Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Hijacking VNC Connections to Gain Access to OT Control Devices in Critical Infrastructure

A coalition of U.S. and international cybersecurity agencies has issued a warning regarding the exploitation of exposed Virtual Network Computing (VNC) connections by pro-Russia hacktivists. These attacks target operational technology (OT) systems within…

A coalition of U.S. and international cybersecurity agencies has issued a warning regarding the exploitation of exposed Virtual Network Computing (VNC) connections by pro-Russia hacktivists. These attacks target operational technology (OT) systems within critical infrastructure sectors.

The advisory, released on Tue, Dec 9, 2025, identifies groups such as Cyber Army of Russia Reborn (CARR), Z-Pentest, NoName057(16), and Sector16. These groups are focusing on the water, food, agriculture, and energy sectors using straightforward but effective techniques.

The groups have adapted their strategies since geopolitical tensions increased following Russia's 2022 invasion of Ukraine. CARR has transitioned to OT attacks, with claims of targeting European wastewater plants and U.S. dairy farms. NoName057(16) specializes in DDoS attacks and collaborates on intrusions. New entities like Z-Pentest and Sector16 engage in "hack and leak" operations.

These actors primarily target internet-facing human-machine interfaces (HMIs) with inadequate VNC protections. They utilize tools like Nmap and OpenVAS to scan ports such as 5900, employing VPS-hosted brute-force tools against weak passwords. This allows them to manipulate graphical user interfaces (GUIs) to alter parameters and disable alarms, causing "loss of view" incidents that require manual intervention.

The advisory covers MITRE ATT&CK techniques from reconnaissance to impact, including tactics like logging credentials and posting online proofs. The primary motive is generating media attention rather than espionage.

These attacks target operational technology (OT) systems within critical infrastructure sectors.
Emily Carter · Thehackingpost

Victims of these attacks experience downtime and remediation costs, with occasional physical damage to processes. A notable incident occurred in April 2025, where DDoS attacks facilitated SCADA access, highlighting shared tactics among the groups.

Although no injuries have been reported, the risks to occupied sites are escalating. The impacts include reprogramming fees and operational halts, exacerbated by the attackers' disregard for safety.

Owners of critical infrastructure are advised to take immediate action. Key measures include:

Eliminating internet-exposed OT Segmenting IT/OT networks Enforcing multifactor authentication (MFA) Prohibiting default settings

Advertisement

Organizations should use attack surface tools to identify VNC exposures, audit firewalls, and enable view-only modes. Manufacturers are encouraged to produce "secure by design" devices, incorporating no default settings, software bills of materials (SBOMs), and free logging.

Additional recommendations include backing up HMIs, testing manual failsafes, and monitoring anomalies. In case of an incident, isolate affected systems, hunt threats, reimage systems, re-provision credentials, and report to relevant authorities such as CISA or the FBI.

This advisory builds upon prior alerts, such as CISA's May 2025 OT mitigations, calling for global vigilance. As hacktivists continue to evolve, proactive hardening is essential to counter these low-barrier threats effectively.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories