site-logo
site-logo
site-logo

The OT Lull: What a 30-day decline in direct intrusion activity actually tells us  

The OT Lull: What a 30-day decline in direct intrusion activity actually tells us  

The OT Lull: What a 30-day decline in direct intrusion activity actually tells us  

OT Cyberattack
author

Prayukth K V

Over the past 30 days, telemetry data analysed across Shieldworkz honeypot environments revealed a notable shift: direct intrusion attempts targeting Operational Technology (OT) and Industrial Control System (ICS) assets have reduced a bit.

 To an untrained observer or a corporate board scanning high-level metrics, a drop in direct probes against Level 2 and Level 3 OT assets could convey a wrong message. However, interpreting a month of quiet honeypot telemetry as a true reduction in risk is one of the most dangerous miscalculations an organization can make.

 The underlying data suggests a more nuanced reality. The apparent cooling of direct OT intrusions does not in any way signal that advanced threat actors have abandoned their critical infrastructure objectives. Rather, it reflects a shift or a possible redirection of operational mechanics. Threat actors appear to be trading high-visibility, brute-force initial access attempts against OT assets for deep reconnaissance within existing footholds and aggressive compromises across less-defended municipal and utility IT networks.

The OT lull: What the telemetry data reveals

To evaluate this trend properly, we must strictly separate observed telemetry from analytical interpretation.

Observed telemetry

  • Direct Probing Volume: Shieldworkz honeypots mimicking OT/ICS services such as Modbus, DNP3, Ethernet/IP, and vendor-specific engineering interfaces recorded a marked decline in direct, external intrusion attempts over the past month.

  • Regional Activity Shifts: While direct OT honeypot interactions declined, active operations against energy-adjacent networks in Europe and water utility environments across the Americas maintained a high tempo.

Analytical Interpretation

  • The reduction in direct inbound probes to OT honeypots indicates that adversaries are initiating fewer broad-spectrum, fresh initial-access attempts against exposed industrial devices.

  • This lack of inbound honeypot traffic does not prove that existing, unmonitored production OT networks are clear of adversary presence.

A 30-day window represents a brief snapshot in threat actor campaign cycles. Treating a short-term drop in inbound honeypot activity as evidence of an overall decline in threat actor intent conflates detection visibility with actual adversary operational tempo.

What could explain the decline?

When adversary probes drop across internet-facing telemetry without a corresponding geopolitical resolution or law enforcement takedown, three operational hypotheses emerge:

 Hypothesis A: Attacker Fatigue and Campaign Lifecycle Pauses

The high-tempo campaign cycle observed through mid-2026 placed significant operational strain on threat actors. Maintaining active, multi-stage intrusion pipelines requires continuous infrastructure replenishment, credential harvesting, and payload customization. A temporary lull often follows operational burnout or resource depletion, during which threat groups pause mass-scanning initiatives to retool, rotate infrastructure, and process exfiltrated data.

Hypothesis B: Foothold Consolidation Over Fresh Access

Adversaries that successfully gained access during earlier 2026 campaigns may no longer need to conduct noisy initial-access probes. Rather than burning operational infrastructure to harvest new initial access points, state-sponsored and financially motivated actors frequently shift into an internal maintenance phase. During this phase, efforts focus on establishing persistent secondary access, elevating privileges, and auditing previously compromised environments.

Hypothesis C: Stage-2 Internal Reconnaissance

The observed data aligns closely with observed patterns wherein adversaries already inside operational or enterprise networks pivot to internal reconnaissance and traffic monitoring. This includes mapping network topology, identifying human-machine interfaces (HMIs), locating engineering workstations (EWS), identifying key personnel, windows of attack opportunity and parsing industrial protocol flows. This activity occurs entirely within internal boundary zones and creates zero footprint on external-facing honeypots.

The attackers have not gone away

While direct probes against isolated OT assets dropped, adversary activity across municipal and utility IT environments warmed significantly over the exact same period.


European Utility Infrastructure

In Europe, state-sponsored groups—specifically Sandworm, APT28, and APT29—have maintained focused operations targeting energy and utility-adjacent networks. Rather than attempting direct network exploitation against hardened supervisory control and data acquisition (SCADA) systems, these groups continue to compromise corporate IT, administrative, and third-party vendor systems connected to energy providers.

Americas Water Sector

In the Americas, telemetry points to expanded, multi-state intrusions targeting municipal water utilities. Small to mid-sized municipal operators routinely manage water treatment and distribution infrastructure using centralized IT management platforms that lack dedicated OT security personnel, robust multi-factor authentication (MFA), or strict network segmentation.

