Pro-Russia hacktivist groups have launched a series of opportunistic cyberattacks targeting critical infrastructure entities in the United States and globally. These groups, including Cyber Army of Russia Reborn, Z-Pentest, NoName057(16), and Sector16, exploit minimally secured, internet-facing virtual network computing (VNC) connections to gain access to operational technology (OT) control devices. The attacks are characterized by their relatively low sophistication and impact compared to advanced persistent threat actors, but have resulted in varying degrees of disruption, including physical damage to systems such as water treatment facilities and oil well operations. The hacktivists often seek publicity by exaggerating the effects of their attacks, and their targeting is largely opportunistic, based on the availability of vulnerable systems rather than strategic selection.
Authorities including CISA, the FBI, NSA, Department of Energy, and international partners have issued joint advisories warning OT owners and operators to reduce the exposure of OT assets to the public internet, implement robust authentication, and adopt mature asset management practices. These advisories emphasize the importance of mapping data flows and access points to mitigate the risk of similar attacks. The guidance is part of a broader effort to address the growing threat posed by hacktivist groups leveraging accessible VNC devices to compromise critical infrastructure worldwide.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
The Department of Justice indicted Ukrainian national Victoria Eduardovna Dubranova for supporting the pro-Russia hacktivist groups Cyber Army of Russia Reborn and NoName057(16). The reporting cites the indictment as part of the broader response to these groups' activity.
CISA, FBI, NSA, DOE, EPA, DC3, and international partners issued a joint cybersecurity advisory warning that pro-Russia hacktivists were targeting U.S. and global critical infrastructure through minimally secured internet-facing OT systems. The advisory named key groups, described their tactics and state-linked support, and recommended mitigations such as reducing internet exposure, segmenting IT/OT networks, and enforcing strong authentication.
Pro-Russia groups including CARR, Z-Pentest, NoName057(16), and Sector16 conducted opportunistic attacks by scanning for internet-facing VNC services, brute-forcing weak or default credentials, and accessing HMI devices and in some cases SCADA networks. Affected sectors included water, wastewater, food and agriculture, energy, and oil and gas, with some incidents causing loss of view, operational disruption, and physical damage.
The advisory says pro-Russia hacktivist groups expanded their activity since 2022, increasingly targeting operational technology and industrial control environments tied to critical infrastructure. The groups used opportunistic methods and publicized their actions online to amplify perceived impact.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourcesecurityonline.info
Open sourcehipaajournal.com
Open sourceinfosecurity-magazine.com
Open sourcedarkreading.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.