Z-Pentest is a pro-Russian hacktivist group associated with Cyber Army of Russia Reborn (CARR) and aligned with Russian geopolitical objectives. European and Danish authorities have linked the group to attacks on Western critical infrastructure, particularly water and energy utilities. Danish authorities attributed a December 2024 destructive intrusion at a Danish water utility to Z-Pentest; the intrusion manipulated water pressure, causing physical damage and temporary water outages. The group has also been associated with operational-technology and industrial-control-system targeting, including activity against exposed industrial interfaces. Reporting indicates that Z-Pentest abuses weak, default, reused, or compromised credentials to obtain access to OT environments, where access may enable manipulation of human-machine interfaces and industrial processes. The group combines disruptive operations with propaganda-oriented hacktivism and has ties to CARR. Yuliya Pankratova has been identified by EU sanctions authorities as Z-Pentest's leader, and Denis Degtyarenko as its chief hacker. Z-Pentest was sanctioned by the European Union for targeting critical infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reportedly conducted a destructive cyberattack against a Danish water utility in 2024.
Third-party pro-Russian hacktivist group to which BLACKNET-00 reportedly offered its tools.
Pro-Russian hacking group known for targeting critical infrastructure.
Pro-Russian hacker group sanctioned by the EU for targeting critical infrastructure, including Denmark’s water supply.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.