Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Z-Pentest Alliance

Z-Pentest Alliance

TLP:CLEAR
Active

Also known as: Z-Pentest, tracked as, Earth Bluecrow, DecisiveArchitect, Red Dev 18

Description

Z‑Pentest Alliance emerged as a coalition of pro‑Russian hacktivists with a dual focus on political disruption and monetary exploitation. The group claims responsibility for a series of high‑impact operations, most notably the seizure of Aquacorp’s water‑management SCADA system in January 2026, where it altered sanitization schedules and disabled alarm logs, as well as the manipulation of aviation authority websites across Italy and Israel. Analysts note a strong affinity with the Russian defense‑intelligence organ GRU and the NoName057 network, indicated by shared code libraries (e.g., BlackEnergy modules) and common communication channels such as Telegram groups. Operationally, Z‑Pentest leverages advanced phishing campaigns delivering malicious PDFs (“activity‑report-q4-2023-q1-2024.pdf”) that embed PowerShell scripts to establish footholds. Once inside, the group employs lateral movement via Windows administrative shares and PlugX backdoors, then escalates privileges by abusing credential dumping tools like MESSAGETAP to gain control over PLCs and OT devices. Their tactics are complemented by coordinated DDoS blots aimed at crippling online services during an active compromise. Given the broad range of target sectors – from manufacturing to maritime – the group appears opportunistic, prioritizing assets that provide both visibility for propaganda purposes and lucrative ransom targets. Their operations illustrate a sophisticated blend of sabotage and financial extortion executed through a networked alliance of hacktivist cells.

Goals & Targeting

Targeted Sectors

Financial services
Manufacturing
Energy
Defense
Critical infrastructure
Oil gas
Government
Maritime
Healthcare

Targeted Countries / Regions

RU
AU
US
IR
IL
IT
CN
UA
TR

AI Analysis

Grounded in web research
· 5 hours ago

Executive Summary

The Z‑Pentest Alliance is a pro‑Russian hacktivist collectivity that has demonstrated the ability to infiltrate and commandeer critical industrial control systems across multiple countries, including Italy, Israel, and Australia. In addition to sabotage, the group pursues financial gain through ransomware and extortion tactics, targeting finance, manufacturing, energy, defense, maritime and healthcare sectors. Their recent high‑profile attacks on water‑management SCADA networks underscore an elevated operational tempo and a clear focus on critical infrastructure.

Goals & Targeting

Z‑Pentest Alliance’s strategic objectives intertwine short‑term political influence with long‑term revenue extraction. By targeting high‑profile OT environments in Europe, the Middle East, Southern Africa, and the United States they aim to erode confidence in critical infrastructure providers while simultaneously generating ransom payments from operators in finance and energy sectors. The group selects victims that offer both symbolic value – such as Israeli government facilities or Italian maritime ports – and financial leverage, thereby amplifying their impact across geopolitical lines.

Enhanced Description

Key Capabilities

  • Advanced OT/ICS penetration exploiting SCADA & PLC command paths
  • Persistent remote takeover of industrial control parameters (alarm, schedule, flow)
  • Sophisticated phishing with PDF attachments carrying PowerShell payloads
  • Multi‑stage lateral movement using PlugX and Windows administrative shares
  • Credential dumping via MESSAGETAP and similar tools
  • Barrage DDoS campaigns leveraging fast‑flux DNS
  • Use of bulletproof hosting for C2 infrastructure
  • Ransomware delivery through Clop, RansomHub, and customized RATs

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Discovery
Lateral Movement
Collection
Exfiltration
Command and Control
Impact

ATT&CK Techniques

T1566.001
T1110.001
T1078
T1086
T1059.003
T1045
T1041
T1105
T1077
T1525
T1648

Software / Tooling

Stuxnet
BlackEnergy
PlugX
Shamoon
RansomHub
Clop
Apostle
Lucifer
MESSAGETAP
TurnedUp
SDBbot
Dark
OilRig
Get2
Ghost RAT

Campaigns & Victims

Z‑Pentest’s campaign footprint expands yearly, with a notable surge in 2025–2026 when the group executed OT intrusions in Australia and Italy. Their pattern features rapid infiltration followed by covert manipulation, often accompanied by high‑visibility sabotage (e.g., disabling aviation authority websites). The operational tempo is accelerated by coordination within an alliance that shares tools and intelligence, allowing simultaneous attacks across different geographies. While the group’s focus on critical infrastructure is consistent, their financial motive has shifted toward ransomware distribution in later incidents, indicating a dual‑pronged approach to influence and profit.

IOC Patterns

  • Phishing emails with PDF attachments (e.g., activity-report-q4-2023-q1-2024.pdf)
  • Domain‑based command and control using .gov.uk and Mr.Hamza domains
  • Fast‑flux DNS for malicious hosting
  • Bulletproof hosting services for C2 servers

Recommended Actions

  • Segment OT networks from IT environments and enforce strict access controls with multi‑factor authentication
  • Deploy industrial firewalls that inspect SCADA traffic for anomalous command patterns
  • Implement comprehensive patch management for legacy PLCs and OT components
  • Employ threat hunting tools to detect PowerShell-based lateral movement and credential dumping signatures
  • Configure DNS monitoring to flag fast‑flux domains and suspicious TXT records
  • Conduct regular tabletop exercises simulating OT sabotage scenarios
  • Encourage employees to report unsolicited PDF attachments and provide phishing training
  • Maintain up‑to‑date blacklists of known malicious domains and file hashes
  • Establish incident response playbooks specific to OT ransomware incidents

Suggested Tags

APT
Hacktivism
Pro‑Russian
Industrial Control Systems
OT/ICS Intrusion
Critical Infrastructure
DDoS
Ransomware
Financial Motive
Sabotage
Defense‑Intelligence Affiliation

Confidence Assessment

Confidence in the attribution of Z‑Pentest to a pro‑Russian hacktivist collective is moderate due to consistent claims and shared toolsets with known GRU-linked groups, yet concrete evidence linking to Russia’s official apparatus remains indirect. The lack of precise operational dates, limited publicly disclosed exploit details, and reliance on fragmented incident reports introduce uncertainty regarding the group’s full technical capabilities and exact victim profile. Future analysis would benefit from corroborated malware samples, deeper IOC cross‑validation, and clearer attribution pathways.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.group-ib.com — Cited by web research for: Vidar
  2. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl

Intel Summary

11

Techniques

40

Tools

0

Campaigns

3

IOCs

0

Observed Data

8

Tactics

Tags

Critical Infrastructure
DDoS
Hacktivism
pro-Russia
hacktivism
ICS/OT targeting
APT
Pro‑Russian
Industrial Control Systems
OT/ICS Intrusion
Ransomware
Financial Motive
Sabotage
Defense‑Intelligence Affiliation

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.