Pro-Russian hacktivist group TwoNet recently targeted what they believed to be a real water treatment facility, which was in fact a sophisticated honeypot set up by cybersecurity researchers at Forescout. The group, previously known for distributed denial-of-service (DDoS) attacks, has shifted its focus to targeting operational technology (OT) in critical infrastructure, marking a significant escalation in their tactics. TwoNet gained initial access to the decoy plant by exploiting default credentials on the human-machine interface (HMI), specifically using 'admin/admin' to log in. Once inside, the attackers attempted to enumerate databases and succeeded after refining their SQL queries, demonstrating a methodical approach to reconnaissance. They created a new user account named 'Barlati' and exploited a known cross-site scripting (XSS) vulnerability, CVE-2021-26829, to display a defacement message on the HMI. Beyond defacement, TwoNet engaged in actions intended to disrupt plant operations, including disabling real-time process updates by removing programmable logic controllers (PLCs) from the data source list and altering PLC setpoints, which could have had dangerous consequences in a real facility. The attackers also attempted to disable logs and alarms, further indicating their intent to cause operational disruption and evade detection. Forescout researchers observed that the attackers did not attempt privilege escalation or exploitation of the underlying host, focusing their efforts on the web application layer. The entire attack sequence, from initial access to disruptive action, unfolded in approximately 26 hours, highlighting the group's efficiency and determination. TwoNet publicly claimed responsibility for the attack on their Telegram channel, falsely asserting it was a successful breach of real critical infrastructure. This incident is notable as it is the first time a hacktivist group has claimed an attack that researchers can confirm occurred on a honeypot. The event underscores the evolution of Russian hacktivism from DDoS attacks to more sophisticated OT intrusions with potential physical-world consequences. Security experts, including those from Deepwatch, have warned that such activities represent a growing asymmetric warfare capability, with hacktivist groups seeking to establish reputations as credible threats to critical infrastructure. The attack also involved attempts to manipulate the Modbus protocol, a common industrial control system protocol, further demonstrating the attackers' technical knowledge. While there is no direct evidence linking TwoNet's actions to Russian state direction, their tactics and public claims serve to amplify their perceived threat. The incident provides valuable insight into the methods and motivations of modern hacktivist groups targeting critical infrastructure. It also highlights the importance of honeypots in understanding adversary behavior and improving defensive measures for real-world OT environments. The rapid progression from access to disruption in this case serves as a warning to operators of critical infrastructure about the need for robust security controls and monitoring.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
On October 9, 2025, Forescout publicly reported that TwoNet had attacked its water-treatment honeypot and highlighted the group's evolution from DDoS activity to attempted OT disruption. The company warned that similar tradecraft against real critical infrastructure could be highly disruptive and recommended stronger authentication, segmentation, restricted exposure, and protocol-aware monitoring.
After compromising the decoy environment, TwoNet publicly portrayed the incident on Telegram as a successful attack on real critical infrastructure. The claim was false because the target was a researcher-operated fake water treatment facility.
Roughly 26 hours after gaining access, the attackers removed PLCs from the HMI data source list, changed PLC setpoints, and attempted to disable logs and alarms. Researchers characterized the sequence as a rapid progression from access to disruptive OT-style actions.
After initial access, TwoNet enumerated databases, created a new user account for persistence, and exploited the old stored XSS vulnerability CVE-2021-26829 to deface the HMI. Forescout assessed the activity remained focused on the HMI web application layer rather than host-level compromise or privilege escalation.
In September 2025, TwoNet accessed what it believed was a water treatment facility by logging into the HMI with default credentials such as admin/admin. The environment was actually a realistic honeypot created by researchers to observe adversary behavior.
Before the honeypot incident, TwoNet's Telegram activity showed interest in targeting HMI/SCADA interfaces in 'enemy countries' and offering cybercrime services, including claimed access to SCADA systems in Poland. Researchers cited this as evidence of the group's shift toward OT-related targeting.
Earlier in 2025, Intel471 assessed the pro-Russian group TwoNet as primarily focused on DDoS activity, including use of MegaMedusa Machine malware. Later reporting said the group began trying to rebrand as a broader cybercrime operation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.