Sector16 is a pro-Russia hacktivist group that emerged in January 2025 through collaboration with Z-Pentest. It is part of a loosely connected Russia-aligned ecosystem that also includes Cyber Army of Russia Reborn (CARR), NoName057(16), and affiliated actors. Sector16 maintains a public Telegram presence and is known for publicity-driven operations, including hack-and-leak style claims and exaggerated impact reporting aligned with pro-Russian narratives. The group has been identified as an opportunistic threat to critical infrastructure, particularly operational technology and industrial control system environments. Reported targeting includes energy infrastructure, as well as broader critical infrastructure sectors such as water, food and agriculture. Sector16 has been associated with attacks against Western organizations, including claimed compromises of U.S. energy infrastructure, and has been named among actors targeting critical infrastructure globally. Sector16’s tradecraft is assessed as relatively low sophistication but operationally dangerous when exposed or weakly secured industrial remote access is available. Observed behaviors include reconnaissance and scanning for internet-facing remote access services, exploitation of weak authentication, password spraying and brute-force attempts, and opportunistic use of stolen or reused credentials. The group has been linked to abuse of exposed VNC access to reach human-machine interface and, in some cases, SCADA environments, where attackers may manipulate settings through legitimate graphical interfaces, disable alarms, alter parameters, rename devices, or cause temporary loss of view for operators. Publicity and propaganda amplification via social platforms are central to its operating model. Sector16 is frequently described as a newer and less experienced actor than some peers, but it has nonetheless demonstrated the ability to obtain access to industrial environments through weak authentication controls and credential abuse. Some reporting assesses that members may have received indirect Russian government support in exchange for conducting operations aligned with Russian strategic goals, but the group is primarily characterized as a pro-Russia hacktivist actor rather than a formally attributed state unit.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Russian opportunistic threat actor named in advisories as targeting global critical infrastructure.
Hacktivist companion group described as expanding from DDoS into operational technology intrusions affecting industrial HMIs in water, energy, and agriculture sectors.
Emerging pro-Russia hacktivist group using opportunistic stolen credentials and weak authentication controls to gain access, including attacks affecting critical infrastructure sectors.
Pro-Russia hacktivist group cited in a joint advisory as part of opportunistic critical-infrastructure targeting activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.