Corelight
Cybersecurity Advisory on Pro-Russia Hacktivist Threats
Pages
5
Time to read
7 mins
Publication
Language
English
Pages
5
Time to read
7 mins
Publication
Language
English
This document is a Joint Cybersecurity Advisory AA25-343A released by CISA, FBI, NSA, DOE, EPA, and international partners, detailing the activities of pro-Russia hacktivists targeting critical infrastructure. It outlines the attack sophistication of these groups, which, while less advanced than APT groups, still pose significant risks to operational technology (OT) environments. The advisory identifies primary attack vectors, including the exploitation of minimally secured Virtual Network Computing (VNC) connections, and highlights targeted sectors such as Energy, Food and Agriculture, and Water and Wastewater Systems. The document emphasizes the need for organizations to reduce exposure of OT assets, adopt mature asset management processes, and implement robust authentication procedures. Additionally, it discusses the unsophisticated tactics, techniques, and procedures (TTPs) employed by these hacktivists, including scanning for vulnerable devices and using brute force password attacks. The advisory serves as a critical resource for understanding the evolving threat landscape and implementing necessary defenses.