HomeMalware & ThreatsPro-Russia Hacktivists Ramp Up OT Intrusion Claims Across EU

Pro-Russia Hacktivists Ramp Up OT Intrusion Claims Across EU

Published on

spot_img

ENISA Reports Significant Cyber Threats Targeting Critical Infrastructure by Pro-Russia Hacktivists

In a recent alarming report by the European Union Agency for Cybersecurity (ENISA), evidence indicates a dramatic rise in cyberattacks against operational technology (OT) and industrial environments, particularly attributed to pro-Russia hacktivist groups. This surge underscores growing vulnerabilities within critical infrastructure across Europe, prompting concerns about the security landscape in these vital sectors.

ENISA’s annual Threat Landscape report revealed that in 2025, ideology-driven cyberattacks constituted a staggering 57.3% of total recorded incidents. Comparatively, financially motivated attacks accounted for approximately 30%. A total of 4,709 hacktivist claims were made against EU member states, with a striking 89.5% of these incidents centered on distributed denial-of-service (DDoS) attacks. The remaining claims involved unauthorized access to systems, aggravating the already precarious cybersecurity scenario in Europe.

During a briefing, Jamila Boutemeur, head of ENISA’s threat analysis team, emphasized the concerning nature of these findings. She pointed out that while the DDoS attacks initiated by hacktivists often caused minimal disruption—usually lasting only a few minutes or hours—the increase in unauthorized access incidents, particularly targeting operational technology, warranted heightened vigilance. She stated, "Operational technology systems are particularly deployed within organizations involved in critical sectors, such as the energy sector, telecommunications, and transport. So, of course, this is something that should be highlighted and watched."

Prominently mentioned in the report was the pro-Russia group, NoName057(16), which was identified as the leading perpetrator of these attacks. Following a significant infrastructure takedown orchestrated by Europol in mid-2025, it was anticipated that the activities of NoName057(16) would diminish. However, the group maintained its level of activity throughout the year, being responsible for nearly 48% of recorded hacktivist attacks. The report noted that other hacktivist groups, such as Dark Storm Team, Keymous+, and Mr. Hamza—motivated by pro-Palestinian sentiments—also contributed to the total statistics for that year.

The increased targeting of operational technology systems has raised alarms within various sectors, particularly as these systems are integral to critical infrastructure. Attackers aimed at compromising OT systems in Europe, with noteworthy episodes linked to Russian-affiliated entities attempting to breach water infrastructure. A significant incident at the end of December 2025 reportedly involved the deployment of data-wiping malware against Poland’s power grid, an attack that security researchers attributed to Russian military intelligence.

The report also shed light on the pattern of targeted sectors. Public administration emerged as the most affected entity in the EU in 2025, accounting for 32% of incidents. Other sectors, including business services and transport, each represented 8% of the cases, followed by manufacturing at 7% and finance and banking at 6%. Notably, after hacktivism, cybercrime accounted for 36% of reported incidents, with ransomware being implicated in two-fifths of those cases.

A significant observation within the report is the inherent complexity of categorizing cyberattacks. The blurring lines between cybercriminal activities and state-sponsored operations create challenges in understanding the nature of different attacks. Boutemeur pointed out that although this "blurriness" poses certain challenges, defenders should focus on identifying attack pathways rather than simply classifications of threats. She further emphasized the importance of understanding vulnerabilities, particularly as 71% of reported vulnerabilities in 2025 highlighted the network as the attack vector, indicating that internet-facing systems remain especially susceptible to exploitation.

The total number of weaknesses reported in 2025 escalated by 22% compared to the previous year, with more than 48,000 flaws being assigned Common Vulnerabilities and Exposures (CVE) identifiers. While not all disclosed vulnerabilities were exploited, the sheer increase is disconcerting, as it opens up more possibilities for attackers.

Boutemeur noted the rise of third-party and supply chain attacks as another noteworthy trend. These assaults occur when attackers target a supplier or intermediary organization that provides a pathway to their ultimate victim. Furthermore, attacks on EU institutions and officials beyond European borders have been on the rise, demonstrating the expansive reach of malicious actors.

Additionally, the impact of artificial intelligence on these cybersecurity dynamics is highlighted in the report. In 2025, before the advent of sophisticated AI models such as Anthropic’s Mythos, there was already evidence of AI being utilized in both malicious and defensive capacities. Boutemeur predicts that AI will serve as a "force multiplier" across various threats, facilitating the creation of more convincing phishing attacks while also assisting defenders in identifying breaches and enhancing situational awareness.

Moreover, AI’s role in generating deceptive content—ranging from images to audio and text—has emerged as a common tool for threat actors. The report warned that such capabilities significantly expand the potential reach and impact of malicious campaigns.

The agency also noted Russia’s strategic use of information manipulation and interference, particularly during election periods in 2025, indicating a systematic approach to undermining political stability and electoral integrity. Meanwhile, China was characterized as employing similar tactics to intimidate dissenters and bolster its international image.

The overall implications of ENISA’s report are concerning, signaling a pressing need for enhanced cybersecurity measures, particularly in critical infrastructure domains, to mitigate the increasingly sophisticated and targeted threats posed by hacktivists and other malicious entities.

Source link

Latest articles

Is Your OT Team Prepared to Lead During a Cyberattack?

Critical Infrastructure...

OpenAI Cancels Release of GPT-6.1 Astra Due to Internal Safety Concerns

OpenAI has made the significant decision to cancel the anticipated release of GPT-6.1 Astra,...

RatHat’s Evolving C2 Panel Indicates a Shift Toward Malware-as-a-Service Model

In a recent analysis published by Cleafy on September 28, significant transformations in the...

Why AI Will Not Solve Your Cybersecurity Issues

The Evolving Landscape of Cybersecurity in the Age of AI James Gillies, the Head of...

More like this

Is Your OT Team Prepared to Lead During a Cyberattack?

Critical Infrastructure...

OpenAI Cancels Release of GPT-6.1 Astra Due to Internal Safety Concerns

OpenAI has made the significant decision to cancel the anticipated release of GPT-6.1 Astra,...

RatHat’s Evolving C2 Panel Indicates a Shift Toward Malware-as-a-Service Model

In a recent analysis published by Cleafy on September 28, significant transformations in the...