Zestix
Zestix, also known as Sentap, is a financially motivated threat actor described as an initial access broker (IAB) operating on dark web and Russian-language cybercrime forums. Reporting links Zestix/Sentap activity to at least 2021, with the persona emerging prominently in late 2024 or early 2025. The actor has been observed auctioning and selling stolen corporate data and access from approximately 50 organizations. The activity is consistently described as credential-driven rather than exploit-driven. Zestix used credentials harvested by infostealer malware including RedLine, Lumma, and Vidar, often from infected employee devices, and then accessed enterprise file-sharing and collaboration platforms such as ShareFile, ownCloud, and Nextcloud using valid accounts. Multiple sources state the intrusions did not rely on software vulnerabilities or zero-days; lack of multi-factor authentication, poor credential hygiene, long-lived passwords, and failure to invalidate sessions were key enablers. Some credentials had reportedly been present in infostealer logs for years before use. Zestix has targeted organizations across multiple sectors, including aviation, defense, healthcare, utilities, mass transit, telecommunications, legal, real estate, government, aerospace, engineering, robotics, and finance. Mentioned victims include Iberia, Pickett & Associates, Intecro Robotics, Maida Health, CRRC MA, K3G, NMCV Business LLC, CiberC, Sekisui House, Burris & Macomber, Pan-Pacific Mechanical, Bradley R. Tyer & Associates, The Providence Group, Australian NBN, and UrbanX.io. Reported stolen data includes health records, government contracts, engineering blueprints, defense project files, legal documents, financial archives, aircraft maintenance and safety documentation, utility maps, transit schematics, and other sensitive corporate files. The actor is described as exfiltrating victim data and selling both the data and access to compromised systems, sometimes with proof-of-access screenshots. Hudson Rock is the primary reporting source in the provided content. Several items in the content state the actor is believed to be an Iranian national, and some reporting notes claimed links to the FunkSec group, but those points are presented as reported attribution rather than established fact.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- aviation
- construction
- legal
- robotics
- critical-infrastructure
Tradecraft
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
3 malware families attributed to this actor across reporting.
Recent activity
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Initial access broker of Iranian origin, selling access to compromised corporate file-sharing portals, motivated by financial gain and linked to ransomware group FunkSec.
Zestix is known for stealing and selling corporate data obtained by breaching file-sharing platforms such as ShareFile, Nextcloud, and ownCloud, using credentials harvested by infostealer malware.
Zestix is a lone hacker, believed to be an Iranian national, who used infostealer malware to obtain credentials and access sensitive data from approximately 50 major companies worldwide. The stolen data is being auctioned on dark web forums.
Zestix is conducting credential theft and subsequent breaches of enterprise file-sharing and collaboration platforms by leveraging infostealer malware to harvest credentials, then using those credentials to access systems lacking multi-factor authentication.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.