Operational Twilight: APTs, OT, & geopolitics of a dying climate
Cybelle Oliveira (Lavilla Hacker)
DEF CON 33 · Day 1 · Main Stage
Overview
In an increasingly volatile global landscape, Cybelle Oliveira, a prominent CTI researcher and founder of Lavilla Hacker, presented a compelling and urgent talk at DEF CON titled "Operational Twilight: APTs, OT, & geopolitics of a dying climate." Her presentation unveiled a critical and often overlooked nexus: the strategic weaponization of extreme weather and climate events by nation-state Advanced Persistent Threats (APTs) to amplify the impact of cyberattacks on critical infrastructure. Oliveira argues that this emerging threat vector demands a fundamental shift in how the cybersecurity community approaches defense, particularly in the realm of Operational Technology (OT).

Key moments
- 0:00 Introduction: CTI, climate, geopolitics, and APTs
- 2:00 Worst threat landscape and climate infrastructure targets
- 2:30 APTs abusing extreme weather conditions for attacks
- 3:15 Massive increase in critical infrastructure cyber attacks
- 4:10 Expanding attack surface and legacy OT vulnerabilities
- 7:40 APTs now intentionally exploiting climate infrastructure for impact
- 8:00 Nation-states developing climate warfare doctrines
- 9:00 Attacks impact civilians, not just military targets
Operational Twilight: APTs, OT, & geopolitics of a dying climate
Speakers: Cybelle Oliveira (Lavilla Hacker)
Conference: DEF CON
YouTube: https://www.youtube.com/watch?v=Ekp5iMPEgVw
Overview
In an increasingly volatile global landscape, Cybelle Oliveira, a prominent CTI researcher and founder of Lavilla Hacker, presented a compelling and urgent talk at DEF CON titled "Operational Twilight: APTs, OT, & geopolitics of a dying climate." Her presentation unveiled a critical and often overlooked nexus: the strategic weaponization of extreme weather and climate events by nation-state Advanced Persistent Threats (APTs) to amplify the impact of cyberattacks on critical infrastructure. Oliveira argues that this emerging threat vector demands a fundamental shift in how the cybersecurity community approaches defense, particularly in the realm of Operational Technology (OT).
The core of Oliveira's research highlights a disturbing trend where geopolitical conflicts, driven by nation-states, are converging with the escalating climate crisis. APT groups are no longer merely seeking economic disruption or espionage; they are actively learning to exploit weather conditions—such as severe winters, intense heatwaves, or floods—to maximize physical damage, create chaos, and achieve broader strategic objectives like political destabilization and military advantage. This intentional leveraging of environmental stressors transforms climate infrastructure from a secondary consideration into a primary, high-value target for adversaries.
This talk is crucial because it redefines the scope of cyber warfare, pushing beyond traditional IT targets to encompass the physical world and its environmental vulnerabilities. As global conflicts intensify and climate change manifests in more extreme ways, understanding this intersection is vital for defenders. Oliveira's work provides a stark warning and a call to action, urging the cybersecurity community to integrate climate and geopolitical intelligence into their threat models and defensive strategies to protect human lives and essential services from this evolving and devastating form of cyber-physical warfare.
Background
▶ Watch: Introduction: CTI, climate, geopolitics, and APTs (0:00)
The global cybersecurity landscape is currently being reshaped by an unprecedented confluence of geopolitical conflicts and the accelerating impacts of climate change. Cybelle Oliveira emphasized that these aren't isolated phenomena but rather interacting forces that create a uniquely perilous environment for critical infrastructure. The widespread digitalization of industrial and Operational Technology (OT) systems, often built upon legacy architectures, has dramatically expanded the attack surface for sophisticated adversaries.
Many critical infrastructure systems, particularly those governing utilities like power grids, water treatment, and transportation, rely on decades-old protocols and hardware. These legacy OT systems, often designed without modern security considerations, present inherent vulnerabilities that are difficult and expensive to remediate. Oliveira highlighted that while IT systems have seen continuous security improvements, OT environments, which often dictate physical processes (e.g., IECs), remain a soft underbelly. This problem is exacerbated by the sheer scale of interconnected devices; Oliveira cited estimates of 50 billion connected devices, ranging from industrial controllers to consumer-grade solar panels and smart home systems, all contributing to an ever-growing attack surface.
