PLAYBOOKSNETHOSTATTRIBDETECT
← all playbooks
THREAT ACTOR · HACKTIVIST
Hacktivist Operations
From script kiddies running Shodan queries to state-aligned pseudo-hacktivists deploying wipers. The spectrum is wider than it's ever been. The line between "ideological vandalism" and "state-directed destruction with a Telegram channel" barely exists anymore.
opportunistic to state-aligned · DDoS to ICS manipulation · Telegram as C2 and amplification · claims exceed capability, but capability is rising
The spectrum

"Hacktivist" used to mean Anonymous in Guy Fawkes masks defacing a website. In 2025, it means a range from genuine script kiddies running publicly available tools against exposed HMIs, to state-intelligence-aligned groups operating under hacktivist cover to provide deniability for destructive operations. You have to assess which one you're dealing with because the response is entirely different.

Tier 1: Script kiddies and opportunists. Run Shodan queries for exposed HMIs, VNC, and Modbus. Use default credentials. Screenshot the HMI and post to Telegram for clout. Real but limited impact: they can flip settings on exposed interfaces but lack the knowledge to cause sustained or targeted damage. The risk is accidental disruption, not intentional destruction. Respond by closing the exposure.

Tier 2: Organized hacktivists with growing capability. Z-Pentest, Dark Engine, CyberArmyofRussia_Reborn, and successors. They run coordinated campaigns, use Cobalt Strike or Sliver C2, employ LOTL techniques, and publish intrusion walkthroughs and ICS screenshots for psychological impact. Some campaigns have demonstrated basic lateral movement from compromised jump hosts to domain controllers to PLC management interfaces. In 2025, Dragos observed hacktivists exploiting OPC UA endpoints, BACnet devices, and MQTT brokers alongside the usual HMI and Modbus targets. This tier is closing the gap between "script kiddie" and "operator."

Tier 3: State-aligned pseudo-hacktivists. State intelligence operations wearing a hacktivist mask. Solntsepek (front for ELECTRUM/Sandworm), BAUXITE/CyberAv3ngers (IRGC-CEC), and KillNet successors. They deploy wipers, target critical infrastructure, and coordinate with geopolitical events. The "hacktivist" label provides deniability. The capability and targeting are state-grade. If your IR reveals wiper malware or ICS-protocol-level manipulation, you are not dealing with hacktivists. You are dealing with a state actor using a Telegram channel as cover.

Claims exceed capability, but capability is rising. Most hacktivist Telegram claims are exaggerated, recycled, or fabricated. Screenshots may be from unrelated systems. DDoS is temporary. Website defacement is cosmetic. But Dragos documented real hacktivist operations in 2025 that achieved unauthorized parameter changes at US water facilities and leveraged C2 frameworks previously associated with advanced adversaries. The mistake is dismissing all hacktivist claims as noise. Some of them are real, and the ones that are real are getting more capable.
Active hacktivist groups and clusters (2025-2026)

Pro-Russia aligned: CyberArmyofRussia_Reborn (proven ICS manipulation of US water HMIs), KillNet and successors (DDoS campaigns against NATO governments and infrastructure), Solntsepek (ELECTRUM/Sandworm front, deployed destructive malware against Ukrainian ISPs), NoName057(16) (DDoS-as-a-service via DDoSia tool, targets government websites in NATO countries). These groups coordinate via Telegram and time operations to geopolitical events.

Pro-Iran aligned: BAUXITE/CyberAv3ngers (IRGC-CEC, compromised Unitronics PLCs at US water facilities, deployed wipers against Israeli targets June 2025, IOControl malware campaign affecting 400+ OT devices globally). These are the most capable hacktivist-branded groups in the ICS space.

Other alignments: Anonymous Sudan (massive DDoS campaign against Microsoft, ChatGPT, and US government sites, members arrested late 2024), various pro-Palestinian and pro-Ukrainian groups of varying capability, and hacktivist-for-hire services that will DDoS or deface for anyone willing to pay.

