Sector16 is a pro-Russia hacktivist group formed in January 2025 through collaboration with Z-Pentest. Public reporting describes it as a newer, relatively novice actor within a broader pro-Russia hacktivist ecosystem that also includes Cyber Army of Russia Reborn (CARR), NoName057(16), and Z-Pentest. Sector16 maintains a public Telegram presence where it shares statements, videos, and claims of compromising U.S. energy infrastructure, and its messaging aligns with pro-Russia narratives. Some reporting states Sector16 members may have received indirect Russian government support in exchange for conducting operations aligned with Russian strategic goals. Sector16 has been identified in joint U.S. and international advisories as targeting global critical infrastructure, particularly operational technology and industrial control system environments in the water and wastewater, food and agriculture, and energy sectors; some reporting also references aviation, manufacturing, transportation, telecommunications, and government services. The group is described as opportunistic rather than strategically selective, often prioritizing publicity and “hack-and-leak” style operations and frequently exaggerating impacts via Telegram videos and posts. Observed tradecraft attributed to Sector16 includes exploiting poorly secured remote access to industrial equipment, especially internet-facing VNC services, scanning exposed systems, using brute force, password spraying, default or weak credentials, reused or stolen credentials, and weak authentication controls to gain access to HMI and sometimes SCADA environments. Reporting states that, after access, actors may manipulate system parameters through the GUI, change credentials or device names, disable alarms, restart or shut down devices, and cause temporary “loss of view,” forcing operators into manual control. Sector16 has also been associated with broader hacktivist tactics including DDoS activity, defacement, hack-and-leak operations, and propaganda amplification via Telegram. Advisories and reporting characterize Sector16 as less sophisticated than state APT actors and as frequently misunderstanding the industrial systems it targets, but still capable of causing operational disruption and, in some cases across the broader campaign set, physical damage. Sector16 is also described as part of a trend in which pro-Russia hacktivists increasingly abuse valid credentials and authentication weaknesses rather than relying solely on exposed services.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Russian opportunistic threat actor named in advisories as targeting global critical infrastructure.
Emerging pro-Russia hacktivist group using opportunistic stolen credentials and weak authentication controls to gain access, including attacks affecting critical infrastructure sectors.
Pro-Russia hacktivist group cited in a joint advisory as part of opportunistic critical-infrastructure targeting activity.
Pro-Russia hacktivist group linked to DoS/DDoS attacks targeting UK local authorities and critical national infrastructure / critical service operators.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.