Sunday, April 13, 2025
HomeCVE/vulnerabilityHacktivist Groups Attacking Industrial Control Systems To Disrupt Services

Hacktivist Groups Attacking Industrial Control Systems To Disrupt Services

Published on

SIEM as a Service

Follow Us on Google News

Hacktivist groups are increasingly targeting critical infrastructure’s Operational Technology (OT) systems, motivated by geopolitical issues that, unlike traditional website defacements, can disrupt essential services and endanger public safety.  

The success of high-profile attacks on Industrial control systems (ICS) by groups with minimal technical expertise highlights a worrying evolution in hacktivism, which necessitates reevaluating hacktivist tactics and their growing role in the cyber threat landscape. 

They are increasingly targeting OT systems, critical infrastructure that controls physical processes, and their goal is to disrupt operations and gain media attention for their cause.

- Advertisement - Google News

These groups may be state-backed and can launch denial-of-service attacks or exploit vulnerabilities. 

While some boast more than they achieve, successful OT attacks pose serious threats like water utility disruption, while social media amplifies the impact of these incidents, creating a cycle that encourages further attacks.

With ANYRUN You can Analyze any URL, Files & Email for Malicious Activity : Start your Analysis

CyberAv3ngers, an anti-Israel hacktivist group, targeted industrial control systems manufactured by Unitronics as they compromised programmable logic controllers (PLCs) using brute-force attacks and exploited default credentials, which resulted in manipulation of human-machine interfaces (HMI) in critical infrastructure like water treatment facilities. 

The attacks disrupted operations in multiple locations globally, including the Municipal Water Authority of Aliquippa and the Drum/Binghamstown Water Scheme, highlighting the ability of hacktivists to leverage basic techniques for significant impact and potentially inspiring future large-scale attacks.  

CyberArmyofRussia_Reborn, a pro-Russian hacktivist group likely affiliated with APT28 and Sandworm, has been targeting critical infrastructure since 2023.

In January 2024, they compromised water treatment plants in Texas by exploiting vulnerabilities in VNC technology to manipulate water tank controls. 

Subsequent attacks on US, Polish, and French OT environments suggest broader disruption efforts, as this hacktivist group demonstrates a concerning evolution, employing sophisticated tactics against critical infrastructure for potential political gains. 

Pro-Ukraine hacktivist group Blackjack launched a cyberattack on Moskollektor, a Russian infrastructure management organization. Using custom Fuxnet malware to target Moskollektor’s OT monitoring network, Blackjack potentially countered the ongoing geopolitical conflict.

According to Dragos, Fuxnet specifically exploited vulnerabilities in Moskollektor’s system and likely requires modification for broader attacks. 

Blackjack claimed to have disrupted sensors, infiltrated emergency services, and compromised access credentials, though the extent of the damage is uncertain, which highlights the increasing sophistication of hacktivist operations and the influence of media coverage in amplifying their impact. 

Hacktivist groups are showing increasing sophistication in their attacks on Operational Technology (OT) systems, as early groups like CyberAv3ngers exploited weaknesses in OT systems to cause disruptions, and later groups, possibly inspired by these tactics, used similar methods with more sophistication and potentially state backing to launch broader attacks. 

Now, groups like Blackjack are developing and deploying custom malware, potentially targeting physical systems, which suggests that hacktivists are more capable of causing real-world damage through cyber attacks.

Looking for Full Data Breach Protection? Try Cynet's All-in-One Cybersecurity Platform for MSPs: Try Free Demo 

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

Threat Actors Manipulate Search Results to Lure Users to Malicious Websites

Cybercriminals are increasingly exploiting search engine optimization (SEO) techniques and paid advertisements to manipulate...

Hackers Imitate Google Chrome Install Page on Google Play to Distribute Android Malware

Cybersecurity experts have unearthed an intricate cyber campaign that leverages deceptive websites posing as...

Dangling DNS Attack Allows Hackers to Take Over Organization’s Subdomain

Hackers are exploiting what's known as "Dangling DNS" records to take over corporate subdomains,...

HelloKitty Ransomware Returns, Launching Attacks on Windows, Linux, and ESXi Environments

Security researchers and cybersecurity experts have recently uncovered new variants of the notorious HelloKitty...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Threat Actors Manipulate Search Results to Lure Users to Malicious Websites

Cybercriminals are increasingly exploiting search engine optimization (SEO) techniques and paid advertisements to manipulate...

Hackers Imitate Google Chrome Install Page on Google Play to Distribute Android Malware

Cybersecurity experts have unearthed an intricate cyber campaign that leverages deceptive websites posing as...

Dangling DNS Attack Allows Hackers to Take Over Organization’s Subdomain

Hackers are exploiting what's known as "Dangling DNS" records to take over corporate subdomains,...