICS network detection & response (NDR) platform that passively learns your network’s normal and detects the novel, signature-less attacks others miss. On-premise. Explainable. Sovereign by design.

See it on your own network.