TwoNet hacktivist ecosystem churn through rebrands and shifting alliances
Threat Actor MetaFirst reported
Last updated
Happening score
H score
21
Summary
Hide ▲
Show ▼
TwoNet is part of a hacktivist ecosystem that now appears short-lived and highly fluid, with operators persisting through rebrands and shifting alliances, which makes disruption and attribution harder. The broader shift matters because the same ecosystem is also moving from simple DDoS toward OT/ICS targeting. That combination increases the chance that temporary channels hide durable operator continuity and evolving tradecraft.
Timeline
-
10.10.2025 11:15 2 articles · 7mo ago
TwoNet hacktivist ecosystem churn through rebrands and shifting alliances
Initial DisclosureTwoNet surfaced on Telegram in **January 2025** with **DDoS** activity, then opened a new channel in **September** as its messaging broadened toward **OT/ICS targeting**. That shift shows the group's public identity changing while the operator core remained active.
Show sources
- Pro-Russia Hacktivists “Claim” Attack on Water Utility Honeypot — www.infosecurity-magazine.com — 10.10.2025 11:15
- Pro-Russia Hacktivists “Claim” Attack on Water Utility Honeypot — www.infosecurity-magazine.com — 10.10.2025 11:15