Skip to main content
Mallory
🇷🇺 RU

Z-Pentest

Also known asz_pentest

Z-Pentest is a pro-Russian hacktivist group established in September 2024, formed from members of Cyber Army of Russia Reborn (CARR) and NoName057(16). Multiple sources in the content describe it as emerging from fragmentation within earlier pro-Russian groups; one advisory states CARR administrators and a NoName057(16) administrator spun off in late September 2024, using similar TTPs to CARR but without GRU involvement. The group is described as specializing in OT intrusion operations targeting globally dispersed critical infrastructure entities, while also conducting hack-and-leak and defacement activity to amplify pro-Russia messaging. The content consistently associates Z-Pentest with targeting critical infrastructure and industrial environments, including water, energy, food and agriculture, heavy industry, defense suppliers, and food processing facilities. Reported victim geographies include Denmark, Germany, Italy, Poland, the United States, and other NATO-aligned or Western organizations. Danish authorities attributed a 2024 destructive cyberattack on the Tureby Alkestrup Waterworks to Z-Pentest; the attack reportedly changed water pressure, burst a pipe, and temporarily disrupted water service. Other reporting says the group claimed compromises of U.S.-based industrial control systems, SCADA networks, and CCTV systems, and claimed access to industrial networks in Germany, Italy, and Poland. Its tradecraft is described as opportunistic and focused on weak authentication and exposed remote access rather than advanced malware. The content states Z-Pentest and related groups commonly exploit poorly secured internet-facing VNC connections to OT devices and HMI/SCADA environments, often scanning ports 5900-5910, using VPS infrastructure, brute forcing passwords, abusing default or weak credentials, password spraying, reused leaked credentials, and credential-stuffing-like automated login attempts. By 2025, the group was described as repeatedly accessing industrial interfaces through compromised authentication pathways. After access, actors are reported to manipulate HMI settings via legitimate interfaces, including changing credentials, parameters, device names, instrument settings, disabling alarms, restarting or shutting down devices, and causing temporary "loss of view" requiring manual intervention. The content notes that some attacks attributed to this ecosystem have caused physical damage in some cases. Z-Pentest is repeatedly grouped with CARR, NoName057(16), and Sector16 as part of a broader pro-Russia hacktivist ecosystem that evolved from DDoS activity into OT and ICS intrusion activity. Companion groups and related names directly mentioned in the content include Cyber Army of Russia Reborn (CARR), NoName057(16), Sector16, Dark Engine, and the Infrastructure Destruction Squad. The group largely avoids DDoS compared with some peers and instead emphasizes OT intrusion claims, propaganda, and media amplification. One source also notes claims that the group is based out of Serbia, but the content consistently characterizes it as pro-Russian and Russia-affiliated.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Military
  • Capital Goods
  • Food, Beverage & Tobacco

Where they target

Geographies tied to known operations.

  • 🇩🇪 Germany
  • 🇮🇹 Italy
  • 🇵🇱 Poland

Where they're from

Attributed origin per open-source reporting.

  • RU
MITRE ATT&CK

Tradecraft

13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

7 of 15 tactics16 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
2 techniques
T1591×2
Gather Victim Org Information
T1595
Active Scanning
T1595.002×2
Vulnerability Scanning
TA0042
Resource Development
1 technique
T1583
Acquire Infrastructure
T1583.003×2
Virtual Private Server
TA0001
Initial Access
1 technique
T1133
External Remote Services
TA0003
Persistence
1 technique
T1133
External Remote Services
TA0006
Credential Access
1 technique
T1110
Brute Force
T1110.003×3
Password Spraying
T1110.004
Credential Stuffing
TA0008
Lateral Movement
1 technique
T1021
Remote Services
T1021.005×3
VNC
TA0040
Impact
4 techniques
T1485
Data Destruction
T1491
Defacement
T1498×3
Network Denial of Service
T1499
Endpoint Denial of Service
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping13

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.