Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      June 2, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      June 2, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      June 2, 2025

      How To Prevent WordPress SQL Injection Attacks

      June 2, 2025

      How Red Hat just quietly, radically transformed enterprise server Linux

      June 2, 2025

      OpenAI wants ChatGPT to be your ‘super assistant’ – what that means

      June 2, 2025

      The best Linux VPNs of 2025: Expert tested and reviewed

      June 2, 2025

      One of my favorite gaming PCs is 60% off right now

      June 2, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      `document.currentScript` is more useful than I thought.

      June 2, 2025
      Recent

      `document.currentScript` is more useful than I thought.

      June 2, 2025

      Adobe Sensei and GenAI in Practice for Enterprise CMS

      June 2, 2025

      Over The Air Updates for React Native Apps

      June 2, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      You can now open ChatGPT on Windows 11 with Win+C (if you change the Settings)

      June 2, 2025
      Recent

      You can now open ChatGPT on Windows 11 with Win+C (if you change the Settings)

      June 2, 2025

      Microsoft says Copilot can use location to change Outlook’s UI on Android

      June 2, 2025

      TempoMail — Command Line Temporary Email in Linux

      June 2, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»New Russian Threat Group Hacks Into U.S. Oil and Gas Facilities

    New Russian Threat Group Hacks Into U.S. Oil and Gas Facilities

    January 31, 2025

    New Russian threat group Sector 16 hacks U.S. energy

    Cyble dark web researchers have identified a new pro-Russian hacktivist group that’s been hacking into oil and gas facility control panels in the U.S.

    Cyble detailed two claims by the new “Sector 16” group that members hacked into control panels in energy facilities and tampered with system control settings. The new Russian threat group has been working with another pro-Russian group – Z-Pentest – which has been hacking into critical water and energy infrastructure since last year.

    Dramatic Videos Detail Control Panel Hacks

    Like Z-Pentest, Sector 16 has been posting screen recordings of its exploits to underground forums and channels, continuing a trend of Russian hacktivists posting videos of their members tampering with critical infrastructure control panels.

    Cyble speculated that that the videos may be “more to establish credibility or threaten than to inflict actual damage, although in one case Z-Pentest claimed to disrupt a U.S. oil well system.”

    In one incident, Sector 16 teamed with Z-Pentest to hack into a supervisory control and data acquisition (SCADA) system managing oil pumps and storage tanks in Texas. The groups posted a video showing the system interface, including real-time data on tank levels, pump pressures, casing pressures, and alarm management features.

    The logos of both groups were embedded into the video, suggesting a close alliance between the two groups, Cyble said (image below).

    Sector 16 and Z-Pentest control panel hack
    Sector 16 and Z-Pentest control panel hack (Cyble)

    Sector 16 later claimed sole responsibility for hacking into the control systems of a U.S. oil and gas production facility, and released a video “purportedly demonstrating their access to the facility’s operational data and systems,” Cyble said.

    The video showed “control interfaces associated with the monitoring and management of critical infrastructure,” the Cyble report said.

    The system controls included shutdown management, production monitoring, tank level readings, gas lift operations, and Lease Automatic Custody Transfer (LACT) data, “all critical components in the facility’s operations. Additionally, they were also able to access valve control interfaces, pressure monitoring, and flow measurement data, highlighting the potential extent of access.”

    U.S. cybersecurity officials have been concerned about critical infrastructure threats from adversaries like Russia and China, but critical sectors like energy, healthcare and transportation remain vulnerable to attack.

    Pro-Islamic Groups Launch DDoS Attacks on U.S. Government

    Cyble also examined claims of DDoS attacks on the U.S. government by pro-Islamic hacktivists like Mr. Hamza, which united with Z-Pentest and other pro-Russian groups in European attacks in December.

    Mr. Hamza teamed with Velvet Team in DDoS attacks on U.S. government and military platforms, Cyble said, noting that targeted systems included a U.S. Army development and communications network, an FBI portal for bank robbery information, and the United States Africa Command’s official platform.

    Such motivated threat groups – willing to work across ideological lines to advance their goals – poses substantial risks to critical infrastructure in dire need of stronger cybersecurity protections.

    The Cyble dark web report also detailed recent ransomware and data breach claims made by threat actors.

    Source: Read More

    Hostinger
    Facebook Twitter Reddit Email Copy Link
    Previous ArticleAccelerate digital pathology slide annotation workflows on AWS using H-optimus-0
    Next Article CISA and FDA Warn of Critical Backdoor in Contec CMS8000 Patient Monitors

    Related Posts

    Security

    Chrome Zero-Day Alert: CVE-2025-5419 Actively Exploited in the Wild

    June 2, 2025
    Security

    CISA Adds 5 Actively Exploited Vulnerabilities to KEV Catalog: ASUS Routers, Craft CMS, and ConnectWise Targeted

    June 2, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    RFP Templates and Guidebook

    News & Updates

    MuxServe: A Flexible and Efficient Spatial-Temporal Multiplexing System to Serve Multiple LLMs Concurrently

    Development

    AURORA-M: A 15B Parameter Multilingual Open-Source AI Model Trained in English, Finnish, Hindi, Japanese, Vietnamese, and Code

    Development

    MOZA built the best steering wheel for Euro Truck Simulator 2 you could ever hope to find and I’m obsessed

    Development
    Hostinger

    Highlights

    Laravel 11 CRUD Operation

    May 4, 2025

    In this tutorial, we will learn how to create a CRUD Operation using Laravel 11.…

    CVE-2022-44454 – Apache HTTP Server Cross-Site Request Forgery

    May 28, 2025

    Divine D.: un nuovo smartphone GNU/Linux con processore RK3588S

    May 17, 2025

    Dark Web Actor Advertises New Click Fraud Software for Online Marketing Deception

    June 13, 2024
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.