Blog Anatomy of a Hacktivist Attack: RussianAligned Group Targets OT/ICS

Forescout honeypot caught hacktivist activity targeting a decoy water treatment plant in Sept. 2025. A Russian-aligned group, TwoNet, claimed responsibility for the attack. The group logged into the human-machine interface (HMI) for: defacement, process disruption, manipulation, and evasion. Author: AlienVault

Related Tags:
overflame

human-machine interface

TwoNet

megaMedusa

T1031

T1464

russian

T1016.001

raas

Associated Indicators:
45.157.234.199

2.181.103.232

92.43.161.74

77.91.122.234

45.14.247.87

87.150.146.207

80.210.133.38

95.90.199.75

212.83.190.55