Z-Alliance is a Russian-aligned hacktivist threat group associated with pro-Russian and, in some reporting, pro-Iranian cyber activity. The group has been identified among state-aligned or ideologically aligned actors that evolved beyond low-impact distributed denial-of-service operations into more operationally significant activity involving reconnaissance of operational technology and internet-connected devices, including camera systems, and claimed disruptive actions against industrial targets. Reporting also places Z-Alliance among groups that have claimed compromises of surveillance cameras or have been observed targeting them, reflecting interest in cyber-physical intelligence collection and potentially disruptive access. Z-Alliance has been linked to activity targeting industrial environments through exploitation of exposed remote access services and human-machine interface systems protected by default or weak credentials. This tradecraft is consistent with attempts to gain access to OT control systems and conduct disruptive industrial targeting. The group has also publicly issued statements in Russian declaring support for Iran and has claimed attacks against Israeli infrastructure, including a pumping station, during periods of heightened regional conflict. These behaviors indicate an ideologically driven actor operating in alignment with broader geopolitical narratives rather than a purely criminal enterprise. The available reporting supports characterization of Z-Alliance as a Russian-aligned hacktivist actor with capabilities spanning reconnaissance, scanning for exposed systems, initial access through weakly secured internet-facing assets, and disruptive post-compromise activity against industrial or critical infrastructure environments. High-confidence evidence does not establish ransomware operations as a defining feature.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russia-aligned hacktivist group involved in OT/IoT reconnaissance and disruptive industrial targeting beyond traditional DDoS activity.
Listed as a threat group that has claimed to have compromised cameras or has been observed targeting cameras.
Hacktivist group publicly supporting Iran; claims targeting of Israeli water infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.