A joint advisory from CISA, NSA, and NCSC has identified specific tactics being deployed against operational technology (OT) environments. According to the intelligence, attackers are abusing legitimate SCADA management software to establish lateral movement within compromised networks — a technique that exploits trust placed in vendor-approved tools.
The same actors are employing Living Off the Land Binaries (LOLbin) attack chains — specifically certutil, ntdsutil, and wmic — to evade endpoint detection and response (EDR) systems. This approach minimizes forensic signatures and allows persistence without deploying custom malware.
A third element compounds the risk: compromised residential SOHO routers are being staged as rotating proxy infrastructure. This suggests attackers are using consumer-grade network devices as obfuscation points, likely to distribute traffic across multiple exit nodes and complicate attribution.
Why this matters: OT networks power critical infrastructure — power distribution, water treatment, manufacturing. Unlike IT environments, OT systems often run legacy software with limited patch cycles and defense-in-depth controls. SCADA software abuse is particularly dangerous because administrators grant it broad system permissions by design. Once inside, an attacker using LOLbins remains difficult to detect because these Windows utilities are expected to run on any system.
The use of residential routers as proxy staging suggests this is not opportunistic. It indicates planning, reconnaissance, and infrastructure preparation — hallmarks of persistent, targeted campaigns.
The advisory's focus on OT–IT segmentation and VPN configuration is specific and actionable: these controls create friction for lateral movement and limit the blast radius if one segment is compromised. Segregation means an attacker cannot simply pivot from corporate IT into operational networks using standard lateral movement techniques.

