Hacktivist Groups Attacking Industrial Control Systems To Disrupt Services

Hacktivist groups are increasingly targeting critical infrastructure’s Operational Technology (OT) systems, motivated by geopolitical issues that, unlike traditional website defacements, can disrupt essential services and endanger public safety.  

The success of high-profile attacks on Industrial control systems (ICS) by groups with minimal technical expertise highlights a worrying evolution in hacktivism, which necessitates reevaluating hacktivist tactics and their growing role in the cyber threat landscape. 

They are increasingly targeting OT systems, critical infrastructure that controls physical processes, and their goal is to disrupt operations and gain media attention for their cause.

These groups may be state-backed and can launch denial-of-service attacks or exploit vulnerabilities. 

While some boast more than they achieve, successful OT attacks pose serious threats like water utility disruption, while social media amplifies the impact of these incidents, creating a cycle that encourages further attacks.

With ANYRUN You can Analyze any URL, Files & Email for Malicious Activity : Start your Analysis

CyberAv3ngers, an anti-Israel hacktivist group, targeted industrial control systems manufactured by Unitronics as they compromised programmable logic controllers (PLCs) using brute-force attacks and exploited default credentials, which resulted in manipulation of human-machine interfaces (HMI) in critical infrastructure like water treatment facilities. 

The attacks disrupted operations in multiple locations globally, including the Municipal Water Authority of Aliquippa and the Drum/Binghamstown Water Scheme, highlighting the ability of hacktivists to leverage basic techniques for significant impact and potentially inspiring future large-scale attacks.  

CyberArmyofRussia_Reborn, a pro-Russian hacktivist group likely affiliated with APT28 and Sandworm, has been targeting critical infrastructure since 2023.

In January 2024, they compromised water treatment plants in Texas by exploiting vulnerabilities in VNC technology to manipulate water tank controls. 

Subsequent attacks on US, Polish, and French OT environments suggest broader disruption efforts, as this hacktivist group demonstrates a concerning evolution, employing sophisticated tactics against critical infrastructure for potential political gains. 

Pro-Ukraine hacktivist group Blackjack launched a cyberattack on Moskollektor, a Russian infrastructure management organization. Using custom Fuxnet malware to target Moskollektor’s OT monitoring network, Blackjack potentially countered the ongoing geopolitical conflict.

According to Dragos, Fuxnet specifically exploited vulnerabilities in Moskollektor’s system and likely requires modification for broader attacks. 

Blackjack claimed to have disrupted sensors, infiltrated emergency services, and compromised access credentials, though the extent of the damage is uncertain, which highlights the increasing sophistication of hacktivist operations and the influence of media coverage in amplifying their impact. 

Hacktivist groups are showing increasing sophistication in their attacks on Operational Technology (OT) systems, as early groups like CyberAv3ngers exploited weaknesses in OT systems to cause disruptions, and later groups, possibly inspired by these tactics, used similar methods with more sophistication and potentially state backing to launch broader attacks. 

Now, groups like Blackjack are developing and deploying custom malware, potentially targeting physical systems, which suggests that hacktivists are more capable of causing real-world damage through cyber attacks.

Looking for Full Data Breach Protection? Try Cynet's All-in-One Cybersecurity Platform for MSPs: Try Free Demo 

Aman Mishra

Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Recent Posts

Landmark Admin Suffers Major Breach, Exposing Data of 1.6M+ Users

Landmark Admin, LLC (“Landmark”), a Texas-based third-party administrator for life insurance carriers, has confirmed that…

2 hours ago

SquareX to Reveal Critical Data Splicing Attack at BSides SF, Exposing Major DLP Vulnerability

SquareX researchers Jeswin Mathai and Audrey Adeline will be disclosing a new class of data exfiltration techniques at BSides San…

2 hours ago

Firefox Fixes High-Severity Vulnerability Causing Memory Corruption via Race Condition

Mozilla has released Firefox 137.0.2, addressing a high-severity security flaw that could potentially allow attackers…

3 hours ago

Tails 6.14.2 Released with Critical Fixes for Linux Kernel Vulnerabilities

The Tails Project has urgently released Tails 6.14.2, addressing critical security vulnerabilities in the Linux kernel…

4 hours ago

APT29 Hackers Use GRAPELOADER in New Attack Against European Diplomats

Check Point Research (CPR) has uncovered a new targeted phishing campaign employing GRAPELOADER, a sophisticated…

5 hours ago

Chinese Hackers Unleash New BRICKSTORM Malware to Target Windows and Linux Systems

A sophisticated cyber espionage campaign leveraging the newly identified BRICKSTORM malware variants has targeted European…

5 hours ago