logo

Hacktivists target critical infrastructure, hit decoy plant

ID: 4834c2fd-cf3a-54b0-8df5-e73c52770606

STIX ID: report--4834c2fd-cf3a-54b0-8df5-e73c52770606

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-10-09

Date Updated: 2026-07-18

Author: Ionut Ilascu

...
...

A pro‑Russian hacktivist group named TwoNet shifted from DDoS to OT/ICS targeting and compromised a researcher‑deployed decoy water treatment HMI: using default credentials, SQL enumeration and a stored XSS (CVE-2021-26829) they created an account, displayed “Hacked by Barlati,” removed PLCs from data sources and modified PLC setpoints, demonstrating rapid movement to disruptive actions; Forescout recommends strong authentication, network segmentation, IP‑based admin access controls and protocol‑aware detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.