Hunt checklist: hacktivist activity detected
  1. 1. Determine whether the claim is real Most hacktivist Telegram posts are false, exaggerated, or recycled screenshots from previous operations. Before responding: verify whether the claimed target is actually yours, check whether the screenshot matches your actual HMI/SCADA interface, and determine whether the claimed access is technically possible given your exposure. Do not mobilize a full IR based on a Telegram post alone.
  2. 2. Check for internet-exposed OT interfaces The #1 hacktivist entry point. Search for: HMIs, VNC sessions, Modbus endpoints, DNP3 interfaces, MQTT brokers, OPC UA servers, and BACnet devices accessible from the internet. Use Shodan/Censys to see what they can see. If it's exposed, assume it's been found. Close it immediately. Air-Gapped OT playbook · Shodan/Censys self-audit
  3. 3. Check for default or weak credentials on exposed devices Unitronics PLCs hit by CyberAv3ngers were using default credentials. Exposed HMIs with no authentication are trivially accessible. Audit: every internet-facing device for default passwords, every VNC session for password protection, and every web-based management interface for authentication requirements.
  4. 4. Assess whether this is a hacktivist or a state actor in disguise Key differentiators: hacktivists screenshot and leave. State actors persist and destroy. If you find: wiper malware, ICS-protocol-level commands from non-engineering sources, sustained persistence mechanisms, or evidence of long-term access preceding the public claim, escalate immediately. You are not dealing with opportunists. See Sandworm (Solntsepek front) and BAUXITE in Air-Gapped OT.
  5. 5. Check for DDoS impact on OT availability DDoS against IT web properties is cosmetic. DDoS against internet-facing OT services (remote monitoring, cloud-connected SCADA, cellular gateways) can cause operational impact. If OT services depend on internet connectivity: verify they're still reachable, check whether DDoS traffic is reaching OT-adjacent infrastructure, and ensure failover to local control is functioning. NET: C2 · Firewall/IDS DDoS counters
  6. 6. Check for data leaks and credential exposure Hacktivists increasingly publish stolen configuration files, network diagrams, employee lists, and credential databases. Check: have your configs or credentials appeared on Telegram channels or paste sites? Stolen network diagrams give any future attacker (hacktivist or nation-state) a roadmap to your environment. Dark web monitoring · Telegram OSINT · Paste site monitoring
  7. 7. Verify OT device state and process integrity If there's any evidence of actual OT access (not just claims): verify PLC logic state against known-good backelines, check HMI configurations for unauthorized parameter changes, review alarm configurations for suppression or modification, and verify that safety systems are functioning correctly. CyberArmyofRussia_Reborn achieved unauthorized parameter changes at US water facilities through exposed HMIs. Air-Gapped OT checklist items 3, 8, 9
  8. 8. Harden and close the exposure The fix for most hacktivist operations is removing the exposure they exploited. Put it behind a VPN. Add authentication. Segment it from the internet. Patch the default credentials. The hacktivist will move on to the next exposed target. The state actor behind the hacktivist mask will not, but closing the trivial access forces them to use more detectable methods.
The convergence problem. In 2025, hacktivists adopted Cobalt Strike, Sliver C2, LOTL techniques, and open-source offensive tools previously associated with advanced adversaries. State actors adopted hacktivist personas for deniability. Ransomware affiliates adopted hacktivist messaging for pressure campaigns. The categories are blurring. The response should be driven by what you observe on your network (capability, persistence, intent), not by what the actor calls themselves on Telegram.
EU now sanctions the hacktivist ecosystem directly (July 2026). The European Union sanctioned nine individuals and four entities tied to Russian military intelligence AND affiliated hacktivist groups for attacks on European critical infrastructure. This extends the accountability framework beyond state actors to include the proxy hacktivist ecosystem Russia uses for plausible deniability. The sanctions validate the Tier 3 "state-aligned pseudo-hacktivist" model: governments now formally treat these groups as extensions of state intelligence, not independent ideological actors.
IoT as a surveillance vector (July 2026). Dutch intelligence revealed that at least one Russian agency is systematically compromising publicly exposed IP cameras across Europe to monitor NATO military logistics and Ukrainian personnel movements. Not ICS manipulation, not data theft: passive surveillance of physical-world operations through internet-connected cameras at sensitive locations. The same exposed-device attack surface that hacktivists probe for HMI screenshots, state actors use for persistent intelligence collection. Audit externally accessible camera infrastructure at defense-adjacent facilities, logistics hubs, and critical infrastructure sites.
Related playbooks

Air-Gapped OT / ICS (the environment most frequently targeted by hacktivists)
Sandworm (operates through the Solntsepek hacktivist persona)
Edge Device Compromised (exposed OT interfaces are the hacktivist entry point)
Living-off-the-Land Activity (Tier 2+ hacktivists now use LOTL techniques)