News Room
16
Share
DHS Issues Emergency Directive Following Surge in Cyber Intrusions Targeting U.S. Municipal Water and Power Systems
criticalCritical Infrastructure

DHS Issues Emergency Directive Following Surge in Cyber Intrusions Targeting U.S. Municipal Water and Power Systems

A coordinated campaign has compromised industrial control systems in over a dozen facilities across the Midwest and Texas, utilizing evolved OT-specific malware for potential physical sabotage.

20 July 2026Last updated 20 August 20264 min readMandiant
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Critical Infrastructure
Severity:
Critical
Actor Type:
Nation-State
Geography:
North America
Confidence:
High Confidence
Source:
Mandiant
Read Time:
4 min

Executive Summary

Recent intelligence indicates a significant escalation in cyber operations targeting U.S. critical infrastructure. Over the last 48 hours, the Department of Homeland Security (DHS) has confirmed breaches at multiple municipal water treatment and power distribution centers across the Midwest and Texas. These intrusions utilize advanced techniques to bypass traditional perimeter defenses and directly interact with Operational Technology (OT) and Industrial Control Systems (ICS). While federal cyber defense teams have isolated the compromised nodes, the scale of the campaign suggests a well-resourced adversary preparing for potential kinetic disruption.

Threat Analysis

The campaign displays a sophisticated understanding of ICS protocols, specifically Modbus TCP and DNP3. Unlike typical ransomware operations which focus on financial gain, the primary objective here appears to be pre-positioning for disruptive effects. The attackers are leveraging a successor to the 'FrostyGoop' malware family, dubbed 'FrostyV2' (or BUSTLEBERM.EVO), which enables remote manipulation of control registers without requiring a persistent backdoor on the local Human-Machine Interface (HMI). This allows actors to alter physical processes, such as chemical dosing in water systems or circuit breaker status in power grids, with minimal digital footprint.

Technical Details

Initial access was achieved via zero-day vulnerabilities in regional ISP-managed edge routers and VPN gateways. Once inside the enterprise IT network, actors performed lateral movement using legitimate administrative credentials harvested through highly targeted spear-phishing conducted earlier this month. Upon reaching the OT segment, the 'FrostyV2' payload was deployed to programmable logic controllers (PLCs). The malware is written in Golang and communicates on Port 502, masquerading as routine industrial polling traffic. Technical analysis shows the malware can read/write to holding registers, potentially spoofing sensor data to operators while simultaneously executing malicious commands to the physical hardware.

Attribution Assessment

Mandiant assesses with high confidence that the activity is linked to a cluster associated with the Russian Federal Security Service (FSB), specifically the group tracked as 'Center 16' (also known as 'UNC3313'). This assessment is based on tactical overlaps with previous campaigns targeting European energy grids and the use of customized command-and-control (C2) infrastructure previously observed in operations against Ukrainian district heating utilities. The timing correlates with increased diplomatic tensions, suggesting the activity serves as a signal of strategic capability.

Implications

This surge marks a shift from opportunistic probing to coordinated readiness for infrastructure sabotage within the continental United States. The exposure of fundamental digital architecture in mid-sized U.S. municipalities highlights critical gaps in regional cybersecurity funding and the persistence of unpatched legacy systems. A successful disruption during the current high-heat season could result in compromised water quality or localized blackouts, posing a direct threat to public safety and economic stability.

Recommendations

Organizations must implement strict network segmentation between IT and OT environments, ensuring no direct paths exist from the internet to ICS hardware. Immediate auditing of all internet-facing devices is required, with a focus on disabling unnecessary services on Port 502 (Modbus). Multi-factor authentication (MFA) must be enforced for all remote access gateways. Security teams should prioritize the deployment of specific detection signatures for the 'FrostyV2' communications profile and monitor for unauthorized Modbus 'Write Single Register' commands originating from non-engineering workstations.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo