Z-Pentest is a pro-Russia hacktivist group focused on disruptive and propagandistic cyber operations against critical infrastructure, especially operational technology and industrial control system environments in the water, energy, food and agriculture sectors. The group is widely described as aligned with Kremlin geopolitical interests and as part of the broader Russia-aligned hacktivist ecosystem that includes Cyber Army of Russia Reborn (CARR), NoName057(16), and Sector16. Public reporting and government advisories characterize it as an OT-focused offshoot formed in September 2024 from members of CARR and NoName057(16), following fragmentation within that ecosystem. Z-Pentest has been linked to intrusions and claimed compromises affecting organizations in the United States and Europe, including Western water and energy utilities. Danish authorities attributed a destructive 2024 cyberattack on a water utility to Z-Pentest. The group has also been associated with targeting industrial interfaces, SCADA-adjacent environments, and other internet-exposed control systems, and has claimed access to industrial networks in multiple European countries. Its targeting has concentrated on critical infrastructure operators, public-sector entities, and industrial organizations in countries supporting Ukraine. The group’s tradecraft is generally assessed as opportunistic and lower sophistication than state APT operations, but still capable of causing real-world disruption when victim environments are weakly secured. Reported tactics include scanning for exposed remote access services, especially VNC-connected human-machine interfaces; brute forcing or reusing weak, default, or leaked credentials; password spraying and credential stuffing; abusing compromised authentication pathways; manipulating HMI settings and device parameters; changing credentials or system names; disabling alarms; causing temporary loss of view; defacement; and hack-and-leak activity used to amplify psychological and propaganda effects. Like related pro-Russian hacktivist actors, Z-Pentest relies heavily on Telegram and social media for coordination, recruitment, branding, and publication of claimed impacts, which may at times exaggerate operational effects. Z-Pentest is notable for representing a shift within the pro-Russian hacktivist scene from primarily distributed denial-of-service activity toward direct OT intrusion and industrial disruption. Some assessments state it largely avoids classic DDoS operations in favor of OT-focused compromises, defacements, and leak operations intended to generate media attention and support pro-Russian narratives. Public advisories have identified the group as an opportunistic but meaningful threat to globally dispersed critical infrastructure, particularly where remote industrial access is exposed and identity controls are weak. Known aliases and closely associated groups include z_pentest, Cyber Army of Russia Reborn (CARR), and NoName057(16). Z-Pentest is best understood as a Russia-aligned hacktivist collective operating in the overlap between propaganda, disruptive cyber activity, and deniable pressure against Western critical infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Russia hacktivist group tied to CARR that targets critical infrastructure in the energy and water sectors.
A pro-Kremlin hacktivist group named among sanctioned entities for targeting Western water and energy utilities.
Groupe hacktiviste pro-russe cité comme l’un des groupes auxquels le suspect arrêté en Espagne serait affilié.
Pro-Russian hacktivist group allegedly linked by Spanish police to the suspect. A person claiming to represent the group denied knowing the detainee and suggested police may have made a mistake.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.