{"id":7648,"date":"2025-10-14T10:03:53","date_gmt":"2025-10-14T10:03:53","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/14\/pro-russian-hacktivist-attacking-ot-ics-devices-to-steal-login-credentials\/"},"modified":"2025-10-14T10:03:53","modified_gmt":"2025-10-14T10:03:53","slug":"pro-russian-hacktivist-attacking-ot-ics-devices-to-steal-login-credentials","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/14\/pro-russian-hacktivist-attacking-ot-ics-devices-to-steal-login-credentials\/","title":{"rendered":"Pro-Russian Hacktivist Attacking OT\/ICS Devices to Steal Login Credentials"},"content":{"rendered":"<p>    Pro-Russian Hacktivist Attacking OT\/ICS Devices to Steal Login Credentials<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A newly identified pro-Russian hacktivist group has successfully infiltrated operational technology and industrial control systems belonging to critical infrastructure organizations, employing sophisticated techniques to steal login credentials and disrupt vital services.<\/p>\n<p>The threat actor, known as TwoNet, represents an emerging class of hacktivists who have expanded beyond traditional distributed denial-of-service attacks to target human-machine interfaces and programmable logic controllers in water treatment facilities, solar installations, and other industrial environments.<\/p>\n<p>The group\u2019s attack methodology demonstrates a concerning evolution in hacktivist capabilities, moving from simple website defacements to complex manipulation of industrial processes.<\/p>\n<p>TwoNet\u2019s operations have been observed across multiple European countries, with particular focus on utilities and energy infrastructure in nations they consider adversarial.<\/p>\n<p>Their activities include database enumeration, system defacement, process disruption, and credential harvesting from internet-exposed OT\/ICS devices.<\/p>\n<p>Forescout analysts <a href=\"https:\/\/www.forescout.com\/blog\/anatomy-of-a-hacktivist-attack-russian-aligned-group-targets-otics\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the malware and attack patterns through sophisticated honeypot operations designed to attract and monitor threat actors targeting critical infrastructure.<\/p>\n<p>The research team\u2019s water treatment facility honeypot successfully captured TwoNet\u2019s intrusion methodology, providing unprecedented visibility into the group\u2019s tactics, techniques, and procedures.<\/p>\n<p>This intelligence gathering effort revealed not only the specific attack vectors employed but also the broader ecosystem of affiliated hacktivist groups operating in coordination.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEghxyz5cmBAQYUhylolwQb4vrSbosL7F-ssjkxpDUswFmPbTMqI1SK6RIR1RgvQjTEAjLF04Pon-x0Qb0Jx5t8yyK09rPcSqMZGxgJpHPWujia98us6Rya4HqsFTbQHXJEqI-XPPBxWVJGIxg3nJfJRDN1pODZbDzyxXBjuBJK8Wk_xeI2x7BILNePiOyY\/s16000\/Threat%2520Actor%2520Network%2520and%2520Affiliations%2520%28Source%2520-%2520Forescout%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Threat Actor Network and Affiliations (Source \u2013 Forescout)<\/figcaption><\/figure>\n<\/div>\n<p>The attackers demonstrated particular expertise in exploiting default <a href=\"https:\/\/cybersecuritynews.com\/esphome-web-server-authentication-bypass\/\" target=\"_blank\" rel=\"noreferrer noopener\">authentication<\/a> mechanisms, utilizing SQL injection techniques, and leveraging known vulnerabilities in human-machine interface systems.<\/p>\n<p>Their operations span multiple industrial protocols including Modbus and S7 communications, indicating sophisticated knowledge of operational technology environments.<\/p>\n<p>The group\u2019s ability to maintain persistence across multiple login sessions and systematically alter critical system configurations represents a significant escalation in hacktivist threat capabilities.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-advanced-database-exploitation-and-system-manipulation-techniques\"><strong>Advanced Database Exploitation and System Manipulation Techniques<\/strong><\/h2>\n<p>The intrusion methodology employed by TwoNet reveals sophisticated database enumeration capabilities that extend far beyond typical hacktivist operations.<\/p>\n<p>The attackers initiated their assault by logging into the human-machine interface using default credentials (admin\/admin), immediately proceeding to execute complex SQL queries designed to extract comprehensive schema information from the target system.<\/p>\n<p>The group\u2019s initial database <a href=\"https:\/\/cybersecuritynews.com\/morphing-meerkat-phaas-using-dns-reconnaissance\/\" target=\"_blank\" rel=\"noreferrer noopener\">reconnaissance<\/a> involved executing sophisticated queries through the sql.shtm page, beginning with failed attempts using primary key enumeration commands.<\/p>\n<p>When these initial queries failed, the attackers demonstrated remarkable <a href=\"https:\/\/cybersecuritynews.com\/detecting-and-responding-to-new-nation-state-persistence-techniques\/\" target=\"_blank\" rel=\"noreferrer noopener\">persistence<\/a> by modifying their approach and successfully extracting detailed table structures using alternative SQL syntax:-<\/p>\n<pre class=\"wp-block-code\"><code>SELECT t.TABLENAME, c.COLUMNNAME, c.COLUMNNUMBER, c.COLUMNDATATYPE,\nc.COLUMNDEFAULT, c.AUTOINCREMENTVALUE, c.AUTOINCREMENTSTART,\nc.AUTOINCREMENTINC\nFROM sys.systables t\nJOIN sys.syscolumns c ON t.TABLEID = c.REFERENCEID\nWHERE t.tabletype = 'T'\nORDER BY t.TABLENAME, c.COLUMNNUMBER<\/code><\/pre>\n<p>Following successful database enumeration, the attackers created a new user account named \u201cBARLATI\u201d and maintained access across multiple sessions spanning nearly 24 hours.<\/p>\n<p>Their systematic approach included exploiting CVE-2021-26829 to inject malicious <a href=\"https:\/\/cybersecuritynews.com\/detecting-malicious-javascript-using-behavior-analysis-and-network-traces\/\" target=\"_blank\" rel=\"noreferrer noopener\">JavaScript<\/a> code into the HMI login page, creating persistent defacement that would trigger alerts whenever administrators accessed the system.<\/p>\n<p>The attackers also demonstrated advanced operational security by modifying system settings to disable logging and alarm mechanisms, effectively blinding <a href=\"https:\/\/cybersecuritynews.com\/enterprise-security-monitoring-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">security monitoring<\/a> systems to their ongoing activities.<\/p>\n<p>The sophistication of these database manipulation techniques, combined with the group\u2019s ability to maintain operational security while conducting multi-stage attacks, indicates access to advanced tooling and significant operational experience that extends beyond typical hacktivist capabilities.<\/p>\n<p class=\"has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/pro-russian-hacktivist-attacking-ot-ics-devices\/\">Pro-Russian Hacktivist Attacking OT\/ICS Devices to Steal Login Credentials<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/pro-russian-hacktivist-attacking-ot-ics-devices\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Pro-Russian Hacktivist Attacking OT\/ICS Devices to Steal Login Credentials A newly identified pro-Russian hacktivist group has successfully infiltrated operational technology and industrial control systems belonging to critical infrastructure organizations, employing sophisticated techniques to steal login credentials and disrupt vital services. The threat actor, known as TwoNet, represents an emerging class of hacktivists who have expanded [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-7648","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7648"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7648"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7648\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7648"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7648"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7648"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}