OT Threat Intelligence: Hacktivists Targeting OT
Hacktivists targeting OT have shifted from website defacement and DDoS to interfering directly with industrial processes, and the barrier to entry has collapsed. Most of the intrusions documented here used exposed remote access and default credentials rather than novel exploits. This KELA Cyber Intelligence Center report tracks pro-Russian and Iranian-linked campaigns against water, wastewater, and energy systems, the OT-focused scanning tools the groups build and sell to each other, and where the claimed impact does not survive verification.
Updated September 3, 2026

Executive Summary
The threat landscape affecting operational technology (OT) and industrial control systems (ICS) is undergoing a structural shift. Hacktivists are moving rapidly from focusing on passive espionage, website defacements and distributed denial-of-service (DDoS) attacks toward active operational disruption of physical industrial processes. Traditionally the exclusive domain of sophisticated, state-sponsored Advanced Persistent Threats (APTs), the targeting of cyber-physical systems (CPS) has been heavily democratized. Geopolitical tensions in Eastern Europe and the Middle East have catalyzed a surge in hacktivist collectives acting as state proxies or independent ideologues, demonstrating a growing willingness to target critical civilian infrastructure in the United States, Europe, Australia, and Israel.
While many recent hacktivist campaigns appear opportunistic, relying on weak configurations, default credentials, or publicly exposed services rather than sophisticated exploitation, they nonetheless present tangible operational and safety risks. Furthermore, with the increasing convergence of IT and OT networks and the consistent sharing of specialized OT-focused tooling, cyber-physical systems have become a permanent and attractive target. This exposure is worsened by systemic vulnerabilities in the field. Industrial cybersecurity studies indicate that fewer than 10% of OT networks have internal monitoring capabilities to detect active scanning, lateral movement, or the mapping of physical control loops. Consequently, attackers are able to operate with significant dwell times.
Against this backdrop, organizations should treat cyber threat intelligence (CTI) as a core component of OT risk management rather than as a supplementary security function. Continuous monitoring of threat actors, hacktivist channels, underground communities, initial access brokers, exposed-asset discussions, newly disclosed vulnerabilities, and evolving adversary tactics can provide early warning of emerging campaigns and shifts in targeting intent. By integrating external intelligence with internal telemetry and asset inventories, organizations can prioritize the most credible threats, adapt defensive controls as adversary behavior evolves, and reduce the time between the emergence of a threat and the implementation of protective measures. This intelligence-led approach is particularly important in an environment where hacktivist campaigns can develop rapidly in response to geopolitical events, public disclosures, or the discovery of exposed industrial systems.
If you missed our previous blog about how OT and IT, catch up here about how each team perceives risks, and what each can do about it.
Eurasian and Pro-Russian Campaigns Against Western OT/ICS Infrastructure
Pro-Russian hacktivist groups, operating under varying degrees of state coordination, have consistently targeted "low-hanging fruit", underfunded and under-resourced water, wastewater, and energy utilities in the US and NATO member states. These small-scale facilities often expose their control systems directly to the internet to facilitate remote troubleshooting, lack multifactor authentication (MFA), and do not maintain proper OT/IT network segmentation.
Case Studies of OT Manipulation and Claimed Operational Disruption: The Cyber Army of Russia Reborn (CARR)
The Cyber Army of Russia Reborn (CARR) is a hacktivist group operating on infrastructure linked with high confidence to the Russian GRU's Unit 74455 (Sandworm/APT44); however, its exact membership is fluid, and the degree to which Russian intelligence directly dictates its daily operations remains unclear. It has executed multiple disruptive campaigns against Western municipal utilities:
- Muleshoe, Texas (January 2024): CARR exploited an exposed remote login system for industrial software controlling a municipal water tank. The hackers manually manipulated the Human-Machine Interface (HMI) to override pump controls, causing the water tank to overflow and spill raw water. Operators had to take the system offline and switch to manual controls to stop the disruption.
- Stanton, Texas (August 2024): The group claimed to gain unauthorized access to an exposed HMI regulating water filtration, turbidity, and flow rates. Video evidence posted on the group's Telegram channel showed the attackers allegedly randomly inputting numbers and adjusting configuration valves over several minutes, eventually causing the utility to discharge untreated raw water.
