TwoNet is a pro-Russian hacktivist group that emerged in January 2025 and has been associated with anti-Ukraine and anti-Western targeting. Reporting links the group to roughly 40 members and to Telegram-based coordination, propaganda, and target promotion. TwoNet initially focused on distributed denial-of-service activity, but later expanded into website defacement, data dumping, doxxing, and attempted operational technology and industrial control system intrusions. The group has promoted attacks against government and infrastructure targets in Ukraine, Spain, and the United Kingdom, and has also been linked to activity against Israeli defense and technology organizations. TwoNet has claimed partnerships or affiliations with other pro-Russian brands, including CyberTroops and OverFlame. TwoNet is notable for a September 2025 intrusion against a decoy ICS/OT environment designed to resemble a water treatment facility. In that incident, the actor obtained access through default credentials on an HMI, performed database reconnaissance, created an additional user for persistence, exploited CVE-2021-26829 in OpenPLC ScadaBR to deface the HMI login page, and attempted disruptive actions including manipulating HMI settings, disabling logs and alarms, removing PLCs from data sources, and changing PLC setpoints. The target was a honeypot rather than a real utility, but the operation demonstrated interest in moving from nuisance activity into disruptive industrial targeting. Broader reporting also associates Russian-aligned groups including TwoNet with exploiting internet-facing VNC connections and HMI devices protected by weak or default credentials. The group has been described as short-lived and opportunistic, with exaggerated or fabricated public claims used to boost reputation. Its Telegram activity reportedly evolved from DDoS promotion into broader cybercrime-style offerings, including hack-for-hire services, initial access brokerage, and purported ransomware affiliate opportunities. Some of these offerings have been assessed as potentially fraudulent or reputation-building rather than evidence of mature criminal capability. Even so, TwoNet reflects a wider trend in Russian-aligned hacktivism toward blending influence operations, disruptive cyber activity, and exploratory OT intrusion attempts against critical infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russia-aligned hacktivist group focused on OT/ICS environments, especially water-sector targets, with attempts to access and disrupt water treatment operations and broader industrial environments.
Pro-Russian hacktivist activity that evolved from DDoS into ICS/OT targeting and disruption/defacement. In the cited incident, they accessed an OpenPLC ScadaBR environment using default credentials, created a new user (“BARLATI”), exploited CVE-2021-26829 (XSS) to deface the HMI login page, and attempted to reduce visibility by disabling logs and alarms. The group is also described as offering RaaS, hack-for-hire, and initial access services, and claiming ties to other pro-Russian collectives.
Pro-Russian hacktivist group observed targeting industrial control/HMI systems (OpenPLC ScadaBR) using default credentials for initial access, then web-layer exploitation (CVE-2021-26829 XSS) to deface HMI pages and change settings (e.g., disable logs/alarms). The group reportedly started with Telegram-coordinated DDoS and expanded into industrial targeting, doxxing, and commercialized offerings (RaaS, hack-for-hire, initial access brokerage).
Described as a Russian hacktivist group observed attempting to manipulate industrial control system (ICS) settings; caught targeting a decoy industrial plant.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.