Historically, nation-state APTs have focused on objectives like espionage, intellectual property theft, or economic disruption. However, the current geopolitical climate, marked by conflicts in regions like Ukraine, Gaza, and numerous other flashpoints globally, has shifted the focus towards more destructive and destabilizing operations. Oliveira provided alarming statistics: in the last year alone, there were confirmed incidents in critical infrastructure at a rate of approximately three per week, with a staggering 89% of these causing real physical damage. Even more concerning, 67% of these incidents were timed to coincide with extreme weather events, indicating a deliberate strategy rather than mere coincidence. The sheer volume of attacks is staggering, with 420 million attacks on critical infrastructure reported in the last couple of years—a 30% increase—and an estimated 13 attacks per second globally. These figures underscore a critical reality: adversaries are not merely probing; they are actively and frequently engaging in destructive cyber operations against the physical world.
Key Findings
▶ Watch: APTs abusing extreme weather conditions for attacks (2:30)
Cybelle Oliveira's research uncovers several critical findings that redefine the understanding of nation-state APT activity and its implications for global security:
First, a paradigm shift in APT strategy has occurred: adversaries are now intentionally abusing weather conditions to maximize the destructive impact of their cyberattacks. Instead of climate impacts being an unintended consequence, they are becoming a calculated factor in attack planning. This means targeting systems during periods of extreme cold, heat, or flooding to amplify human suffering, cause greater infrastructure damage, and create widespread chaos.
Second, climate infrastructure is emerging as a primary strategic target for nation-state APTs, moving beyond its previous status as a secondary or incidental target. Adversaries recognize the immense strategic value in disrupting essential services tied to climate resilience, such as energy grids, water treatment facilities, and agricultural systems. The ability to control or disrupt these elements during times of environmental stress offers significant geopolitical leverage, potentially more so than traditional economic or data-centric targets.
Third, Oliveira identified at least 12 distinct nation-state APT groups actively targeting climate infrastructure. Key players in this evolving domain include Russia, Ukraine, China, and North Korea, all of whom are reportedly developing specific warfare doctrines that incorporate environmental cyber warfare tactics. For instance, Russia has demonstrated a clear preference for launching attacks during winter, leveraging cold temperatures to compound the effects of energy grid disruptions.
Fourth, the pervasive use of legacy OT protocols, such as Modbus, presents easily exploitable and highly effective attack vectors. These protocols, designed in an era without modern security concerns, lack fundamental safeguards like authentication, encryption, or integrity checks, making them extremely vulnerable to manipulation. This allows APTs to achieve significant physical impact without necessarily employing sophisticated zero-day exploits.
Finally, the talk highlighted the FrostGroup (also known as Sandworm or APT28) attack in Ukraine as a quintessential example of this new era of cyber-physical warfare. This incident, which targeted a municipal district energy company, demonstrated the perfect convergence of weather correlation, minimal operational footprint, and the exploitation of inherently insecure protocols to cause profound physical disruption and human suffering. The sophisticated, Go-based malware used in this attack, likely a variant of Industroyer2, underscored the capabilities of these groups to craft tools specifically for OT environments.
Technical Deep Dive
▶ Watch: Expanding attack surface and legacy OT vulnerabilities (4:10)
The technical core of Cybelle Oliveira's presentation centered on the inherent vulnerabilities within Operational Technology (OT) environments and how nation-state APTs are exploiting them. She emphasized that many of these systems, crucial for managing physical processes, were designed decades ago without security in mind, making them ripe targets.
A prime example is the Modbus protocol. Developed in 1979, Modbus is a serial communication protocol that has become a de facto standard in industrial automation. Its ubiquity in devices like thermostats, pumps, sensors, and programmable logic controllers (PLCs) makes it a critical component of many industrial and climate-related infrastructures. Oliveira underscored its fundamental security flaws: Modbus operates in plain text, meaning all commands and data are transmitted unencrypted and unauthenticated. It lacks encryption, integrity checks, and access control mechanisms. As Oliveira starkly put it, "it's just plain text, it's no just there easy say hey attack me."
