Z-Pentest is a pro-Russian hacktivist group established in September 2024 from members of Cyber Army of Russia Reborn (CARR) and NoName057(16). Public reporting describes it as a Kremlin-aligned offshoot that emerged after fragmentation within earlier pro-Russian hacktivist networks, with some assessments stating it adopted many of CARR’s tactics while operating without direct GRU involvement. The group is closely tied to the broader Russian state-aligned hacktivist ecosystem and has been sanctioned by the European Union. Yuliya Pankratova has been identified as its founder or leader, and Denis Degtyarenko as a principal operator or chief hacker in sanctions reporting. Z-Pentest specializes in operational technology and industrial control system intrusion activity against globally distributed critical infrastructure. Its targeting has focused on water, energy, food and agriculture, and other industrial environments in the United States and Europe. Reported victim geography includes Denmark, the United States, Germany, Italy, and Poland, and the group has also been associated with targeting Western utilities more broadly. Danish authorities attributed a destructive 2024 cyberattack on a Danish water utility to Z-Pentest, and multiple advisories and law-enforcement actions have linked the group to attacks or claimed compromises involving industrial control systems, SCADA environments, and related operational networks. The group’s tradecraft is generally characterized as opportunistic and lower sophistication than traditional state APT operations, but still capable of causing real-world disruption where exposed or weakly protected OT assets are present. Reported techniques include scanning for exposed remote access services, exploiting poorly secured remote connections to industrial equipment, brute forcing or reusing weak, default, or leaked credentials, credential stuffing, and abusing valid authentication pathways to access human-machine interfaces and other industrial management systems. Once inside, operators have been reported manipulating interface settings, changing device names or parameters, disabling alarms, causing temporary loss of view, and conducting defacement or hack-and-leak activity to amplify propaganda value. Z-Pentest has also been linked to DDoS-adjacent ecosystems, but is more consistently described as emphasizing OT intrusion, defacement, and publicity over pure denial-of-service operations. The group uses Telegram and related online channels for coordination, messaging, and amplification, and has been described as blending propaganda-driven operations with direct OT intrusion. It is part of a wider cluster of pro-Russian actors including CARR, NoName057(16), Sector16, and related companion groups that have evolved from disruptive website attacks into more consequential activity against industrial environments. Its dominant motivation is geopolitical and aligned with Russian interests, particularly retaliation against states supporting Ukraine and broader anti-Western influence objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Russian hacker group sanctioned by the EU for targeting critical infrastructure, including Denmark’s water supply.
Hacktivist group mentioned because its founder is among those tied to Cyber Army of Russia Reborn.
Pro-Russia hacktivist group tied to CARR that targets critical infrastructure in the energy and water sectors.
A pro-Kremlin hacktivist group named among sanctioned entities for targeting Western water and energy utilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.