Pro-Russian Hacktivists Intensify Attacks on North American Critical Infrastructure
Pro-Russian hacktivist groups have escalated cyberattacks targeting critical infrastructure in North America, exploiting vulnerabilities in operational technology systems.
Encrygma is selling the entire Full Cyber Weapon Research of Pro-Russian Hacktivists Intensify Attacks on North American Critical Infrastructure for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Critical Infrastructure
- Severity:
- Critical
- Actor Type:
- Hacktivist
- Geography:
- North America
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Executive Summary
In recent months, pro-Russian hacktivist groups have significantly intensified cyberattacks against critical infrastructure in North America. These groups, including Cyber Army of Russia Reborn (CARR), Z-Pentest, NoName057(16), and Sector16, have exploited vulnerabilities in operational technology (OT) systems, particularly targeting industrial control systems (ICS) and supervisory control and data acquisition (SCADA) networks. (nsa.gov)
Attack Vectors and Techniques
The primary attack vector involves exploiting inadequately secured, internet-facing virtual network computing (VNC) connections to infiltrate OT control devices within critical infrastructure systems. Once access is gained, these actors manipulate human-machine interfaces (HMIs) to alter settings, disable alarms, and change administrative passwords, leading to operational disruptions. For instance, in April 2024, a pro-Russian hacktivist group remotely manipulated control systems within five water and wastewater systems and two dairies in the United States, causing water to overflow and storage tanks to overfill. (dni.gov)
Targeted Sectors
The sectors most affected by these attacks include:
-
Water and Wastewater Systems: Compromises have led to overflows and potential contamination risks.
-
Energy: Manipulation of control systems has resulted in operational disruptions and potential safety hazards.
-
Food and Agriculture: Attacks have targeted dairy facilities, leading to operational disruptions. (dni.gov)
Mitigation Recommendations
To mitigate the risks associated with these attacks, organizations are advised to implement the following measures:
-
Reduce Exposure: Limit the exposure of OT assets to the public-facing internet.
-
Network Segmentation: Implement network segmentation between IT and OT networks to contain potential breaches.
-
Asset Management: Adopt mature asset management processes, including mapping data flows and access points.
-
Authentication Procedures: Ensure that OT assets use robust authentication procedures.
-
Control System Security: Enable control system security features that can separate and audit view and control functions.
-
Monitoring and Alerts: Collect and monitor OT asset and networking device traffic, and set up alerts for deviations.
-
Recovery Plans: Implement and practice business recovery and disaster recovery plans. (cyber.gc.ca)
Conclusion
The escalation of cyberattacks by pro-Russian hacktivist groups against critical infrastructure in North America underscores the urgent need for enhanced cybersecurity measures. By proactively addressing vulnerabilities and implementing recommended mitigations, organizations can better safeguard their systems against these evolving threats.
Highlights:
- NSA, FBI, and Others Call Out Pro-Russia Hacktivist Groups Targeting Critical Infrastructure > National Security Agency/Central Security Service > Press Release View, Published on Monday, December 08
- U.S. warns of pro-Russian hacktivist attacks against OT systems | TechTarget, Published on Tuesday, April 30
- Joint cyber security advisory on pro-Russia hacktivists conducting opportunistic attacks on global critical infrastructure - Canadian Centre for Cyber Security, Published on Monday, December 08
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

CISA Launches 'Securing the Next 250' Initiative Amidst Escalating Threats to Critical Infrastructure

Qilin Ransomware Surge Targets Industrial Sector as Global Critical Infrastructure Threats Escalate