- European Operations (Poland and France): In January 2023, CARR attempted to sabotage a wastewater facility in a small Polish village. In April 2024, the group gained access to the control system of a small water mill in France, posting screen recordings and making exaggerated claims that they had shut off its electricity generation and altered dam levels.
OT security experts note that these intrusions resemble opportunistic disruption rather than highly engineered physical destruction. The attackers typically do not understand the physics of the target processes; instead, they randomly click interface controls to create a visible effect that can be recorded and shared on social media for propaganda purposes.
Custom Tooling and Access Sharing: Z-Pentest and the TRK25 Scanner
To scale their operations, pro-Russian alliances like Z-Pentest (which includes the Infrastructure Destruction Squad, also known as Dark Engine) develop and share custom OT-focused scanning tools. In the beginning of 2026, they published the source code of a GUI-based utility called the TRK25 ADVANCED SCADA tool on their Telegram channel.
The TRK25 tool is a custom port scanner designed to sweep attacker-defined IP ranges for open ports associated with industrial protocols and remote access interfaces. Specifically, it is reported to probe:
- Modbus (Port 502) and OPC-UA (Port 4840): Looking for unauthenticated industrial endpoints.
- RDP (Port 3389) and VNC (Port 5900): Looking for exposed remote desktop sessions. A core feature of TRK25 is its ability to automatically take screenshots of VNC and RDP sessions that have authentication disabled This allows attackers to quickly filter for active, unsecured HMIs out of the estimated 60,000 VNC servers globally that run without passwords. Testing and operational IP ranges embedded in the tool and subsequent leaks revealed that TRK25 was actively deployed against infrastructure in France, Turkey, Germany, South Korea, Taiwan, and Australia. Furthermore, Infrastructure Destruction Squad routinely monetizes lower-value targets by selling exposed SCADA access on dark web forums and marketing a Python-based ransomware builder called “BlackNet-00”, starting from 2000 USD.2
Screenshot of BlackNet-00 ransomware builder shared by hacktivists
2026 Pro-Russian Hacktivists Activity Against Energy-Related OT and IoT Systems
Two pro-Russian hacktivist entities, AlfaNet and Z-Pentest Alliance, claimed compromises of energy-related OT/IoT systems in Bulgaria and Taiwan in 2026.
In Bulgaria, the group alleged full compromise of a Rapid SCADA server connected to energy and gas infrastructure, claiming administrative access enabled by default credentials, RCE vulnerabilities, and poor OT network segmentation. Separately, under #OpTaiwan claimed access to a smart remote meter reading and energy management system used in Taiwanese rental housing, allegedly enabling real-time monitoring of electricity consumption, voltage, current, power levels, overload alerts, and limited control functions such as lighting and electromagnetic door locks.
Z-Pentest claims to hack hacked an energy metering and management system | KELA Platform
In March 2026, the pro-Russian Z-Pentest Alliance claimed to have compromised the remote management system of a luxury golf course in South Korea, alleging access to an OT/SCADA platform controlling pumps, lighting, course infrastructure, and other facility systems. The group claimed the system was exposed with default credentials and asserted it could disrupt the site's operations. However, the claims were supported only by screenshots and statements from the threat actor, with no independent verification of the alleged access or operational impact.
Z-Pentest targets South Korea| KELA Platform
Additionally, in June 2026, NoName057(16) had gained access to the energy management and heating system of a private facility in the Netherlands, allegedly enabling control over heating parameters, circulation pumps, valves, and other HMI functions. The claim was supported by an HMI screenshot and video. However, the target appears to be a private residence rather than critical infrastructure, and there is no independent evidence confirming the claimed level of access or any operational impact.
NoName057(16) targets Netherlands | KELA Platform
The claims in this chapter highlight continued hacktivist interest in exposed OT, IoT, and energy-management environments, particularly systems with weak remote access controls, poor segmentation, and outdated or insecure configurations. While the group framed the activity as politically motivated cyber reconnaissance and exposure, the alleged access could present operational and safety risks if confirmed, especially where energy monitoring, building access controls, or SCADA-connected environments are reachable from insufficiently protected networks.
