Pro-Russian Hacktivist Attacking OT/ICS Devices to Steal Login Credentials
## Introduction to TwoNet Hacktivist Group Activities
Introduction to TwoNet Hacktivist Group Activities
A new pro-Russian hacktivist group, known as TwoNet, has been identified as infiltrating operational technology (OT) and industrial control systems (ICS) within critical infrastructure organizations. The group has employed advanced techniques to steal login credentials and disrupt essential services.
TwoNet has expanded its operations beyond traditional distributed denial-of-service attacks, targeting human-machine interfaces and programmable logic controllers in industrial environments such as water treatment facilities and solar installations. Their operations have been detected across several European countries, focusing on utilities and energy infrastructure.
Database enumeration System defacement Process disruption Credential harvesting from OT/ICS devices
These activities represent an evolution in hacktivist capabilities, moving from website defacements to intricate manipulation of industrial processes.
The group has employed advanced techniques to steal login credentials and disrupt essential services.
Analysts from Forescout identified TwoNet's malware and attack patterns through honeypot operations. The research provided insights into the group’s tactics, techniques, and procedures, revealing specific attack vectors and the broader ecosystem of affiliated hacktivist groups.
TwoNet has shown expertise in exploiting default authentication mechanisms, utilizing SQL injection techniques, and exploiting known vulnerabilities in human-machine interface systems. Their operations cover multiple industrial protocols, including Modbus and S7 communications, indicating a sophisticated understanding of operational technology environments.
Database Exploitation and System Manipulation
The attackers employed advanced database enumeration techniques, logging into human-machine interfaces using default credentials and executing SQL queries to extract schema information. This process led to the creation of a new user account and maintaining access over extended sessions.
The group exploited CVE-2021-26829 to inject malicious JavaScript into login pages, creating persistent defacement and disabling security monitoring systems to conceal their activities.
The capabilities demonstrated by TwoNet, including advanced tooling and operational experience, indicate a significant escalation in hacktivist threats, presenting new challenges for cybersecurity professionals focused on protecting critical infrastructure.
Based on reporting by Cyber Security News.
