News Room
16
Share
mediumCritical Infrastructure

Cybercriminals Target Eastern Europe's Critical Infrastructure Amid Rising Attacks

Cybercriminal groups are increasingly targeting critical infrastructure in Eastern Europe, including power grids, water systems, and healthcare sectors, posing significant risks to national security and public safety.

₿

Encrygma is selling the entire Full Cyber Weapon Research of Cybercriminals Target Eastern Europe's Critical Infrastructure Amid Rising Attacks for ₿ 0.10 BTC. Contact us.

03 March 2026Last updated 03 March 20266 min readRaptor Cyber Intelligence
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Critical Infrastructure
Severity:
Medium
Actor Type:
Cybercriminal
Geography:
Eastern Europe
Confidence:
Confirmed
Source:
Raptor Cyber Intelligence
Read Time:
6 min

Overview

In early 2026, Eastern Europe has witnessed a notable surge in cybercriminal activities targeting critical infrastructure sectors such as power grids, water systems, industrial control systems (ICS), healthcare, and the financial sector. These attacks have raised concerns about the resilience of national infrastructure and the potential for widespread disruptions.

Recent Incidents

  • Poland's Power Grid Attack (December 2025): On December 29, 2025, Poland's power grid experienced a sophisticated cyberattack that targeted both IT and industrial devices, affecting renewable energy plants, a combined heat and power plant, and a manufacturing company. The National Cybersecurity Center (NCBC) attributed the attack to the Russian state-linked group Berserk Bear. (en.wikipedia.org)

  • Hacktivist Group NoName057(16) Takedown (July 2025): In July 2025, a coalition of twelve countries, along with Eurojust and Europol, dismantled the hacktivist group NoName057(16). This group was responsible for multiple distributed denial-of-service (DDoS) attacks targeting critical infrastructure across Europe, including power suppliers and public transport systems. (eurojust.europa.eu)

Emerging Threat Actors

Several cybercriminal groups have been identified as significant threats to Eastern Europe's critical infrastructure:

  • Z-Pentest: A Russia-aligned hacktivist group that has intensified its focus on ICS attacks, particularly targeting energy infrastructure in Germany and France. Z-Pentest has been known to post videos demonstrating tampering with ICS controls, amplifying the psychological impact of their attacks. (northwave-cybersecurity.com)

  • Dark Engine (also known as Infrastructure Destruction Squad): This group has been active across Europe, Asia, and Latin America, targeting sectors such as energy, food and beverages, and manufacturing. Dark Engine's intrusions often involve leaking ICS/HMI control interface screenshots to demonstrate system compromise. (cyberpress.org)

Malware Tools and Techniques

Cybercriminals have developed and deployed sophisticated malware to exploit vulnerabilities in critical infrastructure:

  • Fuxnet: Attributed to the pro-Ukraine hacktivist group BlackJack, Fuxnet targets industrial sensor networks, specifically those used by Moskollektor, a municipal organization in Moscow responsible for gas, water, and sewage networks. The malware disables thousands of sensors and destroys sensor gateway devices, rendering them inoperable. (dragos.com)

  • FrostyGoop: First identified in early 2024, FrostyGoop is designed to manipulate Modbus TCP/502 communications within ICS environments. It can alter or spoof normal industrial process commands, enabling it to evade antivirus software and cause physical damage to infrastructure. Notably, it was used in an attack on the energy supply for district heating systems in Ukraine. (dragos.com)

Impact on Critical Sectors

  • Energy Sector: The attack on Poland's power grid in December 2025 highlights the vulnerability of energy infrastructure to cyber threats. Disruptions in energy supply can have cascading effects on other sectors and pose significant risks to national security.

  • Water Systems: Hacktivist groups have increasingly targeted water utilities, with incidents reported in Spain, Italy, Poland, and France. These attacks suggest systematic probing of critical infrastructure, including the confirmed manipulation of the Norwegian dam by Z-Alliance. (northwave-cybersecurity.com)

  • Healthcare Sector: The healthcare sector has been a significant target for ransomware attacks, with 477 healthcare entities affected over the period covered by a recent report. The disruption of healthcare services can have severe consequences for public health and safety. (infosecurity-magazine.com)

Conclusion

The increasing frequency and sophistication of cybercriminal attacks on critical infrastructure in Eastern Europe underscore the need for enhanced cybersecurity measures. Collaboration among nations, sharing of threat intelligence, and investment in robust defense mechanisms are essential to mitigate these risks and ensure the resilience of critical infrastructure.

Recent Cyberattacks on Eastern Europe's Critical Infrastructure:

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo