Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16) — GRU Unit 74455-Linked OT/ICS Attacks on US and Global Critical Infrastructure via VNC Exploitation
Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16) (TL-2026-0125), also tracked as AA25-343A, is a critical-severity ICS/SCADA threat, first published 2026-02-21. It is attributed to Cyber Army of Russia Reborn (Russia) with high confidence, affects Multiple OT Vendors VNC-Connected HMI Devices, maps to 27 MITRE ATT&CK techniques (T0816, T0823, T0828), and is covered by 9 detection rules and 16 indicators of compromise.
Key facts for TL-2026-0125
- Threat ID
- TL-2026-0125
- Also known as
- AA25-343A, Operation Eastwood, Pro-Russia Hacktivist OT Campaign, CARR OT Campaign
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- ICS_SCADA
- First published
- 2026-02-21
- Last reviewed
- 2026-02-21
- Attribution
- Cyber Army of Russia Reborn
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- HACKTIVISM
- Target sectors
- water-wastewater, food-agriculture, energy, critical-infrastructure, government, transportation, manufacturing
- Target regions
- United States, Europe, NATO Member States, Ukraine, Global
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16)
Malware and tooling: CaddyWiper, Industroyer, DDoSia
Joint advisory AA25-343A from FBI, CISA, NSA, DOE, EPA, DC3, Europol EC3, and 20+ international partners warns of ongoing pro-Russia hacktivist groups — Cyber Army of Russia Reborn (CARR), Z-Pentest, NoName057(16), and Sector16 — targeting OT/ICS systems in Water/Wastewater, Food/Agriculture, and Energy sectors. CARR was created and funded by GRU Unit 74455 (Sandworm/APT44). Groups exploit unsecured internet-facing VNC connections to access HMI devices, resulting in physical damage to critical infrastructure including US dairy farms and European wastewater facilities. Europol Operation Eastwood dismantled DDoSia infrastructure in parallel.
How Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16) works
On February 20, 2026, the FBI, CISA, NSA, DOE, EPA, DC3, Europol EC3, and over 20 international partner agencies published joint advisory AA25-343A warning of ongoing pro-Russia hacktivist operations targeting critical infrastructure OT/ICS systems globally. This advisory accompanies CISA's May 2025 OT mitigation fact sheet and Europol's Operation Eastwood takedown of NoName057(16) DDoSia infrastructure.
## Threat Actor Groups
### Cyber Army of Russia Reborn (CARR) CARR — also known as 'The People's Cyber Army of Russia' — was created in late February or early March 2022 with assessed direct support from GRU Unit 74455 (GTsST/Military Unit 74455), tracked by the cybersecurity community as Sandworm/APT44. GRU Unit 74455 likely funded CARR's DDoS tools through at least September 2024. CARR began operations via Telegram channel 'CyberArmyofRussia_Reborn' in April 2022, initially conducting DDoS attacks against US and European targets supporting Ukraine.
In late 2023, CARR expanded to ICS attacks, claiming an intrusion against a European wastewater treatment facility in October 2023. In November 2023, CARR targeted HMI devices at two US dairy farms. By late September 2024, CARR administrators became dissatisfied with GRU support levels, leading to the creation of Z-Pentest.
### Z-Pentest Established September 2024, Z-Pentest is composed of members from both CARR and NoName057(16). The group specializes in OT intrusion operations targeting globally dispersed critical infrastructure. Unlike other pro-Russia groups, Z-Pentest largely avoids DDoS activities, focusing on OT intrusions to garner media attention. In March 2025, Z-Pentest posted OT device intrusion evidence using NoName057(16) campaign hashtags. In April 2025, Z-Pentest shared video of HMI defacement with CARR and NoName057(16) references.
### NoName057(16) Created by CISM (Center for the Study and Network Monitoring of the Youth Environment) on behalf of the Kremlin. Senior CISM executives developed the DDoSia tool, paid for infrastructure, administered Telegram channels, and selected DDoS targets. Active since March 2022, NoName057(16) conducts frequent DDoS attacks against NATO member states. In July 2024, the group jointly claimed responsibility with CARR for alleged OT intrusions against US assets. Europol's Operation Eastwood (February 2026) targeted NoName057(16) infrastructure.
