Home Cyber Attack U.S. Intelligence Flags Surge in Pro-Russia Hacktivist Attacks on Critical Infrastructure

U.S. Intelligence Flags Surge in Pro-Russia Hacktivist Attacks on Critical Infrastructure

0
Pro-Russia hacktivist attacks

U.S. and allied intelligence agencies have issued a joint cybersecurity advisory warning of a significant uptick in opportunistic attacks by pro-Russia hacktivist groups targeting critical infrastructure sectors across the United States and allied nations.

The alert, released by the FBI, CISA, NSA, the Department of Energy, and multiple global partners, follows ongoing investigations into coordinated attacks that exploit weak internet-facing virtual network computing (VNC) systems in operational technology (OT) environments.

Hacktivist Groups Expanding Operations

The advisory identifies several threat actors, the Cyber Army of Russia Reborn (CARR), NoName057(16), Z-Pentest, and Sector16, as the main groups behind a series of disruptive operations affecting water, food, and energy systems.

While these groups often exaggerate their achievements on social platforms, agencies warned that even their unsophisticated intrusions could cause temporary loss of visibility, shutdowns, or physical damage in industrial control networks.

CARR, assessed to have ties with Russia’s military intelligence unit GRU 74455, initially carried out denial-of-service (DDoS) campaigns but later expanded to direct industrial control system (ICS) intrusions, including wastewater and dairy sector incidents.

Meanwhile, NoName057(16), linked to Kremlin-funded initiatives, leveraged its proprietary DDoS tool DDoSia to attack NATO-affiliated targets.

The emergence of Z-Pentest in late 2024 formed from CARR and NoName057(16) members—marked a tactical shift toward direct OT exploitation.

The newer group Sector16, allied with Z-Pentest, has since claimed to have compromised the energy sector in early 2025.

Technical Exploitation and Defensive Measures

The attacks focus on publicly exposed VNC-connected human-machine interface (HMI) devices commonly used in industrial control environments.

Hacktivists scan the internet for open ports (typically 5900–5910), use brute-force tools to crack default or weak passwords, and then access HMI panels to modify usernames, disable alarms, or alter parameter settings that can disrupt production or force manual operations.

Authorities emphasized that while these attacks lack the sophistication of advanced persistent threats (APTs), their opportunistic and disruptive nature poses growing risks to the resilience of critical infrastructure.

The advisory outlines recommended mitigations, including strict network segmentation, multi-factor authentication, regular firewall configuration audits, and removal of default credentials.

Organizations are urged to reduce OT device exposure to public networks, deploy allowlists, and maintain robust backup and recovery plans.

CISA and partner agencies also encourage OT vendors to adopt “secure by design” principles such as mandatory MFA, logging, and Software Bill of Materials (SBOMs) to help operators defend systems out of the box against remote exploitation attempts.

The joint warning is part of an ongoing global effort to contain pro-Russia hacktivist operations that continue to blur the line between activism and state-aligned cyber aggression.

Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version