Supply-Chain Targeting of OT-Adjacent Software Vendors
Suspected state-nexus (unattributed) · 2026-03-08
Observed TTPs
- · Compromise of smaller software vendors serving OT-adjacent clients
- · Trojanized software updates as an initial-access vector
- · Long dwell time before any observable OT-side activity
A recurring theme across our custom-firewall and forensics engagements for critical-infrastructure clients this year has been supply-chain compromise of smaller software vendors — companies too small to be a headline target themselves, but whose software runs inside environments adjacent to operational technology.
The pattern we've observed favors trojanized software updates over direct exploitation: an update package is modified to include a lightweight implant, which then sits dormant for weeks or months before any activity we could directly attribute to it appears on the client side.
This is consistent with an actor prioritizing long-term positioning over immediate impact — the kind of patience typically associated with state-nexus activity, though we have not attributed this cluster to a specific actor.
For clients running OT-adjacent software from smaller vendors, we recommend treating vendor update channels as a distinct trust boundary: verify update signatures independently where possible, and apply the same network segmentation to the vendor's software footprint that you would to the OT environment itself.