This lack of security means that an attacker who gains network access to a Modbus-enabled device can easily read its state or issue commands without any form of authentication. For instance, modifying a temperature setpoint in a heating system, as demonstrated by the potential of a "single register command," can be trivial. Oliveira's Shodan scan in July showed numerous instances of Port 502, the standard Modbus TCP port, openly exposed to the internet, illustrating the vast attack surface.
The most compelling technical case study presented was the FrostGroup attack in Ukraine, attributed to Sandworm (APT28). This incident targeted a municipal district energy company during a period of severe winter cold, resulting in a two-day outage of heating systems for approximately 3,000 people. The attack leveraged a sophisticated Go-based malware, identified by Dragos as Industroyer2 (or variants like FoxNet, NetFootNet), which demonstrated key technical characteristics:
- Cross-platform compatibility: Developed in Go, the malware could execute on Windows, Linux, and various industrial controllers.
- Static linking and no dependencies: This made the malware highly portable and capable of operating effectively even in air-gapped systems or networks with limited external connectivity.
- Minimal footprint: With reportedly only around 200 lines of code, the malware was efficient and stealthy, making detection difficult.
- Protocol exploitation: Instead of relying on zero-day vulnerabilities, the attack primarily exploited the inherent insecurities of OT protocols like Modbus and other TCP/IP-based industrial communication. This meant the attack was effective not because of novel software flaws, but because of the fundamental design weaknesses of the targeted systems.
The attackers achieved "weather correlation perfection," timing their operation to maximize the physical and social impact of the heating system disruption. This involved understanding the operational context of the target, the critical role of heating in extreme cold, and the vulnerabilities of the underlying control systems.
Oliveira also highlighted the expansion of the "green" attack surface. As nations invest in renewable energy sources like solar farms, wind farms, and emerging technologies like hydrogen farms (particularly prevalent in Germany), these new infrastructures often incorporate existing, vulnerable OT components. This creates a paradox: efforts to combat climate change through new energy sources inadvertently introduce new, critical targets for cyber adversaries who can exploit the same legacy protocols and architectural weaknesses. The ease with which these systems can be manipulated—from altering temperature points in HVAC systems to disrupting critical processes in water treatment plants or desalinization facilities—underscores the profound physical and environmental consequences of these cyber intrusions.
Demo / Proof of Concept
▶ Watch: APTs now intentionally exploiting climate infrastructure for impact (7:40)
The talk did not feature a live demonstration or proof of concept. As a CTI researcher, Cybelle Oliveira's focus is on identifying and analyzing threats rather than demonstrating exploitation techniques. Instead, she highlighted the inherent vulnerabilities in critical infrastructure, particularly legacy Operational Technology (OT) protocols like Modbus, and provided concrete examples of how nation-state adversaries have exploited these weaknesses, such as the FrostGroup attack in Ukraine, to achieve significant physical and environmental impact. Her role, as she stated, is to "tell you, hey guys, please fix this," rather than show how to break it.
Defensive Implications
▶ Watch: Attacks impact civilians, not just military targets (9:00)
Cybelle Oliveira's presentation offers critical insights for defenders, necessitating a multi-faceted approach to security that transcends traditional IT-centric models. The convergence of geopolitics, climate, and OT attacks demands a proactive and integrated defense strategy.
Firstly, urgent remediation of legacy OT vulnerabilities is paramount. Protocols like Modbus, with their fundamental lack of authentication, encryption, and access control, represent an open invitation to adversaries. While the cost of modernizing entire OT infrastructures is substantial, organizations must prioritize patching, implementing secure gateways, and exploring secure overlays or wrappers for these vulnerable protocols. The speaker's call to "fix this" must be heeded, acknowledging that these systems were never designed for the internet-connected, hostile environment they now inhabit.
Secondly, security by design must be a core principle for all new critical infrastructure, especially in the rapidly expanding "green" sector. As solar farms, wind farms, hydrogen farms, and future technologies like fusion power plants become integral to national infrastructure, their underlying control systems must incorporate robust security from inception. Merely layering new energy technologies on old, insecure OT foundations is an unacceptable risk.
