Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16) — GRU Unit 74455-Linked OT/ICS Attacks on US and Global Critical Infrastructure via VNC Exploitation

Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16) (TL-2026-0125), also tracked as AA25-343A, is a critical-severity ICS/SCADA threat, first published 2026-02-21. It is attributed to Cyber Army of Russia Reborn (Russia) with high confidence, affects Multiple OT Vendors VNC-Connected HMI Devices, maps to 27 MITRE ATT&CK techniques (T0816, T0823, T0828), and is covered by 9 detection rules and 16 indicators of compromise.

Key facts for TL-2026-0125

Threat ID
TL-2026-0125
Also known as
AA25-343A, Operation Eastwood, Pro-Russia Hacktivist OT Campaign, CARR OT Campaign
Severity
CRITICAL
Status
ACTIVE
Category
ICS_SCADA
First published
2026-02-21
Last reviewed
2026-02-21
Attribution
Cyber Army of Russia Reborn
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
HACKTIVISM
Target sectors
water-wastewater, food-agriculture, energy, critical-infrastructure, government, transportation, manufacturing
Target regions
United States, Europe, NATO Member States, Ukraine, Global
Detection rules
9
Indicators of compromise
16

Malware and tooling in Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16)

Malware and tooling: CaddyWiper, Industroyer, DDoSia

Joint advisory AA25-343A from FBI, CISA, NSA, DOE, EPA, DC3, Europol EC3, and 20+ international partners warns of ongoing pro-Russia hacktivist groups — Cyber Army of Russia Reborn (CARR), Z-Pentest, NoName057(16), and Sector16 — targeting OT/ICS systems in Water/Wastewater, Food/Agriculture, and Energy sectors. CARR was created and funded by GRU Unit 74455 (Sandworm/APT44). Groups exploit unsecured internet-facing VNC connections to access HMI devices, resulting in physical damage to critical infrastructure including US dairy farms and European wastewater facilities. Europol Operation Eastwood dismantled DDoSia infrastructure in parallel.

How Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16) works

On February 20, 2026, the FBI, CISA, NSA, DOE, EPA, DC3, Europol EC3, and over 20 international partner agencies published joint advisory AA25-343A warning of ongoing pro-Russia hacktivist operations targeting critical infrastructure OT/ICS systems globally. This advisory accompanies CISA's May 2025 OT mitigation fact sheet and Europol's Operation Eastwood takedown of NoName057(16) DDoSia infrastructure.

## Threat Actor Groups

### Cyber Army of Russia Reborn (CARR) CARR — also known as 'The People's Cyber Army of Russia' — was created in late February or early March 2022 with assessed direct support from GRU Unit 74455 (GTsST/Military Unit 74455), tracked by the cybersecurity community as Sandworm/APT44. GRU Unit 74455 likely funded CARR's DDoS tools through at least September 2024. CARR began operations via Telegram channel 'CyberArmyofRussia_Reborn' in April 2022, initially conducting DDoS attacks against US and European targets supporting Ukraine.

In late 2023, CARR expanded to ICS attacks, claiming an intrusion against a European wastewater treatment facility in October 2023. In November 2023, CARR targeted HMI devices at two US dairy farms. By late September 2024, CARR administrators became dissatisfied with GRU support levels, leading to the creation of Z-Pentest.

### Z-Pentest Established September 2024, Z-Pentest is composed of members from both CARR and NoName057(16). The group specializes in OT intrusion operations targeting globally dispersed critical infrastructure. Unlike other pro-Russia groups, Z-Pentest largely avoids DDoS activities, focusing on OT intrusions to garner media attention. In March 2025, Z-Pentest posted OT device intrusion evidence using NoName057(16) campaign hashtags. In April 2025, Z-Pentest shared video of HMI defacement with CARR and NoName057(16) references.

### NoName057(16) Created by CISM (Center for the Study and Network Monitoring of the Youth Environment) on behalf of the Kremlin. Senior CISM executives developed the DDoSia tool, paid for infrastructure, administered Telegram channels, and selected DDoS targets. Active since March 2022, NoName057(16) conducts frequent DDoS attacks against NATO member states. In July 2024, the group jointly claimed responsibility with CARR for alleged OT intrusions against US assets. Europol's Operation Eastwood (February 2026) targeted NoName057(16) infrastructure.

### Sector16 Formed January 2025 through collaboration with Z-Pentest. Novice pro-Russia hacktivist group maintaining Telegram presence with claims of compromising US energy infrastructure. Members may have received indirect Russian government support in exchange for specific cyber operations.

## Attack Methodology — VNC Exploitation Chain

The attack methodology is unsophisticated, inexpensive to execute, and easy to replicate:

1. **Reconnaissance**: Scan for internet-facing devices with open VNC ports (default 5900, range 5901-5910) using Nmap, OPENVAS, or similar internet-scraping tools. 2. **Initial Access**: Initiate temporary VPS for password brute-force operations. Use VNC software to access hosts with default, weak, or no passwords. 3. **Confirmation**: Confirm connection to vulnerable HMI device. Log IP address, port, and password. 4. **OT Manipulation**: Using HMI graphical interface, capture screen recordings while performing: - Modify usernames/passwords (operator lockout) - Modify operational parameters and setpoints - Modify device names (defacement) - Modify instrument settings - Disable/suppress alarms - Create loss of view (mandating local manual intervention) - Device restart or shutdown 5. **Propaganda**: Disconnect VNC, research compromised company, post embellished images/videos to Telegram channels promoting Russian ideology. 6. **Amplification**: Groups cross-post, amplify each other's claims, create additional channels, and share TTPs with new partner groups.

