"Hacktivist" used to mean Anonymous in Guy Fawkes masks defacing a website. In 2025, it means a range from genuine script kiddies running publicly available tools against exposed HMIs, to state-intelligence-aligned groups operating under hacktivist cover to provide deniability for destructive operations. You have to assess which one you're dealing with because the response is entirely different.
Tier 1: Script kiddies and opportunists. Run Shodan queries for exposed HMIs, VNC, and Modbus. Use default credentials. Screenshot the HMI and post to Telegram for clout. Real but limited impact: they can flip settings on exposed interfaces but lack the knowledge to cause sustained or targeted damage. The risk is accidental disruption, not intentional destruction. Respond by closing the exposure.
Tier 2: Organized hacktivists with growing capability. Z-Pentest, Dark Engine, CyberArmyofRussia_Reborn, and successors. They run coordinated campaigns, use Cobalt Strike or Sliver C2, employ LOTL techniques, and publish intrusion walkthroughs and ICS screenshots for psychological impact. Some campaigns have demonstrated basic lateral movement from compromised jump hosts to domain controllers to PLC management interfaces. In 2025, Dragos observed hacktivists exploiting OPC UA endpoints, BACnet devices, and MQTT brokers alongside the usual HMI and Modbus targets. This tier is closing the gap between "script kiddie" and "operator."
Tier 3: State-aligned pseudo-hacktivists. State intelligence operations wearing a hacktivist mask. Solntsepek (front for ELECTRUM/Sandworm), BAUXITE/CyberAv3ngers (IRGC-CEC), and KillNet successors. They deploy wipers, target critical infrastructure, and coordinate with geopolitical events. The "hacktivist" label provides deniability. The capability and targeting are state-grade. If your IR reveals wiper malware or ICS-protocol-level manipulation, you are not dealing with hacktivists. You are dealing with a state actor using a Telegram channel as cover.
Pro-Russia aligned: CyberArmyofRussia_Reborn (proven ICS manipulation of US water HMIs), KillNet and successors (DDoS campaigns against NATO governments and infrastructure), Solntsepek (ELECTRUM/Sandworm front, deployed destructive malware against Ukrainian ISPs), NoName057(16) (DDoS-as-a-service via DDoSia tool, targets government websites in NATO countries). These groups coordinate via Telegram and time operations to geopolitical events.
Pro-Iran aligned: BAUXITE/CyberAv3ngers (IRGC-CEC, compromised Unitronics PLCs at US water facilities, deployed wipers against Israeli targets June 2025, IOControl malware campaign affecting 400+ OT devices globally). These are the most capable hacktivist-branded groups in the ICS space.
Other alignments: Anonymous Sudan (massive DDoS campaign against Microsoft, ChatGPT, and US government sites, members arrested late 2024), various pro-Palestinian and pro-Ukrainian groups of varying capability, and hacktivist-for-hire services that will DDoS or deface for anyone willing to pay.
- 1. Determine whether the claim is real Most hacktivist Telegram posts are false, exaggerated, or recycled screenshots from previous operations. Before responding: verify whether the claimed target is actually yours, check whether the screenshot matches your actual HMI/SCADA interface, and determine whether the claimed access is technically possible given your exposure. Do not mobilize a full IR based on a Telegram post alone.
- 2. Check for internet-exposed OT interfaces The #1 hacktivist entry point. Search for: HMIs, VNC sessions, Modbus endpoints, DNP3 interfaces, MQTT brokers, OPC UA servers, and BACnet devices accessible from the internet. Use Shodan/Censys to see what they can see. If it's exposed, assume it's been found. Close it immediately. Air-Gapped OT playbook · Shodan/Censys self-audit
- 3. Check for default or weak credentials on exposed devices Unitronics PLCs hit by CyberAv3ngers were using default credentials. Exposed HMIs with no authentication are trivially accessible. Audit: every internet-facing device for default passwords, every VNC session for password protection, and every web-based management interface for authentication requirements.
- 4. Assess whether this is a hacktivist or a state actor in disguise Key differentiators: hacktivists screenshot and leave. State actors persist and destroy. If you find: wiper malware, ICS-protocol-level commands from non-engineering sources, sustained persistence mechanisms, or evidence of long-term access preceding the public claim, escalate immediately. You are not dealing with opportunists. See Sandworm (Solntsepek front) and BAUXITE in Air-Gapped OT.
- 5. Check for DDoS impact on OT availability DDoS against IT web properties is cosmetic. DDoS against internet-facing OT services (remote monitoring, cloud-connected SCADA, cellular gateways) can cause operational impact. If OT services depend on internet connectivity: verify they're still reachable, check whether DDoS traffic is reaching OT-adjacent infrastructure, and ensure failover to local control is functioning. NET: C2 · Firewall/IDS DDoS counters
- 6. Check for data leaks and credential exposure Hacktivists increasingly publish stolen configuration files, network diagrams, employee lists, and credential databases. Check: have your configs or credentials appeared on Telegram channels or paste sites? Stolen network diagrams give any future attacker (hacktivist or nation-state) a roadmap to your environment. Dark web monitoring · Telegram OSINT · Paste site monitoring
- 7. Verify OT device state and process integrity If there's any evidence of actual OT access (not just claims): verify PLC logic state against known-good backelines, check HMI configurations for unauthorized parameter changes, review alarm configurations for suppression or modification, and verify that safety systems are functioning correctly. CyberArmyofRussia_Reborn achieved unauthorized parameter changes at US water facilities through exposed HMIs. Air-Gapped OT checklist items 3, 8, 9
- 8. Harden and close the exposure The fix for most hacktivist operations is removing the exposure they exploited. Put it behind a VPN. Add authentication. Segment it from the internet. Patch the default credentials. The hacktivist will move on to the next exposed target. The state actor behind the hacktivist mask will not, but closing the trivial access forces them to use more detectable methods.
Air-Gapped OT / ICS (the environment most frequently targeted by hacktivists)
Sandworm (operates through the Solntsepek hacktivist persona)
Edge Device Compromised (exposed OT interfaces are the hacktivist entry point)
Living-off-the-Land Activity (Tier 2+ hacktivists now use LOTL techniques)