🔴 [LATEST] IRAN DEPLOYS 2 CYBER FRONTS: HANDALA TARGETS ISRAEL, CYBERAV3NGERS TARGETS US    ◆    🔴 [LATEST] PARAGUAY'S MITIC SERVER DOWN FOR 24 HOURS, THEGARUDAEYE IN SPOTLIGHT    ◆    🔴 [LATEST] THEHATMAN SELLS 3.6 MILLION AZURE EMPLOYEE RECORDS FROM FORTUNE 500 COMPANIES    ◆    🔴 [LATEST] 24 HOURS OF DIGITAL BLACKOUT: THEGARUDAEYE SILENCES PARAGUAY'S CULTURE MINISTRY PORTAL IN THE NAME OF PALESTINE    ◆    🔴 [LATEST] WHERE HAS DRAGONFORCE MALAYSIA GONE? THE SILENCE OF SOUTHEAST ASIA'S PREMIER HACKTIVISTS

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
Z-PENTEST ALLIANCE

/actor/z-pentest-alliance/  ·  11 intel reports

Year Established
2023
Attribution
Russia (Pro-Russian)
Motivation
Hacktivism, Sabotage, Pro-Russian
Modus Operandi (MO)
ICS/SCADA attacks, claiming access to industrial control systems, water and energy infrastructure targeting
Primary Aliases
Z Pentest, ZPentest

Z-Pentest Alliance is a pro-Russian threat actor that presents itself as a "penetration testing" collective but conducts politically motivated cyberattacks against Western and Ukrainian critical infrastructure, particularly targeting industrial control systems (ICS) and SCADA environments managing water utilities, energy infrastructure, and transportation systems.

The group gained significant attention from cybersecurity researchers and government agencies for publishing videos and screenshots claiming successful access to operational technology (OT) systems at water treatment facilities, oil and gas infrastructure, and power distribution networks across Europe and North America.

Z-Pentest Alliance operates a Telegram channel where they publish evidence of claimed intrusions, often presented as "penetration test results" to provide a veneer of legitimacy to what are effectively unauthorised attacks against critical national infrastructure. Their focus on ICS/SCADA environments reflects a strategic objective aligned with Russian military doctrine regarding hybrid warfare.

The group has claimed attacks against water treatment facilities in Romania, Italy, and other European nations that have provided support to Ukraine. US and European cybersecurity agencies have issued advisories specifically mentioning Z-Pentest Alliance alongside other pro-Russian ICS-targeting groups, recommending that critical infrastructure operators audit their internet-exposed OT systems and implement robust network segmentation to reduce exposure.

STATUS: ACTIVE CLASSIFICATION: HACKTIVIST COLLECTIVE LAST SEEN: Aug 2026

> LINKED_INTEL_REPORTS (11)

> cd ../articles