Critical Infrastructure Security, Threat Intelligence

Global critical infrastructure targeted by pro-Russia hacktivists

High voltage substation under sunset. The Department of Energy is putting $12 million behind six university-led cybersecurity research projects that look for innovative ways to securely build or design the nation’s energy systems. (Photo Credit: bjdlzx via Getty Images)

Organizations in the energy, water, and food and agriculture industries around the world were noted by the U.S. and its allies to have been compromised by multiple pro-Russia hacktivists groups via vulnerable industrial equipment connections, reports Cybersecurity Dive.

Attacks by Cyber Army of Russia Reborn, Sector16, NoName057(16), and Z-Pentest involved password spraying tactics to remotely infiltrate industrial equipment-controlling human machine interface devices, send commands to HMIs, and alter device credentials, according to a joint advisory from the Cybersecurity and Infrastructure Security Agency, the FBI, the National Security Agency, and three other U.S. federal agencies, as well as Europol and agencies from Canada, Australia, the UK, and a dozen other countries.

"[Groups'] apparent low level of technical knowledge results in haphazard attacks where actors intend to cause physical damage but cannot accurately anticipate actual impact. Despite these limitations, the authoring organizations have observed these groups willfully cause actual harm to vulnerable critical infrastructure," said the alert.

Such a development comes as the U.S. charged Ukrainian national Victoria Eduardovna Dubranova for helping two Russian hacktivist operations in conducting attacks against critical infrastructure.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds