Pro-Russia hacktivist groups, including Cyber Army of Russia Reborn (CARR), NoName057(16), Z-Pentest, and Sector16, have escalated their operations from DDoS attacks to targeting operational technology (OT) systems in critical infrastructure sectors such as water, food, agriculture, and energy. These groups exploit exposed Virtual Network Computing (VNC) connections with weak security, using tools like Nmap and brute-force attacks to gain access to human-machine interfaces (HMIs). Once inside, they manipulate system parameters, disable alarms, and cause operational disruptions, often publicizing their actions for propaganda purposes. The U.S. and international cybersecurity agencies have issued joint advisories detailing these tactics, highlighting the opportunistic nature of these attacks and the use of MITRE ATT&CK techniques ranging from reconnaissance to impact, including "loss of view" scenarios that force manual intervention.
Recent U.S. government indictments and sanctions confirm that CARR was founded and directed by Russian military intelligence (GRU) as a means to conduct unattributable disruptive operations. Notable incidents attributed to these groups include attacks on public drinking water systems, resulting in water spills, and a Los Angeles meat processing facility, which suffered spoiled products and an ammonia leak. While the technical sophistication of these actors is limited, their ability to cause downtime, remediation costs, and occasional physical damage underscores the persistent risk posed by exposed OT systems and weak remote access protections in critical infrastructure environments.

See the actors and campaigns active against you right now.
5 events from the most recent confirmed update back to the earliest known activity.
The joint advisory urged critical infrastructure operators to remove internet-exposed OT assets, segment networks, enforce MFA, and eliminate default or weak credentials. It also called on manufacturers to adopt secure-by-design practices to reduce the impact of these intrusions.
U.S. and international cybersecurity agencies issued a joint advisory warning that groups including CARR, Z-Pentest, NoName057(16), and Sector16 were exploiting internet-exposed VNC connections to access OT devices in water, food, agriculture, and energy sectors. The advisory said the attacks caused downtime, remediation costs, and in rare cases physical damage, though no injuries were reported.
After CARR was viewed by its handlers as ineffective, a splinter group called Z-Pentest was formed with a stronger focus on operational technology disruption. U.S. and partner agencies later identified it alongside other pro-Russia groups targeting critical infrastructure.
CARR evolved from conducting distributed denial-of-service attacks to targeting operational technology environments. Its operators used exposed remote access services and weak credentials to access OT systems and manipulate human-machine interfaces.
The U.S. government revealed that Russia's GRU funded and directed CyberArmyofRussia_Reborn (CARR) to carry out disruptive attacks against critical infrastructure, including U.S. water systems, meat processing facilities, and election infrastructure. The activity marked the use of nominally hacktivist fronts for state-backed operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.