## Simultaneous DDoS + SCADA Pattern

Pro-Russia hacktivist groups have performed simultaneous DDoS attacks against targeted networks to facilitate SCADA intrusions, combining volumetric denial-of-service with direct OT manipulation.

## GRU/Sandworm (APT44) Context

GRU Unit 74455 (Sandworm/APT44) is responsible for some of the most consequential cyber attacks in history: Ukraine power grid disruptions (2015, 2016), NotPetya (2017), Olympic Destroyer (2018 Pyeongchang), and the 2022 Ukraine substation attack using MicroSCADA LotL techniques. Mandiant graduated Sandworm to APT44 in April 2024.

The GRU's disruptive playbook follows five phases: Living on the Edge (edge infrastructure compromise), Living off the Land (native tools), Going for the GPO (Active Directory wiper deployment), Disrupt and Deny (wipers/ransomware), and Telegraphing Success (hacktivist personas on Telegram). CARR and affiliated groups represent the 'Telegraphing Success' layer — GRU-sponsored personas conducting lower-sophistication operations with plausible deniability.

## Impact Assessment

While these groups demonstrate limited technical sophistication, their attacks have caused real physical impact: - Temporary loss of view requiring manual intervention at water treatment and dairy facilities - Unauthorized parameter modifications at energy sector HMI devices - Operational downtime requiring PLC programmer intervention to restore systems - Substantial labor costs for system remediation - Attacks against occupied factories and community facilities demonstrate disregard for human safety

## Europol Operation Eastwood

On February 20, 2026, Europol EC3 announced Operation Eastwood, a global operation targeting NoName057(16) infrastructure. This coordinated takedown involved law enforcement agencies across multiple countries and dismantled DDoSia distribution infrastructure and command nodes.

MITRE ATT&CK techniques used in TL-2026-0125

Inhibit Response Function (ICS)

T0816 Device Restart/Shutdown; T0878 Alarm Suppression; T0892 Change Credential

Execution (ICS)

T0823 Graphical User Interface

Impact (ICS)

T0828 Loss of Productivity and Revenue; T0829 Loss of View; T0831 Manipulation of Control

Impair Process Control (ICS)

T0836 Modify Parameter; T1692.001 Command Message

Persistence (ICS)

T0859 Valid Accounts

Initial Access (ICS)

T0883 Internet Accessible Device

Lateral Movement (ICS)

T0886 Remote Services; T1694.001 Default Credentials

discovery

T1018 Remote System Discovery

lateral-movement

T1021.005 VNC

defense-evasion

T1036 Masquerading; T1078.001 Default Accounts

execution

T1059 Command and Scripting Interpreter

credential-access

T1110.003 Password Spraying

collection

T1113 Screen Capture

persistence

T1133 External Remote Services

impact

T1489 Service Stop; T1491.002 External Defacement; T1498 Network Denial of Service

resource-development

T1583.003 Virtual Private Server

reconnaissance

T1591 Gather Victim Org Information; T1595.002 Vulnerability Scanning

Affected products and versions in Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16)

  • Multiple OT Vendors — VNC-Connected HMI Devices
    Vulnerable versions: All internet-facing VNC with default/weak/no authentication
  • Multiple SCADA Vendors — Supervisory Control and Data Acquisition Systems
    Vulnerable versions: Internet-accessible SCADA with VNC remote access
  • RealVNC / TightVNC / UltraVNC — VNC Server
    Vulnerable versions: All versions with default or weak authentication when internet-facing
  • Multiple — Water/Wastewater Treatment Control Systems
    Vulnerable versions: Facilities with internet-exposed HMI/SCADA
  • Multiple — Energy Sector OT/ICS Systems
    Vulnerable versions: Substations, oil/gas systems with internet-exposed HMI
  • Multiple — Food/Agriculture Processing Control Systems
    Vulnerable versions: Dairy farms, food processing with internet-exposed HMI

Remediation for Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16)

Patches

  • No CVE patches — attacks exploit misconfigured OT access, not software vulnerabilities
  • Update all OT firmware to vendor-supported versions (retire End-of-Life systems)
  • Apply vendor hardening guides for SCADA/HMI platforms (Siemens, Schneider, ABB, Rockwell)

Immediate actions

  • Remove all OT/ICS devices from direct public internet exposure immediately
  • Audit all VNC connections — disable any with default, weak, or no passwords
  • Change all default passwords on HMI devices, PLCs, and SCADA systems to unique strong passwords
  • Scan for open VNC ports (5900-5910) on all internet-facing IP ranges and close them
  • Implement VPN with phishing-resistant MFA for any required remote OT access
  • Disable VNC autostart and unnecessary remote access services on OT assets
  • Monitor for brute-force attempts against VNC services via IDS/IPS
  • Block known DDoSia C2 infrastructure at perimeter firewall
  • Review and restrict clipboard/screen recording capabilities on HMI sessions

