Skip to main content
Mallory
🇷🇺 RU2 malware familiesExploits CVEs in the wild

TwoNet

Also known astwonet

TwoNet is a pro-Russian / Russian-aligned hacktivist group that surfaced in January 2025. Reporting cited in the content describes it as recently formed, with roughly 40 members involved in hacking, software development, and open-source intelligence gathering. TwoNet was initially associated primarily with distributed denial-of-service (DDoS) activity, including attacks promoted on Telegram against government and infrastructure targets in Ukraine, Spain, and the U.K., and data-dump activity against Israeli defense and technology companies. Intel 471 identified TwoNet as one of two new pro-Kremlin hacktivist groups, and the content also notes claimed ties or partnerships with other pro-Russian actors, including CyberTroops and OverFlame. Across multiple reports in the content, TwoNet is described as evolving from DDoS activity into targeting operational technology and industrial control system environments. In September 2025, Forescout reported that TwoNet targeted an ICS/OT honeypot designed to mimic a water treatment facility, then falsely portrayed the incident on Telegram as a real critical-infrastructure compromise. According to the cited reporting, TwoNet gained access to the HMI using default credentials (admin/admin), ran SQL queries to enumerate the database schema, created a new account named "BARLATI," and exploited CVE-2021-26829 in OpenPLC ScadaBR to deface the HMI login page with a "Hacked by Barlati" message. Forescout also reported that the group attempted disruptive actions including defacement, process disruption, manipulation, disabling logs and alarms, removing PLCs from the HMI data source list, changing PLC setpoints, and disabling real-time updates. The content states Forescout assessed the actor focused on the HMI web application layer and did not attempt privilege escalation or exploitation of the underlying host. The content further states that Russian-aligned groups including TwoNet have evolved from DDoS activity into OT and IoT reconnaissance and disruptive industrial targeting, and that such actors exploit internet-facing VNC connections and HMI devices with default or weak credentials to access OT control systems. Several reports characterize TwoNet as financially motivated in addition to hacktivist branding. The group is described as advertising ransomware-as-a-service, hack-for-hire, initial access brokerage, and purported access to SCADA systems in Poland; one report notes an offer for a ransomware affiliate slot. Some cited reporting assessed parts of these offerings, including a purported crypto-locker, as likely scams. The content indicates TwoNet maintained a Telegram presence, used it to boast about attacks, and engaged in signal-boosting of other hacktivist groups. Handles most associated with the group include "BARLATI" and "DarkWarios." Multiple reports describe the group as short-lived: its Telegram activity ceased or went dark around late September 2025, though the content notes that hacktivist operators may persist through rebranding or shifting alliances.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Utilities

Where they target

Geographies tied to known operations.

  • 🇪🇸 Spain
  • 🇮🇹 Italy
  • 🇵🇱 Poland
  • 🇫🇷 France

Where they're from

Attributed origin per open-source reporting.

  • RU
MITRE ATT&CK

Tradecraft

2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

2 of 15 tactics2 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0006
Credential Access
1 technique
T1110
Brute Force
TA0008
Lateral Movement
1 technique
T1021
Remote Services
ACTIVITY FEED

Recent activity

18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

eclecticiq blogNews
Jun 11, 2026
The Escalating Cyber Risk Landscape in Regional Conflicts & Strategic Actions for 2026

Russia-aligned hacktivist group focused on OT/ICS environments, especially water-sector targets, with attempts to access and disrupt water treatment operations and broader industrial environments.

Read more
securityaffairsNews
Dec 1, 2025
U.S. CISA adds an OpenPLC ScadaBR flaw to its Known Exploited Vulnerabilities catalog

Pro-Russian hacktivist activity that evolved from DDoS into ICS/OT targeting and disruption/defacement. In the cited incident, they accessed an OpenPLC ScadaBR environment using default credentials, created a new user (“BARLATI”), exploited CVE-2021-26829 (XSS) to deface the HMI login page, and attempted to reduce visibility by disabling logs and alarms. The group is also described as offering RaaS, hack-for-hire, and initial access services, and claiming ties to other pro-Russian collectives.

Read more
the hacker newsNews
Nov 30, 2025
CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

Pro-Russian hacktivist group observed targeting industrial control/HMI systems (OpenPLC ScadaBR) using default credentials for initial access, then web-layer exploitation (CVE-2021-26829 XSS) to deface HMI pages and change settings (e.g., disable logs/alarms). The group reportedly started with Telegram-coordinated DDoS and expanded into industrial targeting, doxxing, and commercialized offerings (RaaS, hack-for-hire, initial access brokerage).

Read more
bleeping computerNews
Oct 29, 2025
Canada says hacktivists breached water and energy facilities

Described as a Russian hacktivist group observed attempting to manipulate industrial control system (ICS) settings; caught targeting a decoy industrial plant.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping2

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal2

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs1

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.