🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

~/ › Threat Intelligence › article

Threat Intelligence

Inside OpDominó: Z-Pentest Alliance Escalates Spanish Cyberattacks

> By Haider | Aug 04, 2026 | 4 min read

⚠️ THREAT INTELLIGENCE ADVISORY:
The pro-Russian hacktivist collective Z-Pentest Alliance has formally announced OpDominó, a coordinated cyber campaign heavily targeting Spanish critical infrastructure and digital assets. The group claims to have successfully breached multiple vulnerable systems, operating with perceived impunity.

OpDominó

For defenders and cybersecurity agencies in Spain, this campaign represents a sustained escalation in hacktivist pressure, moving beyond isolated incidents into a branded, multi-target offensive designed to embarrass national security postures.

> TABLE_OF_CONTENTS [toggle]

Table of Contents

> TARGET_INFRASTRUCTURE

The Launch of OpDominó and OpSpain

The Z-Pentest Alliance, amplifying their reach through aligned channels like “Desinformador Ruso”, recently published a manifesto detailing the motivations behind OpDominó. Following their earlier compromise of an industrial poultry farm’s SCADA systems, the group has broadened its scope, claiming that Spain is one of the most vulnerable countries in terms of cybersecurity.

The actors boldly stated: “The level of protection is so low that it would be a sin not to take advantage of it and punish them for such negligence.” By leveraging hashtags such as #OpDominó and #OpSpain, the group aims to rally decentralized hacktivist affiliates to concentrate their efforts against Spanish targets.

Tactics: Claims of Systemic Vulnerabilities

While the group frequently employs Layer-7 DDoS attacks, their recent communications imply deeper network intrusions. Accompanying their announcement was a blurry video thumbnail depicting a compromised CCTV feed, timestamped late July 2026. This suggests that the attackers are actively scanning for, and exploiting, unpatched edge devices, exposed surveillance cameras, and misconfigured IoT controllers.

Observed threat patterns:

1. Opportunistic Exploitation: The group’s methodology heavily relies on scanning the public internet for low-hanging fruit-systems lacking Multi-Factor Authentication (MFA) or utilizing default credentials.

2. Silent Intrusions: The attackers claim a methodology of stealth and control, stating: “We simply entered, subdued them, did what we wanted, and left calmly, as if nothing had happened.” This rhetoric is designed to induce paranoia among defenders regarding undetected breaches.

Psychological Impact and Propaganda

A core component of OpDominó is psychological warfare. The group explicitly dismisses Western media and “moralism,” choosing instead to frame their attacks as a justifiable punishment for poor security practices. By blending real, opportunistic compromises with aggressive propaganda, the Z-Pentest Alliance seeks to degrade public trust in Spanish digital infrastructure and project an inflated image of their own capabilities.

Mitigation Recommendations

  1. Conduct immediate perimeter scans to identify and isolate any exposed RDP, SSH, SCADA, or CCTV interfaces accessible from the public internet.
  2. Enforce strict password policies and mandate MFA for all external-facing administrative portals.
  3. Review network segmentation protocols to ensure that a compromise of an edge device (like an IoT camera) cannot facilitate lateral movement into core operational or IT networks.
  4. Monitor threat intelligence feeds and dark web forums for specific indicators of compromise (IOCs) related to the Z-Pentest Alliance’s known infrastructure.

CyberAsia is actively tracking the developments of this campaign. For ongoing analysis of hacktivist operations, see CyberAsia threat intelligence updates.


> subscribe_to_intel

Join 5,000+ analysts. Get uncensored threat intelligence and breach alerts delivered directly to your inbox. Privacy Policy.

> establish_connection:
[X/Twitter]
[Telegram]

Mitigation & Prevention Strategies

Exploitation of vulnerabilities in critical infrastructure and edge devices requires immediate remediation to prevent catastrophic disruption:

  • Patch Management: Apply vendor-supplied security patches or firmware updates immediately. For legacy systems, deploy virtual patching via network firewalls.
  • Isolate OT Networks: SCADA and OT environments must be strictly isolated from corporate IT networks (the Purdue Model) to prevent spillover attacks.
  • Continuous Monitoring: Deploy Endpoint Detection and Response (EDR) solutions and monitor network traffic for indicators of compromise (IoCs) associated with known exploits.

Strategic Defense Matrix and Incident Hardening

Operational intelligence analysis of this Threat Intelligence campaign indicates that the threat actors frequently exploit configuration oversights, unpatched external-facing gateways, and weak credential management policies across targeted organizations. Enterprise security operations centers (SOC) and defensive engineering teams must deploy layered perimeter safeguards to detect and neutralize similar threat vectors before lateral movement occurs.

  • Continuous Asset and Perimeter Auditing: Maintain real-time inventory of all public-facing services, verifying SSL/TLS certificates and eliminating unauthenticated administrative interfaces following CISA Defensive Guidelines.
  • Behavioral Anomaly and Zero-Trust Telemetry: Enforce strict hardware-backed multi-factor authentication (MFA) across all remote access nodes and implement endpoint detection and response (EDR) telemetry mapped to the MITRE ATT&CK Framework.
  • Threat Intelligence Integration: Security teams are encouraged to correlate emerging indicators of compromise (IoCs) and evaluate network vulnerability profiles using our Cyber Risk Checker or submit anonymous confidential threat data via CyberAsia Secure Drop.

Disclaimer: The information presented in this threat intelligence report is for educational and cybersecurity research purposes only. CyberAsia reports on cyber incidents to help organizations understand and defend against emerging threats. We do not provide hacking instructions, host stolen data, or endorse illegal activities.

> INTELLIGENCE_NOTICE

The report above detailing Inside OpDominó: Z-Pentest Alliance Escalates Spanish Cyberattacks is part of the CyberAsia public archive. For organizations requiring Indicators of Compromise (IoCs), YARA signatures, and specialized malware containment guidelines for threat intelligence threats, please refer to our Secure Drop or contact the research desk.

> ABOUT_AUTHOR: Haider

Lead Cyber Threat Intelligence (CTI) Editor at CyberAsia, specializing in regional cybercrime syndicates, threat actor tracking, and dark web intelligence investigations.

> related_intel --suggest