Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

Article Types

Countries / Regions

Search Results (4)

Search Parameters:
Keywords = state-sponsored cyber operations

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
17 pages, 3766 KB  
Article
Living Off the Land Attacks on IEC 61850 Substations
by Robin Eriksen Birkeland and Siv Hilde Houmb
Appl. Sci. 2026, 16(13), 6693; https://doi.org/10.3390/app16136693 - 3 Jul 2026
Viewed by 724
Abstract
Power from Shore (PfS) is becoming more widespread for offshore petroleum installations, which have introduced new dependencies and the potential for a single point of failure. In addition, the cyber threat landscape is increasing, with state-sponsored actors demonstrating the capabilities and willingness to [...] Read more.
Power from Shore (PfS) is becoming more widespread for offshore petroleum installations, which have introduced new dependencies and the potential for a single point of failure. In addition, the cyber threat landscape is increasing, with state-sponsored actors demonstrating the capabilities and willingness to target Operational Technology (OT) systems. Threat actors have been seen using living off the land techniques, such as with the Industroyer malware, which utilized legitimate but malicious IEC 104 commands to open circuit breakers. To evaluate these vulnerabilities, in this study, a Design Science Research approach was applied to map a generalized substation and develop a Software-in-the-Loop simulator, which was used to test a specific attack vector against substation automation systems. The results confirm that an adversary with local network access can successfully inject valid IEC 61850 Manufacturing Message Specification (MMS) commands to trigger unauthorized circuit breaker operations. Furthermore, it is also shown that a simulated substation can be used as a tool when developing OT malware. Full article
(This article belongs to the Section Electrical, Electronics and Communications Engineering)
Show Figures

Figure 1

24 pages, 3662 KB  
Article
Maritime Industry Cybersecurity Threats in 2025: Advanced Persistent Threats (APTs), Hacktivism and Vulnerabilities
by Minodora Badea, Olga Bucovețchi, Adrian V. Gheorghe, Mihaela Hnatiuc and Gabriel Raicu
Logistics 2025, 9(4), 178; https://doi.org/10.3390/logistics9040178 - 18 Dec 2025
Cited by 4 | Viewed by 5436
Abstract
Background: The maritime industry, vital for global trade, faces escalating cyber threats in 2025. Critical port infrastructures are increasingly vulnerable due to rapid digitalization and the integration of IT and operational technology (OT) systems. Methods: Using 112 incidents from the Maritime [...] Read more.
Background: The maritime industry, vital for global trade, faces escalating cyber threats in 2025. Critical port infrastructures are increasingly vulnerable due to rapid digitalization and the integration of IT and operational technology (OT) systems. Methods: Using 112 incidents from the Maritime Cyber Attack Database (MCAD, 2020–2025), we developed a novel quantitative risk assessment model based on a Threat-Vulnerability-Impact (T-V-I) framework, calibrated with MITRE ATT&CK techniques and validated against historical incidents. Results: Our analysis reveals a 150% rise in incidents, with OT compromise identified as the paramount threat (98/100 risk score). Ports in Poland and Taiwan face the highest immediate risk (95/100), while the Panama Canal is assessed as the most probable next target (90/100). State-sponsored actors from Russia, China, and Iran are responsible for most high-impact attacks. Conclusions: This research provides a validated, data-driven framework for prioritizing defensive resources. Our findings underscore the urgent need for engineering-grade solutions, including network segmentation, zero-trust architectures, and proactive threat intelligence integration to enhance maritime cyber resilience against evolving threats. Full article
Show Figures

Figure 1

44 pages, 3307 KB  
Review
Evolution Cybercrime—Key Trends, Cybersecurity Threats, and Mitigation Strategies from Historical Data
by Muhammad Abdullah, Muhammad Munib Nawaz, Bilal Saleem, Maila Zahra, Effa binte Ashfaq and Zia Muhammad
Analytics 2025, 4(3), 25; https://doi.org/10.3390/analytics4030025 - 18 Sep 2025
Cited by 10 | Viewed by 26412
Abstract
The landscape of cybercrime has undergone significant transformations over the past decade. Present-day threats include AI-generated attacks, deep fakes, 5G network vulnerabilities, cryptojacking, and supply chain attacks, among others. To remain resilient against contemporary threats, it is essential to examine historical data to [...] Read more.
The landscape of cybercrime has undergone significant transformations over the past decade. Present-day threats include AI-generated attacks, deep fakes, 5G network vulnerabilities, cryptojacking, and supply chain attacks, among others. To remain resilient against contemporary threats, it is essential to examine historical data to gain insights that can inform cybersecurity strategies, policy decisions, and public awareness campaigns. This paper presents a comprehensive analysis of the evolution of cyber trends in state-sponsored attacks over the past 20 years, based on the council on foreign relations state-sponsored cyber operations (2005–present). The study explores the key trends, patterns, and demographic shifts in cybercrime victims, the evolution of complaints and losses, and the most prevalent cyber threats over the years. It also investigates the geographical distribution, the gender disparity in victimization, the temporal peaks of specific scams, and the most frequently reported internet crimes. The findings reveal a traditional cyber landscape, with cyber threats becoming more sophisticated and monetized. Finally, the article proposes areas for further exploration through a comprehensive analysis. It provides a detailed chronicle of the trajectory of cybercrimes, offering insights into its past, present, and future. Full article
Show Figures

Figure 1

23 pages, 369 KB  
Review
CNA Tactics and Techniques: A Structure Proposal
by Antonio Villalón-Huerta, Ismael Ripoll-Ripoll and Hector Marco-Gisbert
J. Sens. Actuator Netw. 2021, 10(1), 14; https://doi.org/10.3390/jsan10010014 - 10 Feb 2021
Cited by 4 | Viewed by 5482
Abstract
Destructive and control operations are today a major threat for cyber physical systems. These operations, known as Computer Network Attack (CNA), and usually linked to state-sponsored actors, are much less analyzed than Computer Network Exploitation activities (CNE), those related to intelligence gathering. While [...] Read more.
Destructive and control operations are today a major threat for cyber physical systems. These operations, known as Computer Network Attack (CNA), and usually linked to state-sponsored actors, are much less analyzed than Computer Network Exploitation activities (CNE), those related to intelligence gathering. While in CNE operations the main tactics and techniques are defined and well structured, in CNA there is a lack of such consensuated approaches. This situation hinders the modeling of threat actors, which prevents an accurate definition of control to identify and to neutralize malicious activities. In this paper, we propose the first global approach for CNA operations that can be used to map real-world activities. The proposal significantly reduces the amount of effort need to identify, analyze, and neutralize advanced threat actors targeting cyber physical systems. It follows a logical structure that can be easy to expand and adapt. Full article
(This article belongs to the Special Issue Security Threats and Countermeasures in Cyber-Physical Systems)
Show Figures

Figure 1

Back to TopTop