Dedicated Channels
In June 2026, KELA observed a trend in which threat actors opened dedicated Telegram channels to advertise and sell tools allegedly designed for attacks against industrial systems, OT environments, and critical infrastructure. One such example is TRK25 ADVANCED ICS, a Telegram channel promoting malicious software and penetration tools targeting industrial control systems, including PLCs, SCADA environments, RTUs, IEDs, energy management systems, remote communication servers, and control centers.
The actor claimed that the TRK25 ADVANCED SCADA tool can scan CIDR ranges, identify industrial services such as Modbus, Siemens S7, DNP3, OPC, VNC, RDP, and SSH, classify discovered devices by risk level, generate reports, perform password guessing, access remote screens, capture screenshots, and interfere with HMI interfaces. The tool was advertised for $200 with full source code and one week of support, using Infrastructure Destruction Squad’s contact handle @blacknetransom.
A dedicated Telegram channel for selling tools targeting ICS and OT systems
Middle Eastern Hacktivism & State-Backed Fronts: Tactical Comparative Analysis
In the Middle Eastern theater, the line between grass-roots hacktivism and state-directed destructive operations is heavily blurred. While pro-Russian hacktivists focus primarily on opportunistic remote desktop takeovers, some Iranian groups exhibit deeper technical knowledge of PLC memory maps, custom protocol manipulation, and software supply chains.
CyberAv3ngers: From Default Password Exploitation to Authentication Bypassֵ
CyberAv3ngers, officially attributed to the Iranian Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC), has operated a multi-wave campaign targeting Western critical infrastructure:
- Phase 1 (Late 2023 – 2024): The group launched opportunistic attacks against Israeli-manufactured Unitronics Vision PLCs deployed in water and energy sectors across the US (including the Municipal Water Authority of Aliquippa, Pennsylvania) and Ireland. The attackers scanned for TCP port 20256 exposed to the public internet. By authenticating with default or blank passwords, they overwrote ladder logic files, altered device configurations to lock out operators, and forced the integrated HMIs to display anti-Israel propaganda.
- Phase 2 (2026 – Present): The group transitioned to targeting higher-tier industrial hardware, specifically Rockwell Automation Logix controllers. Instead of relying on default passwords, the group began exploiting CVE-2021-22681, an authentication bypass vulnerability stemming from an unprotected cryptographic key used to verify communication between Rockwell's Studio 5000 Logix Designer and the PLCs. By extracting or replicating this key, the attackers can connect to internet-exposed controllers without authentication, download modified project configurations, and disrupt industrial processes.
To maintain persistent access across compromised IoT/OT devices, CyberAv3ngers developed the IOCONTROL malware (also known as OrpraCab or QueueCat). IOCONTROL is reported as a modular Linux-based payload deployed on routers, PLCs, firewalls, and fuel management systems. It utilizes MQTT over TLS (Port 8883) for Command-and-Control (C2) communication to blend with standard IoT traffic, resolves domains using DNS-over-HTTPS (DoH) to bypass DNS monitoring, and encrypts its local configurations using AES-256-CBC.
Pro-Palestine Hackers Movement (PPHM) and Al Ahad Allianceֵ
Operating within the "Holy League" alliance alongside pro-Russian entities, the Pro-Palestine Hackers Movement (PPHM) and Al Ahad coordinate high-profile DDoS and targeted ICS intrusions:
- PPHM: Active since October 2023, PPHM uses Metasploit frameworks to scan and exploit SCADA/ICS vulnerabilities. The group also used custom iOS spyware, such as Phenakite, which bypasses security checks to execute remote jailbreaks, record audio, and exfiltrate GPS metadata from compromised mobile endpoints.
- Al Ahad: Emerging in late 2024, Al Ahad utilizes decentralized operations on Signal and Signal-boosting partnerships with NoName057(16). They target software vulnerabilities in content management systems (such as WordPress) of energy companies to establish initial footholds, using social engineering and fake journalist personas to distribute malicious payloads.
Al Ahad targets energy companies, together with NoName057(16) | KELA Platform
Targeting of Modbus-Enabled Industrial Control Systems
Pro-Palestinian hacktivist actors have increasingly claimed attacks against internet-exposed industrial control systems using tools designed to manipulate the Modbus protocol. In September 2025, the Telegram channel “UNIT 1948” published a list of IP addresses and announced completion of “Phase 5” of an operation dubbed “Modbus Killer.” In other incident by the same group, KELA’s investigation linked the activity to a script referred to as “Mod Killer,” which appeared to target Schneider Electric TSXETY4103 PLC units by manipulating registers, files, and control commands, potentially enabling denial-of-service, process disruption, and unauthorized changes to industrial operations.