Workarounds

  • If VNC remote access is business-critical, restrict to private IP network connections only
  • Implement IP allowlisting for all remote OT access pathways
  • Use jump servers/bastion hosts for OT remote access instead of direct VNC
  • Enable alarm logging and tamper detection on all HMI devices
  • Configure automated alerts for parameter changes, alarm suppressions, and credential modifications on HMI systems

Longer-term hardening

  • Segment IT and OT networks with DMZ for control data passing to enterprise systems
  • Implement network monitoring at OT/IT boundary for unauthorized VNC connections
  • Deploy ICS-specific intrusion detection (Claroty, Dragos, Nozomi) on OT networks
  • Maintain and regularly test manual override capabilities for all critical OT processes
  • Implement asset management mapping all OT data flows, access points, and internet exposure
  • Establish business continuity plans with fail-safe mechanisms, islanding, and software backups
  • Configure OT authentication using role-based access control (RBAC) with least privilege
  • Disable dormant accounts across all OT and remote access systems
  • Conduct regular threat hunting for VNC brute-force and unauthorized OT access patterns
  • Coordinate with third-party managed service providers and system integrators on secure OT configurations

Weaknesses (CWE) in Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16)

CWE-306, CWE-521, CWE-798, CWE-284, CWE-287, CWE-693

Timeline of Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16)

  • Russia invades Ukraine, triggering surge in pro-Russia hacktivist group creation. CARR created with GRU Unit 74455 support in late February/early March 2022.
  • NoName057(16) begins operations, created by CISM on behalf of the Kremlin. Develops DDoSia tool for distributed denial-of-service attacks against NATO member states.
  • CARR launches Telegram channel 'CyberArmyofRussia_Reborn' to organize DDoS attacks against US and European targets supporting Ukraine.
  • Sandworm (APT44/GRU Unit 74455) conducts cyber-physical attack on Ukrainian power substation using MicroSCADA LotL techniques, coinciding with mass missile strikes. CADDYWIPER deployed in IT environment. Source: https://cloud.google.com/blog/topics/threat-intelligence/sandworm-disrupts-power-ukraine-operational-technology
  • CARR expands from DDoS to ICS attacks — claims intrusion against European wastewater treatment facility via VNC exploitation of internet-facing HMI devices.
  • CARR targets HMI devices at two US dairy farms, manipulating operational parameters and capturing screen recordings for Telegram propaganda.
  • Mandiant graduates Sandworm to APT44, publishing comprehensive report on GRU Unit 74455's full-spectrum cyber sabotage operations. Source: https://cloud.google.com/blog/topics/threat-intelligence/apt44-unearthing-sandworm
  • NoName057(16) and CARR jointly claim responsibility for alleged OT intrusions against US critical infrastructure assets, demonstrating operational cooperation.
  • Z-Pentest established by dissatisfied CARR administrators and NoName057(16) members. Group specializes in OT intrusion operations separate from GRU direct involvement.
  • Sector16 formed through collaboration with Z-Pentest. Novice pro-Russia group claims compromises of US energy infrastructure on Telegram. May receive indirect Russian government support.
  • Z-Pentest posts evidence of OT device intrusions using NoName057(16) campaign hashtags. In April 2025, shares video of HMI defacement with CARR and NoName057(16) references.
  • CISA publishes joint fact sheet 'Primary Mitigations to Reduce Cyber Threats to Operational Technology' — baseline guidance for removing OT internet exposure, strong passwords, secure remote access, IT/OT segmentation, and manual operations capability. Source: https://www.cisa.gov/resources-tools/resources/primary-mitigations-reduce-cyber-threats-operational-technology
  • FBI, CISA, NSA, DOE, EPA, DC3, Europol EC3, and 20+ international partners publish joint advisory AA25-343A warning of ongoing pro-Russia hacktivist OT/ICS attacks. Europol announces Operation Eastwood targeting NoName057(16) DDoSia infrastructure. Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-343a
  • Threadlinqs Intelligence publishes TL-2026-0125 with full analysis of pro-Russia hacktivist OT/ICS campaign, dual MITRE Enterprise + ICS framework mapping, and comprehensive detection coverage.
  • As of 2026-05-29, the campaign remains active: joint advisory AA25-343A (CISA/FBI/NSA, Dec 2025) warns of ongoing pro-Russia hacktivist VNC-based OT/ICS attacks, and CARR/Z-Pentest/Sector16 keep targeting water, energy and food sectors. Operation Eastwood (Jul 2025) only briefly disrupted NoName057(16) — it resumed in ~5 days, raised attack volume ~80%, and ran a Feb 2026 Winter Olympics campaign; no CVE exists to patch.

Sources cited for Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16)

More in ics scada

Detection coverage for TL-2026-0125

As of 2026-02-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0125 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats