News Room
16
Share
criticalCritical Infrastructure

Pro-Russia Hacktivists Intensify Cyber Attacks on North American Critical Infrastructure

Pro-Russia hacktivist groups are increasingly targeting North American critical infrastructure, including power grids, water systems, and healthcare facilities, posing significant threats to national security.

₿

Encrygma is selling the entire Full Cyber Weapon Research of Pro-Russia Hacktivists Intensify Cyber Attacks on North American Critical Infrastructure for ₿ 0.10 BTC. Contact us.

10 March 2026Last updated 10 March 20265 min readRaptor Cyber Intelligence
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Critical Infrastructure
Severity:
Critical
Actor Type:
Hacktivist
Geography:
North America
Confidence:
Confirmed
Source:
Raptor Cyber Intelligence
Read Time:
5 min

Executive Summary

In recent months, pro-Russia hacktivist groups have escalated cyber attacks against critical infrastructure in North America. These operations have targeted sectors such as energy, water, healthcare, and financial services, leveraging both sophisticated and unsophisticated techniques to exploit vulnerabilities in industrial control systems (ICS) and supervisory control and data acquisition (SCADA) systems. The heightened threat level necessitates immediate and comprehensive mitigation strategies to safeguard national security and public safety.

Threat Actor Profile

The primary threat actors identified are pro-Russia hacktivist groups, including the Cyber Army of Russia Reborn (CARR), Z-Pentest, NoName057(16), and Sector16. These groups have been observed conducting opportunistic attacks against U.S. and global critical infrastructure, capitalizing on inadequately secured virtual network computing (VNC) connections to infiltrate OT control devices within critical infrastructure systems. (nsa.gov)

Recent Incidents

  • Water Treatment Facility Attack: In December 2024, the People's Cyber Army, a pro-Russia hacktivist group, targeted a water treatment plant in Stanton, Texas. The attackers manipulated control panels to open valves, releasing untreated water into the system. This incident underscores the potential for cyber attacks to cause environmental hazards and public health risks. (cybernews.com)

  • Energy Sector Breaches: Between November 2023 and April 2024, Iran-affiliated and pro-Russia cyber actors gained access to and, in some cases, manipulated critical U.S. industrial control systems in the food and agriculture, healthcare, and water and wastewater sectors. These attacks highlight a potential public safety threat and an avenue for malicious cyber actors to cause physical damage and deny critical services. (dni.gov)

Technical Analysis

The attackers have employed a range of techniques, from exploiting default passwords and unsecured VNC connections to more sophisticated methods targeting ICS and SCADA systems. The use of VNC software has been particularly prevalent, allowing attackers to remotely access and manipulate control systems. The exploitation of these vulnerabilities is often facilitated by poor cyber hygiene practices within critical infrastructure organizations. (cybersecuritynews.com)

Implications

The increasing frequency and sophistication of cyber attacks on critical infrastructure pose significant risks to national security, public safety, and economic stability. The potential for physical damage, service disruptions, and environmental hazards necessitates a proactive and coordinated response from both public and private sectors.

Recommendations

  1. Enhanced Security Measures: Implement robust cybersecurity protocols, including the use of multi-factor authentication, regular system updates, and comprehensive network monitoring to detect and prevent unauthorized access.

  2. Vulnerability Assessments: Conduct regular security assessments to identify and remediate vulnerabilities within ICS and SCADA systems, particularly those related to remote access tools like VNC.

  3. Information Sharing: Establish and maintain information-sharing agreements between government agencies and critical infrastructure operators to facilitate timely dissemination of threat intelligence and best practices.

  4. Incident Response Planning: Develop and regularly update incident response plans to ensure a swift and coordinated reaction to cyber incidents, minimizing potential damage and recovery time.

Conclusion

The escalation of cyber attacks by pro-Russia hacktivist groups against North American critical infrastructure underscores the urgent need for enhanced cybersecurity measures. By implementing the recommended strategies, stakeholders can bolster the resilience of critical systems and mitigate the risks associated with these evolving cyber threats.

Highlights:

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo