sect0r16 is a pro-Russian, state-aligned hacktivist threat actor associated with disruptive targeting of industrial environments in Europe. The group has been identified alongside Z-Pentest and the Infrastructure Destruction Squad in claims of access to industrial networks in Germany, Italy, and Poland. Reported targeting has focused on defense suppliers, heavy industry, and food processing facilities, indicating interest in operational technology and industrial control environments rather than purely symbolic website disruption. sect0r16 fits within the broader evolution of Russian-aligned hacktivist activity from denial-of-service operations toward reconnaissance and intrusion against OT- and IoT-connected infrastructure. High-confidence reporting supports characterization of this ecosystem as exploiting exposed remote-access services and weak or default credentials to gain access to industrial networks. The actor’s observed behavior is consistent with reconnaissance, initial access, and post-compromise activity against European industrial organizations, with likely geopolitical alignment to Russian interests rather than financially motivated crime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.