Z-Pentest Alliance is a pro-Russian hacktivist coalition focused on operational technology and industrial control system targeting, particularly ICS/SCADA environments. Active since at least October 2023, the alliance has been associated with campaigns intended to weaken industrial and control systems in Western and Gulf-aligned countries in support of Russian geopolitical objectives. It has been linked to increased OT targeting in Italy since late 2024 and has also been publicly associated with claimed access to Israeli water infrastructure during the 2026 Iran-Israel crisis. NoName057(16) has been identified as part of this alliance. The group is notable for blending disruptive hacktivist messaging with claimed OT intrusion activity. Reported behavior includes publishing screenshots purporting to show human-machine interface access and real-time visibility into industrial processes, especially water-sector systems. Its operations and public claims indicate a focus on critical infrastructure reconnaissance and post-compromise access claims in addition to broader alignment with the pro-Russian hacktivist ecosystem. During the Milano Cortina 2026 Winter Games period, Z-Pentest Alliance was also named among actors publicly claiming attacks against Italian infrastructure. High-confidence reporting supports characterization of Z-Pentest Alliance as a Russia-aligned coalition with an emphasis on ICS/SCADA targeting and politically motivated operations against Western and partner-country infrastructure. Many specific intrusion claims, especially wartime OT access assertions, remain unverified, so the most defensible assessment is that the actor combines propaganda, intimidation, and claimed critical-infrastructure access with a demonstrated intent to target OT environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Russian collective focused on industrial control system and SCADA targeting, particularly against Western and Gulf-aligned infrastructure.
Threat actor publicly claiming DDoS-related attacks against Italian targets during the Winter Games period.
Pro-Russian-aligned group that published OT/ICS access claims against Israeli water infrastructure during the 2026 escalation.
Actor claiming real-time access to Israeli water infrastructure HMI and control functions, indicative of OT/ICS targeting.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.