Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16) — GRU Unit 74455-Linked OT/ICS Attacks on US and Global Critical Infrastructure via VNC Exploitation — Threadlinqs Intelligence
As of 2026-05-30, Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16) — GRU Unit 74455-Linked OT/ICS Attacks on US and Global Critical Infrastructure via VNC Exploitation is a critical-severity ics scada threat attributed to Cyber Army of Russia Reborn (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-0125 · Severity: CRITICAL · Status: ACTIVE · Category: ICS_SCADA
Attribution: Cyber Army of Russia Reborn · Russia · HACKTIVISM
Joint advisory AA25-343A from FBI, CISA, NSA, DOE, EPA, DC3, Europol EC3, and 20+ international partners warns of ongoing pro-Russia hacktivist groups — Cyber Army of Russia Reborn (CARR), Z-Pentest,
On February 20, 2026, the FBI, CISA, NSA, DOE, EPA, DC3, Europol EC3, and over 20 international partner agencies published joint advisory AA25-343A warning of ongoing pro-Russia hacktivist operations targeting critical infrastructure OT/ICS systems globally. This advisory accompanies CISA's May 2025 OT mitigation fact sheet and Europol's Operation Eastwood takedown of NoName057(16) DDoSia infrastructure.
## Threat Actor Groups
### Cyber Army of Russia Reborn (CARR)
CARR — also known as 'The People's Cyber Army of Russia' — was created in late February or early March 2022 with assessed direct support from GRU Unit 74455 (GTsST/Military Unit 74455), tracked by the cybersecurity community as Sandworm/APT44. GRU Unit 74455 likely funded CARR's DDoS tools through at least September 2024. CARR began operations via Telegram channel 'CyberArmyofRussia_Reborn' in April 2022, initially conducting DDoS attacks against US and European targets supporting Ukraine.
In late 2023, CARR expanded to ICS attacks, claiming an intrusion against a European wastewater treatment facility in October 2023. In November 2023, CARR targeted HMI devices at two US dairy farms. By late September 2024, CARR administrators became dissatisfied with GRU support levels, leading to the creation of Z-Pentest.
### Z-Pentest
Established September 2024, Z-Pentest is composed of members from both CARR and NoName057(16). The group specializes in OT intrusion operations targeting globally dispersed critical infrastructure. Unlike other pro-Russia groups, Z-Pentest largely avoids DDoS activities, focusing on OT intrusions to garner media attention. In March 2025, Z-Pentest posted OT device intrusion evidence using NoName057(16) campaign hashtags. In April 2025, Z-Pentest shared video of HMI defacement with CARR and NoName057(16) references.
### NoName057(16)
Created by CISM (Center for the Study and Network Monitoring of the Youth Environment) on behalf of the Kremlin. Senior CISM executives developed the DDoSia tool, paid for infrastructure, administered Telegram channels, and selected DDoS targets. Active since March 2022, NoName057(16) conducts frequent DDoS attacks against NATO member states. In July 2024, the group jointly claimed responsibility with CARR for alleged OT intrusions against US assets. Europol's Operation Eastwood (February 2026) targeted NoName057(16) infrastructure.
### Sector16
Formed January 2025 through collaboration with Z-Pentest. Novice pro-Russia hacktivist group maintaining Telegram presence with claims of compromising US energy infrastructure. Members may have received indirect Russian government support in exchange for specific cyber operations.
## Attack Methodology — VNC Exploitation Chain
The attack methodology is unsophisticated, inexpensive to execute, and easy to replicate:
1. **Reconnaissance**: Scan for internet-facing devices with open VNC ports (default 5900, range 5901-5910) using Nmap, OPENVAS, or similar internet-scraping tools.
2. **Initial Access**: Initiate temporary VPS for password brute-force operations. Use VNC software to access hosts with default, weak, or no passwords.
3. **Confirmation**: Confirm connection to vulnerable HMI device. Log IP address, port, and password.
4. **OT Manipulation**: Using HMI graphical interface, capture screen recordings while performing:
- Modify usernames/passwords (operator lockout)
- Modify operational parameters and setpoints
- Modify device names (defacement)
- Modify instrument settings
- Disable/suppress alarms
- Create loss of view (mandating local manual intervention)
- Device restart or shutdown
5. **Propaganda**: Disconnect VNC, research compromised company, post embellished images/videos to Telegram channels promoting Russian ideology.
6. **Amplification**: Groups cross-post, amplify each other's claims, create additional channels, and share TTPs with new partner groups.
## Simultaneous DDoS + SCADA Pattern
Pro-Russia hacktivist groups have perform
Weaknesses (CWE)
CWE-306, CWE-521, CWE-798, CWE-284, CWE-287, CWE-693
Target sectors: water-wastewater, food-agriculture, energy, critical-infrastructure, government, transportation, manufacturing
Target regions: United States, Europe, NATO Member States, Ukraine, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
ICS_SCADA, CRITICAL, threat intelligence, cybersecurity, T1591, T1595.002, T1583.003, T1110.003, T1021.005, T0883, T0859, T0812, T0886, T0823