Z-Pentest is a pro-Russian hacktivist group focused on disruptive and intrusive operations against critical infrastructure, particularly operational technology and industrial control system environments in the water, energy, food and agriculture sectors. The group is widely described as aligned with Moscow’s geopolitical objectives and as part of the broader Russian state-aligned hacktivist ecosystem, though reporting also indicates it emerged as an offshoot of Cyber Army of Russia Reborn (CARR) and NoName057(16) after internal fragmentation in late 2024. Public reporting places its formation in September 2024 and identifies it as composed of members drawn from CARR and NoName057(16). Z-Pentest is notable for shifting beyond the denial-of-service activity common among pro-Russian hacktivist brands toward direct OT intrusion operations. Its tradecraft has been associated with opportunistic targeting of internet-exposed remote access services and industrial interfaces, especially VNC-accessible human-machine interfaces, followed by abuse of weak, default, reused, or leaked credentials. Reported behaviors include scanning for exposed services, brute forcing or stuffing credentials, accessing HMI and SCADA environments, changing device names or parameters, disabling alarms, restarting or shutting down devices, and causing temporary loss of view for operators. The group also conducts defacement and hack-and-leak style activity to amplify propaganda value and publicize claimed impact. The actor has been linked to attacks and claimed intrusions affecting organizations in the United States and Europe. High-confidence reporting ties Z-Pentest to targeting Western water and energy utilities and to a destructive December 2024 cyberattack against a Danish water utility that altered water pressure and caused service disruption. It has also been identified in advisories and reporting as claiming compromises involving industrial networks, SCADA environments, and related systems, and as participating in broader campaigns against critical infrastructure entities across NATO-aligned countries. Z-Pentest is closely associated with CARR, NoName057(16), and Sector16, and is often discussed alongside other pro-Russian hacktivist groups that blend propaganda, disruptive cyber activity, and opportunistic OT targeting. Some assessments describe it as using similar tactics to CARR while specializing more heavily in OT intrusion operations and relying less on DDoS than companion groups. Public sanctions actions by the European Union have identified the group as a pro-Kremlin threat actor, and reporting has named Yuliya Pankratova as its founder or leader and Denis Degtyarenko as a key operator. Overall, Z-Pentest represents the evolution of Russian-aligned hacktivism from symbolic disruption toward low-to-moderate sophistication but operationally meaningful intrusion activity against exposed industrial environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Russian hacker group sanctioned by the EU for targeting critical infrastructure, including Denmark’s water supply.
Hacktivist group mentioned because its founder is among those tied to Cyber Army of Russia Reborn.
Pro-Russia hacktivist group tied to CARR that targets critical infrastructure in the energy and water sectors.
A pro-Kremlin hacktivist group named among sanctioned entities for targeting Western water and energy utilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.