Cybercriminals Intensify Attacks on Eastern Europe's Critical Infrastructure
Cybercriminal groups are increasingly targeting Eastern Europe's critical infrastructure, including power grids, water systems, and healthcare sectors, posing significant threats to national security and public safety.
Encrygma is selling the entire Full Cyber Weapon Research of Cybercriminals Intensify Attacks on Eastern Europe's Critical Infrastructure for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Critical Infrastructure
- Severity:
- High
- Actor Type:
- Cybercriminal
- Geography:
- Eastern Europe
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Executive Summary
In early 2026, cybercriminal groups have escalated their attacks on Eastern Europe's critical infrastructure, encompassing power grids, water systems, industrial control systems (ICS), healthcare, and the financial sector. These operations leverage sophisticated malware and exploit vulnerabilities in legacy systems, posing substantial risks to national security and public safety.
Key Threat Actors and Operations
-
Curly COMrades: This emerging cybercriminal group has deployed a custom backdoor malware named MucorAgent, targeting government and judicial organizations in Georgia and energy companies in Moldova. MucorAgent is a .NET-based tool capable of executing AES-encrypted PowerShell scripts and transmitting the output to a command-and-control server using the curl.exe utility. The group's tactics include hijacking Component Object Model (COM) objects and deploying proxy agents like Resocks, though the initial point of entry remains unclear. (techradar.com)
-
Hacktivist Groups: Pro-Russian hacktivist collectives, such as Z-Pentest and NoName057(16), have intensified their campaigns against critical infrastructure in Eastern Europe. These groups have shifted from traditional cyberattacks to more advanced intrusions and data breaches, targeting ICS and operational technology (OT) systems. Their activities have been linked to geopolitical tensions, with evidence suggesting state-backed financing and direction. (scworld.com)
-
Void Rabisu Group: Also known as RomCom, Tropical Scorpius, or Storm-0978, this group conducts both financial cybercrime and intelligence collection via cyberespionage. Their operations have been observed in Eastern Europe, targeting industrial organizations with sophisticated malware and exploiting vulnerabilities in ICS protocols. (ics-cert.kaspersky.com)
Exploited Vulnerabilities and Attack Vectors
Cybercriminals are exploiting several vulnerabilities in critical infrastructure systems:
-
Legacy Systems: Many ICS and SCADA systems in Eastern Europe rely on outdated protocols and software, lacking modern security features. This reliance on legacy systems makes them susceptible to attacks that exploit known weaknesses. (en.wikipedia.org)
-
Default Credentials and Weak Authentication: The use of default passwords and inadequate authentication mechanisms in ICS devices has been a common attack vector. For instance, the Void Rabisu Group has utilized malicious mailings with attachments mimicking legal claims to deliver malware to various sectors, including energy and financial organizations. (ics-cert.kaspersky.com)
-
Insufficient Network Segmentation: Lack of proper network segmentation between IT and OT networks allows attackers to move laterally within organizations, increasing the potential impact of cyberattacks. (itpro.com)
Implications and Recommendations
The escalation of cybercriminal activities targeting critical infrastructure in Eastern Europe underscores the need for enhanced cybersecurity measures. Organizations should prioritize:
-
System Modernization: Upgrading legacy systems to incorporate modern security protocols and practices.
-
Credential Management: Implementing strong, unique passwords and multi-factor authentication across all devices and systems.
-
Network Segmentation: Establishing clear boundaries between IT and OT networks to limit the spread of potential intrusions.
-
Incident Response Planning: Developing and regularly updating incident response plans to ensure swift and effective reactions to cyber incidents.
By addressing these areas, organizations can bolster their defenses against the evolving cybercriminal threat landscape targeting critical infrastructure.
Conclusion
The current cyber threat landscape in Eastern Europe is marked by a significant increase in cybercriminal activities targeting critical infrastructure. The sophistication of these attacks and the exploitation of systemic vulnerabilities highlight the urgent need for comprehensive cybersecurity strategies to safeguard essential services and national security.
Highlights:
- Experts warn criminals are using backdoor malware to target governments, Published on Wednesday, August 13
- CISA shares lessons learned from Polish power grid hack - and how to prevent disaster striking again, Published on Thursday, February 12
- Why cyber attacks on critical national infrastructure are such a huge threat, Published on Wednesday, March 18
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Spanish Rail Infrastructure Breach: Adif Web Systems Exploited to Compromise Renfe Operations

Spanish Rail Operator Renfe Compromised via AI-Assisted Breach of Adif Infrastructure

