Z-Pentest is a pro-Russian hacktivist group established in September 2024 as an offshoot formed by members of Cyber Army of Russia Reborn (CARR) and NoName057(16). Public reporting and government advisories describe it as part of Russia’s broader state-aligned hacktivist ecosystem, though one advisory specifically states the group was formed without direct GRU involvement after fragmentation from earlier groups. The group is closely tied to CARR, shares overlapping personnel and tradecraft, and has been linked to Yuliya Pankratova as founder or leader and Denis Degtyarenko as a principal hacker. Z-Pentest specializes in operational technology and industrial control system intrusion operations against globally distributed critical infrastructure. Its targeting has focused on water and energy utilities and has also extended to agriculture, food processing, heavy industry, defense suppliers, and public-sector infrastructure in the United States and Europe. High-confidence reporting links the group to a destructive December 2024 intrusion against a Danish water utility and to broader targeting in Denmark, Germany, Italy, Poland, and the United States. The group is notable for moving beyond nuisance-level hacktivism into direct intrusion of exposed industrial environments. Its operations commonly involve scanning for internet-exposed remote access services, especially VNC-connected human-machine interfaces, exploiting weak, default, reused, or leaked credentials, brute-force and credential-stuffing-style authentication abuse, and then manipulating industrial interfaces through legitimate administrative access rather than advanced malware. Reported post-access actions include changing parameters, altering device names, disabling alarms, causing loss of view, restarting or shutting down devices, defacement, and hack-and-leak activity used to amplify pro-Russian messaging. Z-Pentest generally emphasizes OT intrusion, defacement, and propaganda over classic DDoS operations. The group’s activity is aligned with Moscow’s geopolitical interests and has been publicly associated with attacks on Western critical infrastructure supporting Ukraine. It has been sanctioned by the European Union and identified by multiple international agencies as an opportunistic but potentially harmful threat to critical infrastructure. Although its tradecraft is often assessed as lower sophistication than state APT operations, documented incidents show that exploitation of poorly secured OT environments can still produce real-world disruption and physical effects.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Russian hacking group known for targeting critical infrastructure.
Pro-Russian hacker group sanctioned by the EU for targeting critical infrastructure, including Denmark’s water supply.
Hacktivist group mentioned because its founder is among those tied to Cyber Army of Russia Reborn.
Pro-Russia hacktivist group tied to CARR that targets critical infrastructure in the energy and water sectors.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.