### Sector16 Formed January 2025 through collaboration with Z-Pentest. Novice pro-Russia hacktivist group maintaining Telegram presence with claims of compromising US energy infrastructure. Members may have received indirect Russian government support in exchange for specific cyber operations.
## Attack Methodology — VNC Exploitation Chain
The attack methodology is unsophisticated, inexpensive to execute, and easy to replicate:
1. **Reconnaissance**: Scan for internet-facing devices with open VNC ports (default 5900, range 5901-5910) using Nmap, OPENVAS, or similar internet-scraping tools. 2. **Initial Access**: Initiate temporary VPS for password brute-force operations. Use VNC software to access hosts with default, weak, or no passwords. 3. **Confirmation**: Confirm connection to vulnerable HMI device. Log IP address, port, and password. 4. **OT Manipulation**: Using HMI graphical interface, capture screen recordings while performing: - Modify usernames/passwords (operator lockout) - Modify operational parameters and setpoints - Modify device names (defacement) - Modify instrument settings - Disable/suppress alarms - Create loss of view (mandating local manual intervention) - Device restart or shutdown 5. **Propaganda**: Disconnect VNC, research compromised company, post embellished images/videos to Telegram channels promoting Russian ideology. 6. **Amplification**: Groups cross-post, amplify each other's claims, create additional channels, and share TTPs with new partner groups.
## Simultaneous DDoS + SCADA Pattern
Pro-Russia hacktivist groups have performed simultaneous DDoS attacks against targeted networks to facilitate SCADA intrusions, combining volumetric denial-of-service with direct OT manipulation.
## GRU/Sandworm (APT44) Context
GRU Unit 74455 (Sandworm/APT44) is responsible for some of the most consequential cyber attacks in history: Ukraine power grid disruptions (2015, 2016), NotPetya (2017), Olympic Destroyer (2018 Pyeongchang), and the 2022 Ukraine substation attack using MicroSCADA LotL techniques. Mandiant graduated Sandworm to APT44 in April 2024.
The GRU's disruptive playbook follows five phases: Living on the Edge (edge infrastructure compromise), Living off the Land (native tools), Going for the GPO (Active Directory wiper deployment), Disrupt and Deny (wipers/ransomware), and Telegraphing Success (hacktivist personas on Telegram). CARR and affiliated groups represent the 'Telegraphing Success' layer — GRU-sponsored personas conducting lower-sophistication operations with plausible deniability.
## Impact Assessment
While these groups demonstrate limited technical sophistication, their attacks have caused real physical impact: - Temporary loss of view requiring manual intervention at water treatment and dairy facilities - Unauthorized parameter modifications at energy sector HMI devices - Operational downtime requiring PLC programmer intervention to restore systems - Substantial labor costs for system remediation - Attacks against occupied factories and community facilities demonstrate disregard for human safety
## Europol Operation Eastwood
On February 20, 2026, Europol EC3 announced Operation Eastwood, a global operation targeting NoName057(16) infrastructure. This coordinated takedown involved law enforcement agencies across multiple countries and dismantled DDoSia distribution infrastructure and command nodes.