IT environments as the gateway to critical infrastructure

The operational shift toward municipal and utility IT is a key observed and analyzed trend that merits a deeper commentary. Adversaries recognize that breaching Level 3 OT directly often requires bypassing jump hosts, handling proprietary vendor protocols, and risking immediate detection via specialized OT anomaly monitoring.

By expanding threat activities to involve enterprise municipal IT systems, threat actors gain several strategic advantages:

  • Shared credential trust: Municipal administrative networks frequently utilize shared domain controllers, single sign-on (SSO) configurations, or legacy VPNs that span both administrative IT and utility operations.

  • Dual-homed management workstations: IT systems in smaller municipal utilities often host dual-homed remote management software (such as TeamViewer, RDP, LogMeIn) used by operators to monitor field assets, offering an unmonitored path past network firewalls.

  • Reduced detection velocity: Municipal IT networks typically generate significant operational noise and often lack round-the-clock Security Operations Center (SOC) coverage, giving adversaries weeks or months to conduct reconnaissance undetected.

This positioning validates the assessment that current market conditions reflect target substitution, not risk reduction. Municipal IT compromise could act as the staging ground for subsequent OT-adjacent disruption.

What the data cannot tell us: Limitations of telemetry

Rigorous intelligence analysis requires acknowledging the boundaries of our collection assets:

  • Honeypot telemetry bias: Honeypots measure opportunistic internet-wide scanning and low-hanging external probing. They cannot capture targeted, living-off-the-land (LotL) tactics executed via compromised valid credentials inside a private utility network.

  • 30-Day window limitations: A single month of data cannot establish a multi-year macro trend. Threat actor activity fluctuates based on development cycles, geopolitical mandates, and infrastructure changes.

  • Attribution and intent boundaries: Probing telemetry alone cannot reveal an adversary's ultimate objective. An actor collecting screenshots of an enterprise network configuration may be conducting routine intelligence gathering or quietly preparing for a destructive wiper campaign.

Having said that, the purpose behind writing this article is to make OT security teams acknowledge this lull and stir a discussion on the possible reasons for it.

Defensive action plan: What OT security teams and SOCs must watch

To mitigate the risks associated with this shift, security teams must pivot their detection strategies from external boundary probing to internal lateral movement.

 


 

Strategic Recommendations for SOCs, CISOs, and OT Operators

Treat IT-OT Jump Hosts as High-Risk Assets

  • Require strict, hardware-backed MFA for all remote access paths linking corporate/municipal IT to OT boundary zones.

  • Terminate all persistent administrative sessions crossing the Purdue Model Level 3 boundary.

Audit Dual-Homed and Remote Management Software

  • Identify and remove unauthorized remote access tools (such as AnyDesk, ScreenConnect, TeamViewer) across all municipal utility administrative endpoints.

  • Enforce strict IP whitelisting and session logging for authorized remote management tools.

Increase Internal Reconnaissance Detections

  • Implement behavioral alerts for credential harvesting tools (e.g., Mimikatz, LSASS memory dumping) and internal subnet scanning within corporate IT environments.

  • Monitor active directory logs for unusual service principal name (SPN) querying or abnormal domain admin privilege escalation attempts.

Monitor Engineering Workstations for Stage-2 Indicators

  • Audit file system changes, unauthorized software installation, and unexpected project file modifications on Engineering Workstations (EWS) and Human-Machine Interfaces (HMIs).

  • Enforce strict baseline checks for programmable logic controller (PLC) and remote terminal unit (RTU) logic downloads, treating unscheduled configuration changes as active security incidents.

The available telemetry is more consistent with an operational shift than with evidence of a strategic retreat and it has to be noted that the 30-day observation (on its own) is not sufficient to establish that conclusion. Treating this lull as a signal to ease defensive posture misinterprets honeypot metrics and overlooks adversary behavior.

As state-sponsored groups and critical-infrastructure actors consider a pivot toward less-resourced municipal and utility IT environments, enterprise security teams must recognize that the perimeter has shifted. The primary threat to industrial operations today is rarely an immediate zero-day strike on an isolated PLC. Instead it is the quiet, persistent consolidation of access across enterprise IT networks that eventually grant adversaries unmonitored access to the physical control loop.

Access the Shieldworkz Threat Intelligence update document for H1 2026

Dossier on threat actor FulcrumSec

 

 

Get Weekly

Resources & News

See How Our Industry-Leading OT Security Solutions Address Critical Security Challenges

You may also like

BG image

Get Started Now

Scale your CPS security posture

Get in touch with our CPS security experts for a free consultation.

BG image

Get Started Now

Scale your CPS security posture

Get in touch with our CPS security experts for a free consultation.

BG image

Get Started Now

Scale your CPS security posture

Get in touch with our CPS security experts for a free consultation.