logo

Hackers Hijacking VNC Connections to Gain Access to OT Control Devices in Critical Infrastructure

ID: 01c41991-0eb2-55d8-951d-f27e0dba02f5

STIX ID: report--01c41991-0eb2-55d8-951d-f27e0dba02f5

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-12-18

Date Updated: 2026-04-21

Author: Guru Baran

...
...

A joint U.S. and international advisory warns that pro‑Russia hacktivist groups (CARR, NoName057(16), Z‑Pentest, Sector16) are actively exploiting internet‑exposed VNC connections to infiltrate OT HMIs in water, food/agriculture, and energy sectors; attackers use straightforward scanning and brute‑force against port 5900, manipulate GUIs to cause “loss of view,” and post proof for publicity. The advisory documents TTPs and impacts, cites an April 2025 case combining DDoS and SCADA access, and urges immediate mitigations—remove internet‑exposed OT, segment IT/OT, enforce MFA, eliminate default credentials, audit firewalls, enable view‑only modes, and follow incident‑response playbooks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.