MITRE ATT&CK techniques used in TL-2026-0125
Inhibit Response Function (ICS)
T0816 Device Restart/Shutdown; T0878 Alarm Suppression; T0892 Change Credential
Execution (ICS)
T0823 Graphical User Interface
Impact (ICS)
T0828 Loss of Productivity and Revenue; T0829 Loss of View; T0831 Manipulation of Control
Impair Process Control (ICS)
T0836 Modify Parameter; T1692.001 Command Message
Persistence (ICS)
Initial Access (ICS)
T0883 Internet Accessible Device
Lateral Movement (ICS)
T0886 Remote Services; T1694.001 Default Credentials
discovery
lateral-movement
defense-evasion
T1036 Masquerading; T1078.001 Default Accounts
execution
T1059 Command and Scripting Interpreter
credential-access
collection
persistence
T1133 External Remote Services
impact
T1489 Service Stop; T1491.002 External Defacement; T1498 Network Denial of Service
resource-development
T1583.003 Virtual Private Server
reconnaissance
T1591 Gather Victim Org Information; T1595.002 Vulnerability Scanning
Affected products and versions in Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16)
- Multiple OT Vendors — VNC-Connected HMI Devices
Vulnerable versions: All internet-facing VNC with default/weak/no authentication - Multiple SCADA Vendors — Supervisory Control and Data Acquisition Systems
Vulnerable versions: Internet-accessible SCADA with VNC remote access - RealVNC / TightVNC / UltraVNC — VNC Server
Vulnerable versions: All versions with default or weak authentication when internet-facing - Multiple — Water/Wastewater Treatment Control Systems
Vulnerable versions: Facilities with internet-exposed HMI/SCADA - Multiple — Energy Sector OT/ICS Systems
Vulnerable versions: Substations, oil/gas systems with internet-exposed HMI - Multiple — Food/Agriculture Processing Control Systems
Vulnerable versions: Dairy farms, food processing with internet-exposed HMI
Remediation for Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16)
Patches
- No CVE patches — attacks exploit misconfigured OT access, not software vulnerabilities
- Update all OT firmware to vendor-supported versions (retire End-of-Life systems)
- Apply vendor hardening guides for SCADA/HMI platforms (Siemens, Schneider, ABB, Rockwell)
Immediate actions
- Remove all OT/ICS devices from direct public internet exposure immediately
- Audit all VNC connections — disable any with default, weak, or no passwords
- Change all default passwords on HMI devices, PLCs, and SCADA systems to unique strong passwords
- Scan for open VNC ports (5900-5910) on all internet-facing IP ranges and close them
- Implement VPN with phishing-resistant MFA for any required remote OT access
- Disable VNC autostart and unnecessary remote access services on OT assets
- Monitor for brute-force attempts against VNC services via IDS/IPS
- Block known DDoSia C2 infrastructure at perimeter firewall
- Review and restrict clipboard/screen recording capabilities on HMI sessions
Workarounds
- If VNC remote access is business-critical, restrict to private IP network connections only
- Implement IP allowlisting for all remote OT access pathways
- Use jump servers/bastion hosts for OT remote access instead of direct VNC
- Enable alarm logging and tamper detection on all HMI devices
- Configure automated alerts for parameter changes, alarm suppressions, and credential modifications on HMI systems
Longer-term hardening
- Segment IT and OT networks with DMZ for control data passing to enterprise systems
- Implement network monitoring at OT/IT boundary for unauthorized VNC connections
- Deploy ICS-specific intrusion detection (Claroty, Dragos, Nozomi) on OT networks
- Maintain and regularly test manual override capabilities for all critical OT processes
- Implement asset management mapping all OT data flows, access points, and internet exposure
- Establish business continuity plans with fail-safe mechanisms, islanding, and software backups
- Configure OT authentication using role-based access control (RBAC) with least privilege
- Disable dormant accounts across all OT and remote access systems
- Conduct regular threat hunting for VNC brute-force and unauthorized OT access patterns
- Coordinate with third-party managed service providers and system integrators on secure OT configurations
Weaknesses (CWE) in Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16)
CWE-306, CWE-521, CWE-798, CWE-284, CWE-287, CWE-693
Timeline of Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16)
- Russia invades Ukraine, triggering surge in pro-Russia hacktivist group creation. CARR created with GRU Unit 74455 support in late February/early March 2022.
- NoName057(16) begins operations, created by CISM on behalf of the Kremlin. Develops DDoSia tool for distributed denial-of-service attacks against NATO member states.
- CARR launches Telegram channel 'CyberArmyofRussia_Reborn' to organize DDoS attacks against US and European targets supporting Ukraine.
- Sandworm (APT44/GRU Unit 74455) conducts cyber-physical attack on Ukrainian power substation using MicroSCADA LotL techniques, coinciding with mass missile strikes. CADDYWIPER deployed in IT environment. Source: https://cloud.google.com/blog/topics/threat-intelligence/sandworm-disrupts-power-ukraine-operational-technology
- CARR expands from DDoS to ICS attacks — claims intrusion against European wastewater treatment facility via VNC exploitation of internet-facing HMI devices.
