Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
critical-infrastructure-threatstate-sponsored-disruptiontelecommunications-sector-threatstate-sponsored-espionage

Geopolitical Cyber Operations Targeting Critical Infrastructure and Economic Systems

Updated 3mo agoFirst seen Jan 14, 20263 sources

Reporting and commentary highlighted how state-linked cyber activity is being used for sustained pressure against critical infrastructure and economic targets rather than isolated, one-off attacks. Taiwan’s government and related reporting described China-linked probing and “prepositioning” against Taiwanese critical infrastructure as ongoing and scaling, consistent with reconnaissance and access maintenance objectives that could enable future disruption. Separately, an op-ed argued that U.S. signaling around the ability to “darken” parts of Caracas and reported disruptions affecting Venezuela’s state oil sector illustrate how cyber-enabled interference can function as a tool of state power below the threshold of open conflict.

A longer-form retrospective on the Russia–Ukraine conflict framed the period as a “full-scale cyber war,” citing the Kyivstar destructive attack attributed to Sandworm as a landmark incident: attackers reportedly maintained access for months before wiping large portions of the operator’s environment, disrupting telecom and related services. The same piece described Ukraine’s broader incident volume growth and the use of multiple wiper malware families, alongside claims of Ukrainian retaliatory operations (e.g., DDoS activity against Russian banking), reinforcing the theme that critical infrastructure and national economic systems are central targets in modern geopolitical cyber campaigns. While one weekly “signals” post also mentioned patch/KEV dynamics and SaaS exposure as near-term risk amplifiers, its primary geopolitical takeaway aligned with the broader pattern of sustained state-linked activity against critical infrastructure.

Share:
Geopolitical Cyber Operations Targeting Critical Infrastructure and Economic Systems
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Jan 14, 20265mo ago

UAC-0190 uses charity lures to target Ukraine-related entities

The Hunt.io blog reports that Kremlin-linked UAC-0190 is using charity-themed lures delivered through messaging apps to deploy PluggyApe against Ukraine-related targets. This reflects a newly described tactic and targeting pattern in the campaign.

Reports describe sustained China-linked probing of Taiwan infrastructure

Reporting published in mid-January 2026 describes ongoing, scaling China-linked cyber activity against Taiwan's critical infrastructure. The activity is assessed as reconnaissance, access maintenance, and prepositioning rather than a single isolated incident.

CISA retires legacy Emergency Directives

CISA is reported to be retiring legacy Emergency Directives, consolidating urgent remediation expectations around the KEV catalog and Binding Operational Directive 22-01. This marks a policy and operational shift in how federal cyber remediation priorities are communicated.

AuraInspector highlighted for Salesforce exposure-path auditing

New tooling called AuraInspector was highlighted as a way to audit Salesforce Aura and Experience Cloud exposure paths associated with misconfiguration-style data exposure. The reporting emphasizes that these cloud/SaaS risks may lack a traditional patch signal.

Brightspeed confirms investigation into claimed data-theft incident

Brightspeed confirmed it is investigating a security incident after criminals claimed to have stolen data and threatened to publish it. The report presents this as an active extortion-related breach development.

January Patch Tuesday and new KEV additions raise exploitation risk

In January 2026, Patch Tuesday activity and newly added entries in CISA's Known Exploited Vulnerabilities catalog increased near-term risk for internet-exposed and patch-lagged organizations. The reporting frames this as a meaningful escalation in defender urgency around exploitation exposure.

React2Shell vulnerability remains under active exploitation

The Hunt.io blog reports that React2Shell (CVE-2025-55182) is continuing to be actively exploited across React and Next.js environments. This indicates an ongoing exploitation phase rather than a newly disclosed issue.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

12 LINKEDOpen in app
Vulnerabilities
1 linked
Threat actors
1 linked
Malware
1 linked
Organizations
9 linked
SalesforceAlphaHuntMicrosoft CorporationBrightspeedBinary DefenseAppleLockheed MartinVercelGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.