• News/
  • https://www.theregister.com/2025/10/10/russia_hacktivists_honeytrap/

Hacktivists deactivate after falling into researchers' trap

The Register
·
Connor Jones
·
Published Oct 10, 2025
·
Updated

Security researchers say they duped pro-Russia cybercriminals into targeting a fake critical infrastructure organization, which the crew later claimed - via their Telegram group - to be a real-world attack. Forescout said the short-lived TwoNet hacktivist group fell for one of its researchers' honeypots, designed to look like a water treatment plant to a remote attacker. Although the intrusion turned out to be an embarrassing own goal for TwoNet, which went on to brag about its endeavours on the messaging and social media app, Forescout's warning is very real. The attack was benign in this case. However, in a real-world scenario, it would have been anything but. Within 26 hours, the attackers had broken into what they thought was a critical infrastructure organization and proceeded to tamper with key systems, defacing authentication screens and disabling alarms and logs. TwoNet initially gained access to the fake water treatment facility by abusing default credentials on the honeypot's human-machine interface (HMI) before enumerating the system's databases and establishing persistence. It then went on to exploit a vulnerability (CVE-2021-26829, CVSS 5.4), allowing it to deface the HMI login screen, and later carry out its disruptive processes, such as disabling real-time updates. TwoNet first popped up in January, primarily focused on DDoS attacks using the MegaMedusa Machine malware, Intel471 said. Its Telegram channel was shut down in March, and the group was not seen again...

Read full article

Affected Software

1 affected component
ForeScout Honeypot
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses how researchers tricked pro-Russia hacktivists into attacking a fake critical infrastructure target.

2

What security implications are discussed in the article?

The article highlights the risks posed by hacktivism and the effectiveness of deception tactics in mitigating cyber threats.

3

What products or software are affected?

The Forescout Honeypot is mentioned as the tool used to lure the pro-Russia hacktivists.

4

Why did the hacktivists deactivate their activities?

The hacktivists claimed to have executed a real-world attack, but their activities were halted after being deceived by the researchers.

5

How did the researchers manage to trap the hacktivists?

Researchers created a fake critical infrastructure organization to lure pro-Russia hacktivists into targeting it.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203