- CARR targets HMI devices at two US dairy farms, manipulating operational parameters and capturing screen recordings for Telegram propaganda.
- Mandiant graduates Sandworm to APT44, publishing comprehensive report on GRU Unit 74455's full-spectrum cyber sabotage operations. Source: https://cloud.google.com/blog/topics/threat-intelligence/apt44-unearthing-sandworm
- NoName057(16) and CARR jointly claim responsibility for alleged OT intrusions against US critical infrastructure assets, demonstrating operational cooperation.
- Z-Pentest established by dissatisfied CARR administrators and NoName057(16) members. Group specializes in OT intrusion operations separate from GRU direct involvement.
- Sector16 formed through collaboration with Z-Pentest. Novice pro-Russia group claims compromises of US energy infrastructure on Telegram. May receive indirect Russian government support.
- Z-Pentest posts evidence of OT device intrusions using NoName057(16) campaign hashtags. In April 2025, shares video of HMI defacement with CARR and NoName057(16) references.
- CISA publishes joint fact sheet 'Primary Mitigations to Reduce Cyber Threats to Operational Technology' — baseline guidance for removing OT internet exposure, strong passwords, secure remote access, IT/OT segmentation, and manual operations capability. Source: https://www.cisa.gov/resources-tools/resources/primary-mitigations-reduce-cyber-threats-operational-technology
- FBI, CISA, NSA, DOE, EPA, DC3, Europol EC3, and 20+ international partners publish joint advisory AA25-343A warning of ongoing pro-Russia hacktivist OT/ICS attacks. Europol announces Operation Eastwood targeting NoName057(16) DDoSia infrastructure. Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-343a
- Threadlinqs Intelligence publishes TL-2026-0125 with full analysis of pro-Russia hacktivist OT/ICS campaign, dual MITRE Enterprise + ICS framework mapping, and comprehensive detection coverage.
- As of 2026-05-29, the campaign remains active: joint advisory AA25-343A (CISA/FBI/NSA, Dec 2025) warns of ongoing pro-Russia hacktivist VNC-based OT/ICS attacks, and CARR/Z-Pentest/Sector16 keep targeting water, energy and food sectors. Operation Eastwood (Jul 2025) only briefly disrupted NoName057(16) — it resumed in ~5 days, raised attack volume ~80%, and ran a Feb 2026 Winter Olympics campaign; no CVE exists to patch.
Sources cited for Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16)
- CISA/FBI/NSA Joint Advisory AA25-343A: Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure
- CISA: Primary Mitigations to Reduce Cyber Threats to Operational Technology
- Europol Operation Eastwood — Global Operation Targets NoName057(16) Pro-Russian Cybercrime Network
- Mandiant/Google: APT44 (Sandworm) — Unearthing Russia's Notorious Cyber Sabotage Unit
- Mandiant/Google: Sandworm Disrupts Power in Ukraine Using Novel Attack Against Operational Technology
- Mandiant/Google: The GRU's Disruptive Playbook — Five-Phase Operational Concept
- CISA: Russia Threat Overview and Advisories
- MITRE ATT&CK for ICS — Industrial Control Systems Framework
- CISA: Identifying and Mitigating Living Off the Land Techniques
- CISA: Cross-Sector Cybersecurity Performance Goals (CPGs)
- CISA: Stuff Off Search — Reduce Internet Attack Surface for OT
- CISA: Priority Considerations for OT Owners/Operators — Secure by Design Components
More in ics scada
- Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran Intrusion at NCBJ Nuclear Centre, Void Manticore's Handala Persona Wipes 200,000 Stryker Devices, DragonForce Ransomware Disrupts Hazeldenes Poultry
- ORB Networks and Nation-State CNI Targeting: Destructive Wiper Attack on Polish Energy Infrastructure via Exposed FortiGate Devices
- AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructure
- CI Fortify: CISA/ASD/NCSC-UK/CCCS Joint OT Isolation Guidance Exposes Communications-Continuity Gap for Critical Infrastructure Operators
- Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic manipulation bypasses pump safeguards
Detection coverage for TL-2026-0125
As of 2026-02-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0125 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.