Hacktivist group
TwoNet
Origin: Russia Status: Active
Confidence: Confirmed
TwoNet is a recent entrant (2025) to the pro-Russia hacktivist space, coordinating via Telegram and focusing on DDoS and “hands-on” ICS/OT intrusion claims. In September–October 2025, TwoNet loudly claimed to have breached a Western water utility HMI, disabled alarms/logs, and tampered with PLCs—subsequent investigations by Forescout revealed the “plant” was a honeypot, exposing TwoNet’s TTPs and exaggerations. Despite the embarrassment, the episode shows growing intent by claim-driven actors to probe internet-facing OT. Confidence: high on the honeypot findings; medium on broader capability.
ATT&CK
MITRE ATT&CK
T1102Web Service
T1190Exploit Public-Facing Application
T1498Network Denial of Service
T1562Impair Defenses
T1585Establish Accounts