🔴 [LATEST] THEGARUDAEYE TAKES DOWN PARAGUAY'S IMMIGRATION SERVER FOR 12 HOURS    ◆    🔴 [LATEST] THEGARUDAEYE DOWNS PARAGUAY FOREIGN MINISTRY OVER TRUMP’S BOARD OF PEACE    ◆    🔴 [LATEST] NONAME057(16) DDOS CAMPAIGN TARGETS GERMAN FERRY AND CITY SERVICES    ◆    🔴 [LATEST] CHAT CONTROL PROTEST: RIPPERSEC BREACH ITALIAN SCADA SYSTEM    ◆    🔴 [LATEST] ANGMAR MEDICAL BREACH & BEACON HACK EXPOSE 710GB DATA

[ SYSTEM_MENU ]

> ESTABLISH_CONNECTION

[ X_TWITTER ] [ TELEGRAM ] [ INSTAGRAM ] [ THREADS ] [ UPSCROLLED ]

CYBERASIA INTEL
Independent portal uncovering global cyber warfare operations, tracking APTs, and reporting zero-day vulnerabilities.

~/SCADA & IoTarticle

SCADA & IoT

NoName057(16) OpRomania CCTV Hack: Pro-Russian Hacktivists Target Retail IoT

> By Haider | Aug 04, 2026 | 4 min read

In a continued escalation of politically motivated cyberattacks under the banner of #OpRomania, the pro-Russian hacktivist group NoName057(16) claims to have gained unauthorized access to the video surveillance systems of a Romanian commercial enterprise. The NoName057(16) OpRomania campaign marks yet another chapter in the group’s sustained effort to destabilize NATO-aligned nations in Eastern Europe.

This incident serves as a stark reminder of the vulnerability of internet-connected IoT devices, particularly in the retail sector, where physical security infrastructure often lacks adequate cybersecurity hardening.

> TABLE_OF_CONTENTS [toggle]

Anatomy of the NoName057(16) OpRomania CCTV Hack

NoName057(16) OpRomania CCTV Hack - compromised retail surveillance camera footage

According to a Telegram post attributed to the group on 3 August 2026, the group claims to have accessed the real-time CCTV cameras of a Romanian pharmacy and natural products store operating under the brands Alevia and Podbal. The footage published by the group, which CyberAsia has reviewed and heavily obscured to protect the identities of those involved, displayed:

> THREAT_INTELLIGENCE_DATA

  • Retail shelves stocked with dietary supplements, essential oils, and cosmetics.
  • Active cash registers and point-of-sale (POS) systems in operation.
  • Store staff and unsuspecting customers going about their daily business.

The threat actors framed this breach as direct retaliation against Romania’s foreign policy stance, stating: “While the Romanian authorities continue to play at ‘European solidarity’ and help the Kyiv regime, we will continue to look where they would not like.”

Who is NoName057(16)?

NoName057(16) is a pro-Russian hacktivist collective that first emerged in March 2022, in March 2022. The group primarily conducts Distributed Denial of Service (DDoS) attacks and opportunistic intrusions against the government, financial, and critical infrastructure sectors of countries perceived to be hostile to Russian interests. Their targets have spanned Poland, Czechia, Germany, Latvia, Lithuania, Finland, and now Romania. The group openly coordinates operations through a public Telegram channel and has developed a crowdsourced DDoS tool called DDoSia, which allows volunteers to contribute their computing resources to amplify attacks. According to threat intelligence researchers at SentinelOne, NoName057(16) represents one of the most active hacktivist groups operating in the current geopolitical landscape.

Technical Reality Check: Opportunistic IoT, Not APT

How the Breach Likely Occurred

While the visual impact of compromised CCTV footage is highly invasive and carries strong psychological and propaganda value, security analysts assess that this type of intrusion rarely requires the sophisticated tooling of an Advanced Persistent Threat (APT) actor.

The NoName057(16) OpRomania CCTV access is highly consistent with opportunistic scanning for publicly exposed IoT cameras suffering from one or more of the following weaknesses:

  1. Default Credentials: Many commercial-grade DVR and IP camera systems ship with factory-default usernames and passwords (e.g., admin/admin, admin/12345) that are never changed by the installer or end user.
  2. Unpatched Firmware: Obsolete firmware with well-documented, publicly available CVEs (Common Vulnerabilities and Exposures) that allow unauthenticated remote code execution or credential bypass.
  3. Direct Internet Exposure: Surveillance systems connected directly to the public internet via port forwarding, with no VPN gateway, firewall rules, or geofencing applied.

Shodan and the Exposed Camera Problem

Tools like Shodan and Censys routinely index hundreds of thousands of internet-exposed camera systems globally, many of which remain accessible with default credentials. Romania is no exception, and it is assessed that the NoName057(16) OpRomania campaign likely involved automated scanning of Romanian IP ranges rather than a targeted, manual intrusion operation.

Mitigations for Retailers and Defenders

Retailers and small businesses must immediately audit their physical security infrastructure to prevent becoming collateral damage in geopolitical hacktivism campaigns like NoName057(16) OpRomania.

> THREAT_INTELLIGENCE_DATA

  • Change Default Passwords: Immediately enforce strong, unique passwords for all DVRs, NVRs, and IP cameras upon installation.
  • Isolate IoT Devices: Place surveillance systems on a dedicated, isolated VLAN completely separated from corporate networks, POS systems, and staff devices.
  • Disable Direct Internet Exposure: If remote viewing is necessary, restrict access via a secure VPN gateway rather than exposing camera interfaces directly to the public internet.
  • Enable Firmware Auto-Updates: Ensure camera firmware is kept up to date to patch known CVEs before they can be weaponized.

For a deeper understanding of how pro-Russian hacktivist groups operate and which sectors they are currently targeting, we recommend reviewing our comprehensive threat intelligence archives.

As #OpRomania continues, poorly secured peripheral devices are likely to remain the lowest-hanging fruit for groups like NoName057(16) seeking quick, high-visibility propaganda victories with minimal technical effort.

Mitigation & Prevention Strategies

Exploitation of vulnerabilities in critical infrastructure and edge devices requires immediate remediation to prevent catastrophic disruption:

  • Patch Management: Apply vendor-supplied security patches or firmware updates immediately. For legacy systems, deploy virtual patching via network firewalls.
  • Isolate OT Networks: SCADA and OT environments must be strictly isolated from corporate IT networks (the Purdue Model) to prevent spillover attacks.
  • Continuous Monitoring: Deploy Endpoint Detection and Response (EDR) solutions and monitor network traffic for indicators of compromise (IoCs) associated with known exploits.

Disclaimer: CyberAsia is an independent Cyber Threat Intelligence (CTI) research organization. The information provided in this report is derived from public intelligence gathering, dark web monitoring, and threat actor claims. It is published strictly for educational purposes, defensive analysis, and public awareness. CyberAsia does not endorse, verify, or facilitate any cyberattacks or illegal activities.

> INTELLIGENCE_NOTICE

The report above detailing NoName057(16) OpRomania CCTV Hack: Pro-Russian Hacktivists Target Retail IoT is part of the CyberAsia public archive. For organizations requiring real-time Indicators of Compromise (IoCs), YARA rules, and extended mitigation strategies for scada & iot threats, please refer to our Secure Drop or contact the research desk.

> share_intel.sh [ X ] [ TG ]

> ABOUT_AUTHOR: Haider

Lead Security Researcher & Malware Reverse Engineer specializing in deconstructing APT toolkits and validating underground breach claims.

> related_intel --suggest