Screenshots from the channel display the initial post detailing the Modbus protocol, alongside the first and second sets of IP addresses compromised by the Modkiller script
Similar claims were later published by the “Infrastructure Destruction Squad,” which identified exposed SCADA and Modbus systems and described possible techniques such as register modification, PLC logic manipulation, HMI takeover, and system shutdown. On July 7, 2026, the group TheSweetNight also claimed to have compromised the Modbus interface of Indonesia’s National Research and Innovation Agency and shut down a nuclear research facility’s water-pump system.
Technical Breakdown of Industrial Protocols: Modbus TCP and Scanning Realities
The Modbus TCP protocol (operating by default on Port 502) is a primary target for hacktivists due to its complete lack of native security controls. Developed without authentication, encryption, or input validation, the protocol treats any client that can establish a TCP connection on port 502 as a fully authorized operator. Although Modbus/TCP Security adds TLS-based authentication and integrity on port 802, legacy port 502 deployments remain common and should not be exposed to untrusted networks.
Hacktivists execute process disruptions by sending raw TCP socket packets containing malicious function codes to exposed PLCs:
- Function Code 0x01 (Read Coils): Used to map digital outputs (e.g., whether a valve is open or closed).
- Function Code 0x03 (Read Holding Registers): Used to read analog configuration states, temperature thresholds, or setpoints.
- Function Code 0x05 / 0x06 (Write Single Coil / Register): Used to force a valve closed, stop a pump, or alter a single configuration register.
- Function Code 0x10 (Write Multiple Registers): Used to execute bulk overwrites to holding registers. If these registers map to process setpoints or control variables, unauthorized use can alter process behavior or disrupt operations, with the specific impact depending on device configuration, register mapping, and process logic.
Historically, hacktivist groups used Metasploit modules alongside custom Python and Go scripts, such as KillBus and theComposer.py, to execute attacks against Modbus and IEC-104 client terminals. A modern iteration of this script-based threat is FrostyGoop, a command-line utility built in Golang that reads target parameters from a local JSON file and executes Modbus function codes 0x03, 0x06, and 0x10 directly against industrial targets without needing to exploit any software vulnerabilities.
Table 1: Key Industrial Protocol & Device Vulnerabilities
The following table summarizes representative OT vulnerabilities and attack vectors that have been exploited or observed in industrial environments. It highlights the affected assets, the underlying technical mechanisms, the potential operational impact, and recommended mitigations to reduce the risk of unauthorized access and manipulation of industrial control systems.
Target Asset | ||||
|---|---|---|---|---|
Vulnerability / Attack Vector | CVE-2021-22681 (CVSS: 9.8) | Exposed Port TCP 20256 / Default Passwords | Protocol by Design (No auth or encryption) | Default SSH Port 22 & Weak Root Credentials |
Technical Mechanism | Unprotected cryptographic key used for software-to-PLC verification | Direct unauthenticated connection via default port | Sending raw TCP packets containing malicious function codes (e.g., 0x06, 0x10) | Brute-forcing the root password on exposed OpenWrt SSH services |
Impact on Process | Unauthorized modifications to PLC logic and project configurations | Alteration of ladder logic, device renaming, and interface defacement | Unauthorized physical valve, pump, or temperature setpoint manipulation | Ransomware encryption of configuration scripts and files |
Mitigations | Keep controllers in RUN mode during normal operations and use PROGRAM or REMOTE only for authorized maintenance. Combine this with segmentation, access controls, change monitoring, and secure engineering-workstation practices | Enforce strong passwords using VisiLogic version 9.9.00 or higher | Implement rigorous OT network segmentation and block external access | Change default root passwords; disable external SSH access; restrict management access to trusted networks; and monitor for configuration-file changes |
Strategic Defensive Recommendations
To mitigate opportunistic hacktivist campaigns targeting critical infrastructure, OT asset owners should immediately implement the following controls:
- Integrate Cyber Threat Intelligence (CTI): Treat CTI as a core component of OT risk management to enable proactive defense. By continuously monitoring adversary tactics, hacktivist channels, and evolving threats, organizations can gain early warning of campaigns, prioritize risks based on credible intelligence, and adapt defensive controls to mitigate emerging threats before they impact operational processes.
