Sector 16
Sector 16 is a pro-Russia hacktivist group. The provided content identifies it as one of several companion or affiliated groups alongside Z-Pentest, Cyber Army of Russia Reborn (CARR), Dark Engine, and NoName057(16). The group is described as having moved beyond distributed denial-of-service activity into operational technology targeting, including documented intrusions affecting industrial HMIs in the water, energy, and agriculture sectors. The content states that since the start of 2025, Sector 16 (also referred to as S16) has been the most prolific Russia-nexus hacktivist group targeting the energy sector, and references a joint Sector 16 and Z-Pentest attack involving SCADA in Texas in which the actors claimed brute-force access to a server. The content also states that Sector 16 and other pro-Russia hacktivist groups have exploited the widespread exposure of accessible VNC devices to attack critical infrastructure entities, with impacts ranging up to physical damage. Known alias directly mentioned in the content: S16.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Utilities
- Energy
- Materials
Where they target
Geographies tied to known operations.
- 🇫🇷 France
Tradecraft
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist companion group described as expanding from DDoS into operational technology intrusions affecting industrial HMIs in water, energy, and agriculture sectors.
Sector 16 is a pro-Russia hacktivist group targeting critical infrastructure using opportunistic attacks.
Sector 16 is a pro-Russia hacktivist group targeting critical infrastructure using opportunistic attacks.
Pro-Russia hacktivist group (claims Serbia) alleging multiple energy-sector OT/SCADA attacks globally; claims include brute-force-enabled access and cyber-physical impacts; unverified.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.