Hackers Hijacking VNC Connections to Gain Access to OT Control Devices in Critical Infrastructure
A coalition of U.S. and international cybersecurity agencies has issued a warning regarding the exploitation of exposed Virtual Network Computing (VNC) connections by pro-Russia hacktivists. These attacks target operational technology (OT) systems within…
A coalition of U.S. and international cybersecurity agencies has issued a warning regarding the exploitation of exposed Virtual Network Computing (VNC) connections by pro-Russia hacktivists. These attacks target operational technology (OT) systems within critical infrastructure sectors.
The advisory, released on Tue, Dec 9, 2025, identifies groups such as Cyber Army of Russia Reborn (CARR), Z-Pentest, NoName057(16), and Sector16. These groups are focusing on the water, food, agriculture, and energy sectors using straightforward but effective techniques.
The groups have adapted their strategies since geopolitical tensions increased following Russia's 2022 invasion of Ukraine. CARR has transitioned to OT attacks, with claims of targeting European wastewater plants and U.S. dairy farms. NoName057(16) specializes in DDoS attacks and collaborates on intrusions. New entities like Z-Pentest and Sector16 engage in "hack and leak" operations.
These actors primarily target internet-facing human-machine interfaces (HMIs) with inadequate VNC protections. They utilize tools like Nmap and OpenVAS to scan ports such as 5900, employing VPS-hosted brute-force tools against weak passwords. This allows them to manipulate graphical user interfaces (GUIs) to alter parameters and disable alarms, causing "loss of view" incidents that require manual intervention.
The advisory covers MITRE ATT&CK techniques from reconnaissance to impact, including tactics like logging credentials and posting online proofs. The primary motive is generating media attention rather than espionage.
These attacks target operational technology (OT) systems within critical infrastructure sectors.
Victims of these attacks experience downtime and remediation costs, with occasional physical damage to processes. A notable incident occurred in April 2025, where DDoS attacks facilitated SCADA access, highlighting shared tactics among the groups.
Although no injuries have been reported, the risks to occupied sites are escalating. The impacts include reprogramming fees and operational halts, exacerbated by the attackers' disregard for safety.
Owners of critical infrastructure are advised to take immediate action. Key measures include:
Eliminating internet-exposed OT Segmenting IT/OT networks Enforcing multifactor authentication (MFA) Prohibiting default settings
Organizations should use attack surface tools to identify VNC exposures, audit firewalls, and enable view-only modes. Manufacturers are encouraged to produce "secure by design" devices, incorporating no default settings, software bills of materials (SBOMs), and free logging.
Additional recommendations include backing up HMIs, testing manual failsafes, and monitoring anomalies. In case of an incident, isolate affected systems, hunt threats, reimage systems, re-provision credentials, and report to relevant authorities such as CISA or the FBI.
This advisory builds upon prior alerts, such as CISA's May 2025 OT mitigations, calling for global vigilance. As hacktivists continue to evolve, proactive hardening is essential to counter these low-barrier threats effectively.
Based on reporting by Cyber Security News.