- Eliminate Direct Internet Exposure: Conduct regular audits to ensure no PLCs, HMIs, or RTUs, engineering workstations, VNC/RDP services, and remote-management portals are directly addressable from the public internet.
- Enforce Secure Remote Access (SRA): Replace consumer-grade remote control tools (such as TeamViewer or AnyDesk) with enterprise-grade Secure Remote Access gateways that enforce multifactor authentication (MFA). Use an OT DMZ, jump host, or purpose-built SRA gateway that enforces multifactor authentication (MFA), least privilege, session recording, device allowlisting, time-bound approvals, and vendor-specific access controls. Avoid exposing raw industrial protocols or remote-desktop services directly to the internet, and utilize protocol translation so that fragile protocols like Modbus never leave the physical network perimeter.
- Harden Controller Physical Mode Switches: For Rockwell/Allen-Bradley and other controllers with physical mode switches, keep controllers in RUN mode during normal operation and move to PROGRAM/REMOTE only during authorized maintenance. Pair this with controller-change monitoring, engineering-workstation hardening, and documented maintenance approval.
- Implement IT/OT Segmentation: Enforce strict firewall rules between the corporate IT network and the OT production network, ensuring that compromised office workstations or email servers cannot be used to pivot directly to engineering workstations, HMIs, remote-access services or controllers.
- Deploy Deep Packet Inspection (DPI): Utilize OT-aware Intrusion Detection Systems (IDS) capable of parsing industrial protocols. Baseline normal industrial traffic and configure alerts for anomalies such as unauthorized Modbus write commands (e.g., Function Code 0x10), engineering-session activity, controller logic changes, unexpected HMI/PLC communications, new VNC/RDP exposure, unexpected MQTT over TLS (Port 8883) outbound traffic originating from the OT zone, and write operations occurring outside approved maintenance windows.
- VNC/RDP-specific Hardening: Disable direct public access to VNC, RDP, and vendor remote-support tools. Where remote desktop is operationally required, place access behind an OT SRA gateway or VPN with MFA, strong passwords, account lockout, session recording, patching, and network allowlists.
- Recovery and Configuration Backups: Maintain offline, tested backups of PLC logic, HMI projects, historian configurations, engineering workstation images, and network-device configs. Test recovery procedures during tabletop and plant-floor exercises.
Hacktivists Targeting OT: FAQ
Which hacktivist groups are targeting OT systems?
The groups documented in this report fall into two clusters. Pro-Russian entities including the Cyber Army of Russia Reborn, the Z-Pentest alliance and its Infrastructure Destruction Squad, AlfaNet, and NoName057(16) have targeted water, wastewater, and energy systems across the United States, Europe, and Asia. Iranian-aligned and pro-Palestinian groups including CyberAv3ngers, the Pro-Palestine Hackers Movement, and Al Ahad have targeted programmable logic controllers and Modbus-enabled systems, generally with deeper technical knowledge than their pro-Russian counterparts. Membership across most of these groups is fluid, and the degree of state direction varies and is often unclear.
How do hacktivists gain access to industrial control systems?
Usually through something that was already open. The recurring methods are exposed remote login interfaces, Human-Machine Interfaces reachable from the public internet, default or blank passwords, VNC and RDP sessions with authentication disabled, and industrial protocols such as Modbus TCP on port 502 that were designed without authentication or encryption and treat any client that connects as an authorized operator. Novel exploitation is the exception. One group did move to exploiting a specific authentication bypass in a controller family, which is a meaningful escalation, but it remains the outlier rather than the pattern.
Are hacktivist claims about disrupting critical infrastructure reliable?
Frequently not, and the gap matters in both directions. Groups routinely present screenshots and video as evidence of control they have not demonstrated, and in one case reviewed here a claim framed as critical infrastructure appears to describe a private residence. Independent verification of claimed operational impact is rare. The takeaway is that inflated claims and real exposure coexist: the same systems producing exaggerated propaganda were genuinely reachable, genuinely unauthenticated, and in several documented cases genuinely manipulated. Discounting the theater is not the same as discounting the risk.












