Z-Pentest — Hacktivist Profile

Z-Pentest is a pro-Russian hacktivist group specialising in intrusions against operational technology and industrial control systems rather than DDoS. The December 2025 joint advisory AA25-343A, led by CISA with the FBI, NSA and international partners, states the group was "established in September 2024" and is "composed of members from CARR and NoName057(16)"; its authoring organizations assess that CARR channel administrators, dissatisfied with the level of support and funding provided by the GRU, created Z-Pentest together with an administrator from NoName057(16), "employing the same tactics, techniques, and procedures (TTPs) as CARR but separate from GRU involvement". The advisory describes these groups abusing scanning tools such as Nmap and OpenVAS to find internet-facing VNC services on default port 5900 and nearby ports 5901-5910, brute-forcing default, weak or absent passwords to reach HMI devices on live control networks, then altering parameters and setpoints from the HMI graphical interface while capturing screen recordings that are posted to social media to publicise and exaggerate the impact. Z-Pentest also runs hack-and-leak operations and defacements to draw attention to pro-Russia messaging, and largely avoids DDoS. Denmark's Defence Intelligence Service attributed a destructive 2024 attack on the Tureby Alkestrup Waterworks, in villages some 35 km south of Copenhagen near Koge, to Z-Pentest - the water pressure was changed and a pipe burst, leaving around 50 households without water for seven hours and roughly 450 more for an hour - and assesses that the group has connections to the Russian state.

Also tracked as

Z-Pentest Alliance, Z-Pentest Beograd, Z-Alliance

Vendor research

Countries linked to this actor

Read the full analysis on IntelFusions