News Room
16
Share
highCritical Infrastructure

Cybercriminals Intensify Attacks on Eastern Europe's Critical Infrastructure

Cybercriminal groups are increasingly targeting Eastern Europe's critical infrastructure, including power grids, water systems, and healthcare sectors, posing significant threats to national security and public safety.

₿

Encrygma is selling the entire Full Cyber Weapon Research of Cybercriminals Intensify Attacks on Eastern Europe's Critical Infrastructure for ₿ 0.10 BTC. Contact us.

30 March 2026Last updated 30 March 20265 min readRaptor Cyber Intelligence
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Critical Infrastructure
Severity:
High
Actor Type:
Cybercriminal
Geography:
Eastern Europe
Confidence:
Confirmed
Source:
Raptor Cyber Intelligence
Read Time:
5 min

Executive Summary

In early 2026, cybercriminal groups have escalated their attacks on Eastern Europe's critical infrastructure, encompassing power grids, water systems, industrial control systems (ICS), healthcare, and the financial sector. These operations leverage sophisticated malware and exploit vulnerabilities in legacy systems, posing substantial risks to national security and public safety.

Key Threat Actors and Operations

  • Curly COMrades: This emerging cybercriminal group has deployed a custom backdoor malware named MucorAgent, targeting government and judicial organizations in Georgia and energy companies in Moldova. MucorAgent is a .NET-based tool capable of executing AES-encrypted PowerShell scripts and transmitting the output to a command-and-control server using the curl.exe utility. The group's tactics include hijacking Component Object Model (COM) objects and deploying proxy agents like Resocks, though the initial point of entry remains unclear. (techradar.com)

  • Hacktivist Groups: Pro-Russian hacktivist collectives, such as Z-Pentest and NoName057(16), have intensified their campaigns against critical infrastructure in Eastern Europe. These groups have shifted from traditional cyberattacks to more advanced intrusions and data breaches, targeting ICS and operational technology (OT) systems. Their activities have been linked to geopolitical tensions, with evidence suggesting state-backed financing and direction. (scworld.com)

  • Void Rabisu Group: Also known as RomCom, Tropical Scorpius, or Storm-0978, this group conducts both financial cybercrime and intelligence collection via cyberespionage. Their operations have been observed in Eastern Europe, targeting industrial organizations with sophisticated malware and exploiting vulnerabilities in ICS protocols. (ics-cert.kaspersky.com)

Exploited Vulnerabilities and Attack Vectors

Cybercriminals are exploiting several vulnerabilities in critical infrastructure systems:

  • Legacy Systems: Many ICS and SCADA systems in Eastern Europe rely on outdated protocols and software, lacking modern security features. This reliance on legacy systems makes them susceptible to attacks that exploit known weaknesses. (en.wikipedia.org)

  • Default Credentials and Weak Authentication: The use of default passwords and inadequate authentication mechanisms in ICS devices has been a common attack vector. For instance, the Void Rabisu Group has utilized malicious mailings with attachments mimicking legal claims to deliver malware to various sectors, including energy and financial organizations. (ics-cert.kaspersky.com)

  • Insufficient Network Segmentation: Lack of proper network segmentation between IT and OT networks allows attackers to move laterally within organizations, increasing the potential impact of cyberattacks. (itpro.com)

Implications and Recommendations

The escalation of cybercriminal activities targeting critical infrastructure in Eastern Europe underscores the need for enhanced cybersecurity measures. Organizations should prioritize:

  • System Modernization: Upgrading legacy systems to incorporate modern security protocols and practices.

  • Credential Management: Implementing strong, unique passwords and multi-factor authentication across all devices and systems.

  • Network Segmentation: Establishing clear boundaries between IT and OT networks to limit the spread of potential intrusions.

  • Incident Response Planning: Developing and regularly updating incident response plans to ensure swift and effective reactions to cyber incidents.

By addressing these areas, organizations can bolster their defenses against the evolving cybercriminal threat landscape targeting critical infrastructure.

Conclusion

The current cyber threat landscape in Eastern Europe is marked by a significant increase in cybercriminal activities targeting critical infrastructure. The sophistication of these attacks and the exploitation of systemic vulnerabilities highlight the urgent need for comprehensive cybersecurity strategies to safeguard essential services and national security.

Highlights:

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo