← Back

When Remote Access Becomes a National Security Risk: Z-Pentest and Pressure on Critical Infrastructure

The White House declared a national emergency to protect the U.S. bulk-power system from risks associated with foreign-made equipment, unauthorized access, and malicious remote action. The measure was not issued in response to Z-Pentest, but it comes as the pro-Russian actor intensifies its pressure narrative against the United States while continuing to publish alleged access to systems where a digital command can alter a physical process.

Leer en Español
Print Share

The White House Changes the Level of the Debate

On August 26, 2026, the White House declared a national emergency to protect the United States bulk-power system.

The decision was not presented as a response to a hacktivist campaign, nor does it mention Z-Pentest Alliance. Its immediate focus is U.S. dependence on foreign-manufactured electrical equipment and the possibility that certain components, suppliers, or associated services could introduce risks to national security.

But the language used in the executive order is difficult to separate from a discussion that has long moved beyond the supply chain alone.

The document identifies sabotage, subversion, unauthorized access, malicious remote action, and disruption of supply as relevant risks. Its scope does not stop at transformers or generators. It includes software, firmware, digital services, maintenance, and remote-access capabilities, and explicitly defines industrial control systems, RTUs, PLCs, intelligent electronic devices, distributed control systems, and safety instrumented systems as components of the bulk-power system.

The U.S. administration further states that a successful attack against this ecosystem could affect the economy, human health and safety, critical infrastructure, and national defense.

The declaration therefore introduces a political dimension that is particularly relevant to understanding the evolution of the OT threat: digital access to certain physical systems is no longer treated solely as a technical cybersecurity problem. It can become a national security issue.

Z-Pentest Has Been Operating Along That Boundary for Some Time

As part of its monitoring of actor-controlled sources, iQBlack has been following an extensive sequence of Z-Pentest publications involving industrial systems, automation, and OT/ICS environments.

The diversity of the targets is significant: water treatment and distribution, pumping stations, hydroelectric facilities, boilers, biogas systems, heating, irrigation, food production, climate control, agricultural infrastructure, and multiple industrial processes.

Not all of these environments qualify as critical infrastructure under strict legal definitions. Nor does every actor publication prove that the described manipulation actually occurred. But a substantial portion of them share a characteristic that matters more for this analysis: the exposed digital interface provides visibility into, or the ability to modify, variables that exist outside the computer.

Within the material reviewed by iQBlack, Z-Pentest has, for example, claimed access in the United States to a SCADA interface associated with an oil and gas facility. The material describes visibility into pressures and flow rates, fluid levels, oil, water, and gas production, valve control, tanks, alarms, and wells, together with an asserted ability to modify aspects of the process.

Another entry under #OpUSA describes access to a food-production system where recipes and parameters such as temperature, humidity, and time could be viewed, together with a manual operating mode. The actor portrayed that access as providing the ability to select recipes and alter parameters in real time.

In another U.S. case, Z-Pentest claimed to have reached a Pentair Aquatic Eco-Systems platform used to manage aquaculture facilities, with visibility into and modification of temperature, liquid level, and dissolved oxygen.

Getting Inside Is Not Yet the Consequence

This distinction is central.

In OT/ICS, obtaining access to a screen does not automatically mean controlling the entire process. Access to an HMI also does not demonstrate sufficient knowledge to produce a specific effect without triggering safeguards, alarms, or additional protection mechanisms.

For that reason, iQBlack keeps three categories separate even though they are frequently blurred together in actor propaganda:

  • declared access,
  • declared manipulation,
  • verifiable physical impact.

That caution does not make the access itself irrelevant. A pumping station, boiler, treatment plant, or industrial process exists to translate a logical command into a physical action. Opening a valve, changing pressure, altering temperature, modifying a dosage, or changing a sequence are not merely computer events.

This was one of the central conclusions of our recent analysis of NoName057(16). The 53 self-attributed OT/ICS accesses examined by iQBlack in that case showed a movement from digital disruption toward systems capable of influencing water, energy, temperature, pumping, chemical processes, agriculture, and manufacturing.

Z-Pentest introduces an important variation on the same equation. For NoName057(16), OT/ICS appears as a capability added to a repertoire historically associated with DDoS. For Z-Pentest, industrial intrusion carries a much more visible weight within its public identity.

U.S. authorities have reached a comparable assessment. A joint advisory issued by the FBI, CISA, NSA, DOE, EPA, and numerous partners identified Z-Pentest among pro-Russian groups that exploit poorly secured, Internet-exposed VNC connections to reach OT control devices within critical infrastructure.

There is therefore no need to imagine an exceptional offensive capability to understand the risk. An exceptional consequence can begin with an extraordinarily ordinary access surface.

The Actor Had Already Explained What It Considers Important

The interview conducted by iQBlack with Z-Pentest adds a particularly useful layer because it allows those publications to be compared with the group’s own description of its activity.

When asked whether OT/ICS represented the core of its operations, Z-Pentest said it was only one of several areas of work. But when asked about the difference between demonstration, intimidation, and actual disruption, the actor downplayed purely psychological effects and argued that real service disruption was considerably more important. That answer helps explain many of its publications.

Displaying an HMI can provide visibility. Showing that the HMI controls pressure, pumping, temperature, or combustion communicates something different: the possibility of moving from access toward operation.

The interview also explored what makes an industrial environment attractive: remote exposure, weak credentials, symbolic value, country, sector, or the potential to provoke a public reaction. Z-Pentest said that virtually all of those factors could play a role, while denying that publicity was the primary criterion. The actor also claimed that a significant portion of its activity is never published.

That last statement cannot be independently verified. But it helps explain the narrative the group is constructing, in which public activity is presented as a window rather than a complete inventory of capability.

Even more significant was its response regarding limits on operations against critical infrastructure. Z-Pentest told iQBlack that it had previously avoided certain civilian infrastructure but that this restriction had since been removed, explicitly mentioning energy and transportation systems among the targets it now considers available within its current framework of confrontation.

This is an actor statement, not evidence that it possesses the capability to execute every scenario it describes. As an indicator of declared intent, however, it is difficult to ignore.

The United States Is Not Only a Technical Target

The warning and pressure dimension became especially visible on August 23. In a publication addressed explicitly to the United States, Z-Pentest questioned whether the country could consider itself protected by geographic distance, its military bases, and its own perception of security. Minutes later, the actor claimed to have compromised a U.S. traffic-camera network and said it could observe the movement of vehicles and equipment. Both publications were tagged #OpUSA, #FuckEastwood, #FuckRedCircus, and #FreeVictoriaDubranova.

The significance of those publications does not depend on accepting the claimed scale of access at face value. Their value lies in the communication sequence: the United States is presented simultaneously as a target, a geopolitical adversary, and the recipient of a warning.

Three days later, on August 26, the White House declared a national emergency concerning the bulk-power system.

There is no basis for asserting that the two developments are causally connected, and making that connection would be incorrect. The executive order has its own background, regulatory objectives, and rationale related to foreign equipment and supply-chain security. Their temporal proximity does, however, expose two sides of the same strategic problem.

On one side is a state seeking to reduce the possibility of remote access, sabotage, and manipulation of sensitive electrical infrastructure. On the other are actors incorporating access to physical systems as an instrument of geopolitical pressure.

Sophistication Is Not the Only Variable

This discussion also connects with another area iQBlack has been monitoring. In our analysis of the TRK25 Advanced SCADA update, we examined a tool presented as an integrated platform for industrial reconnaissance, vulnerability identification, remote access, exploitation, collection, and disruption.

One of its most relevant characteristics was that the exploitable surface did not necessarily have to reside within the industrial protocol itself. Operating systems, remote-access services, authentication layers, gateways, and other components supporting the OT application could provide the path into it.

The U.S. advisory on pro-Russian hacktivism reinforces precisely this idea from another direction: exposed and inadequately secured VNC access can be enough to reach an industrial control device.

This changes the way capability should be measured. An actor does not need to develop Stuxnet to create an OT problem. It may only need to find an interface that should never have been exposed, obtain predictable credentials, traverse a misconfigured remote-access layer, or reach a system whose segmentation does not reflect its physical function.

The sophistication of the attacker matters. But the fragility of the target matters even more.

The U.S. Precedent Already Includes Physical Consequences

In December 2025, the U.S. Department of Justice stated that CARR had attacked public drinking-water systems in several states, damaging controls and causing the release of hundreds of thousands of gallons of water. It also attributed to the group an attack against a meat-processing facility in Los Angeles that allegedly resulted in product loss and an ammonia leak. The DOJ publicly described CARR as also known as Z-Pentest.

There is an attribution tension here that should be preserved. During its interview with iQBlack, Z-Pentest explicitly rejected the equivalence between Z-Pentest and CARR and stated that the latter no longer existed as an independent structure. The group did acknowledge operational coordination and political solidarity with NoName057(16).

Resolving that dispute is not necessary to understand the risk. The official U.S. position demonstrates that authorities already associate this ecosystem with physical activity against critical infrastructure.

The Problem Begins Before the Attack Exists

The August 26 presidential declaration focuses on the bulk-power system and on risks introduced through foreign equipment. But one of its most important concepts is broader: critical infrastructure cannot be evaluated solely through its primary physical component.

The White House explicitly includes software, firmware, digital services, maintenance, and remote access within the surface that must be considered when assessing risk. It is the same problem we have been observing from another direction:

  • An HMI may be the visible interface.
  • The risk may begin in the remote service that leads to it.
  • The PLC may control the process.
  • The exposure may reside in an architecture that made that process reachable.

Infrastructure can be physically robust while simultaneously depending on a digital chain in which a credential, gateway, or weak configuration ultimately connects the Internet to whatever moves water, energy, fuel, temperature, or pressure.

Security therefore cannot be added later as a decorative layer. It must be part of the raw material from which the service is designed, procured, connected, maintained, and operated.

Analytical Closing

Z-Pentest alone does not demonstrate the existence of a threat capable of causing a systemic disruption of the U.S. bulk-power system. Nor was the White House executive order issued in response to the actor’s publications. Conflating those two facts would weaken the analysis.

What can be observed is a convergence.

The United States is elevating the risks of remote access, sabotage, and manipulation of electrical systems into a formal national-security issue. U.S. agencies have been warning for months about pro-Russian collectives reaching OT devices through inadequately protected remote-access surfaces. And Z-Pentest, on the other side of that equation, continues publishing systems where it claims the ability to observe or alter variables associated with physical processes.

The corpus monitored by iQBlack shows that the problem does not end with electricity. Water, pumping, treatment, heating, oil and gas, agriculture, and industrial production are all part of the same observable surface.

The challenge, then, is not merely to ask whether a hacktivist actor possesses extraordinary capabilities. It is also to ask how many physically relevant processes remain reachable without requiring them.

When the answer involves water, energy, pressure, temperature, combustion, or distribution, the meaning of access changes. Because the attack may begin at an interface, but the consequence has no obligation to remain there.

Explore 3C-INT

Expand actor, campaign and operational-link tracking through a structured intelligence layer.

View module More articles

Get new publications

Subscribe to receive new articles and public updates from iQBlack without unnecessary noise.

iQBlack | Threat Intelligence & Threat Research . © Copyright 2026. All Rights Reserved