Thirdly, enhanced threat intelligence is crucial. CTI teams must expand their scope to integrate geopolitical intelligence and climate data into their threat models. Understanding the motivations and capabilities of nation-state actors (e.g., Russia's preference for winter attacks, Iran's regional objectives) and correlating these with predicted extreme weather events allows for more accurate forecasting of potential attack windows and targets. Oliveira's proposed framework, which combines traditional CTI with these new dimensions, is a vital step towards this.
Fourth, robust network segmentation and isolation between IT and OT networks are non-negotiable. While convergence offers operational benefits, the security disparity between IT and OT mandates strict logical and physical separation to prevent IT breaches from cascading into critical physical systems. Implementing unidirectional gateways (data diodes) for data flow from OT to IT can further enhance security.
Fifth, continuous monitoring and anomaly detection in OT environments need significant investment. Given that attacks like Industroyer2 can have a minimal footprint and exploit protocols rather than vulnerabilities, detecting unusual commands or deviations from normal operating parameters is critical. This requires specialized OT security solutions capable of understanding industrial protocols and behaviors.
Sixth, organizations must develop comprehensive incident response plans that account for cascading physical and environmental consequences. A cyberattack on a power grid during a heatwave, for example, is not just a technical incident; it's a public health crisis. Response plans must involve not only IT and OT teams but also emergency services, public health officials, and government agencies to mitigate human suffering and broader societal disruption.
Finally, addressing supply chain vulnerabilities in OT is increasingly important. As AI enhances environmental warfare capabilities, and as global supply chains become more interconnected, securing the entire lifecycle of industrial components and software is essential to prevent pre-compromise or backdoors that could be exploited by nation-state actors. International cooperation and information sharing are also vital to collectively raise defenses against these globally coordinated threats.
Key Takeaways
- Weaponized Weather: Nation-state APTs are deliberately timing cyberattacks on critical infrastructure to coincide with extreme weather events, amplifying physical damage and human impact for strategic geopolitical gain.
- Legacy OT Vulnerability: Decades-old Operational Technology (OT) protocols like Modbus are inherently insecure, lacking authentication, encryption, and integrity checks, making them prime targets for adversaries to cause physical disruption without complex exploits.
- FrostGroup Case Study: The Sandworm (APT28) attack in Ukraine, using Go-based Industroyer2 malware, demonstrated a sophisticated, weather-correlated cyber-physical assault that caused significant heating outages by exploiting insecure protocols.
- Strategic Environmental Impact: The environmental consequences of cyberattacks, such as increased carbon emissions from backup power sources or disruption of water supplies, are no longer collateral damage but are becoming direct strategic objectives for nation-state actors.
- Expanding Green Attack Surface: The rapid deployment of new "green" infrastructures (solar, wind, hydrogen farms) often integrates vulnerable legacy OT, creating new, critical targets for cyber adversaries.
- Holistic Threat Intelligence: Effective defense requires a new approach to Cyber Threat Intelligence (CTI) that integrates geopolitical analysis, climate science, and deep OT security expertise to anticipate and mitigate these converging threats.
About the Speaker(s)
Cybelle Oliveira, known as Lavilla Hacker, is a dedicated CTI researcher from Brazil. She is a co-founder of Lavilla Hacker, an organization specifically focused on empowering cybersecurity professionals from Brazil and Latin America, providing resources and community in Portuguese and Spanish. Oliveira is passionate about the intersection of technology and global challenges, and this talk introduces her ambitious new project: a CTI initiative dedicated to researching the complex interplay between climate change, geopolitics, and nation-state APT attacks. Her work aims to develop a comprehensive framework to understand and address these critical issues, driven by a deep concern for the protection of people and the planet. She also mentions being a cat lover.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Oliveira identifies a genuinely interesting threat framing — APTs timing attacks to weather windows — and grounds it in a real case study (Sandworm/Industroyer2 in Ukraine). The core insight is valid and underexplored at scale, but the talk leans heavily on a CTI narrative layer over technical substance that's mostly already documented, and the statistics get thrown around in ways that invite skepticism.
Heather Calloway (CISO) — SOLID
Oliveira identifies a genuinely important threat convergence — APTs timing OT attacks to weather extremes — and backs it with a credible case study in the Sandworm/Ukraine heating attack. The research framing is interesting, but the talk stops at the warning and never reaches the level of specificity that operators or security leaders need to act.