← Back

Z-Pentest Alliance and ambiguity as structure: an intelligence reading of an exclusive interview

Z-Pentest projects itself as a politicized structure that manages visibility, reserves capabilities, and uses ambiguity to operate between hacktivism, propaganda, transnational cooperation, and gray zones of contact, support, validation, and belonging.

Leer en Español
Print Share

Executive summary

iQBlack conducted an exclusive interview with Z-Pentest Alliance, a pro-Russian hacktivist actor observed in recent years around operations, narratives, and publications associated with OT/ICS systems, critical infrastructure, access exposure, coordination with NoName057(16), and activity within the ecosystem that emerged around Cyber Army of Russia Reborn (a.k.a. CARR).

Several of the responses provided by Z-Pentest Alliance are consistent with elements already observed in public sources, such as its relationship with NoName057(16), its pro-Russian orientation, the place of OT/ICS in its external image, and its tension with Western authorities. But the most relevant layer appears somewhere less obvious: how the actor attempts to organize its identity, what type of ambiguity it preserves, what it avoids specifying, how it manages public visibility, and what role it assigns to internal discipline over individual recognition.

In the interview, it does not project a logic centered on personal prominence. Nor does it present itself as a loose coalition of teams or as an informal community of allied groups. It insists on defining itself as a unified structure, with strategic coordination inside a common system and shared interests. That formulation shifts the meaning of “Alliance”: according to its own narrative, it would not be a federation of actors negotiating with one another, but an entity that projects coherence, discipline, and common direction.

Another central element is its rejection of being boxed into OT/ICS, even though much of its public visibility has been built around access, demonstrations, and narratives linked to industrial infrastructure. Z-Pentest presents OT/ICS as one of several work vectors and not as the total boundary of its activity. It also acknowledges the use of OSINT, although it places it as a significantly smaller part of its activity. That precision does not prove broader capabilities, but it does show the intention to preserve the reputational value of OT/ICS without being reduced to the category of “SCADA group”.

The interview also reveals a useful tension for analysis. Z-Pentest maintains that publicity is not a priority and that many of its operations become known much later or are never made public. However, it accepts interviews, publishes visual proof, and participates in visible alliances. That apparent contradiction suggests that the actor does not reject exposure, but manages it.

The way Z-Pentest describes evidence is also revealing. For a broad audience, the actor prioritizes visually understandable results: panels, screenshots, videos, or scenes that allow viewers to understand that “something happened” without requiring deep technical knowledge. For more robust analytical validation, by contrast, it assigns greater value to the precise identification of the target reached, a detailed description of the damage caused, and the reliability of information about results. That separation between public proof and private validation helps explain how the actor controls what it shows, what it reserves, and what it demands from third parties to assess its activity.

The central axis of this analysis is that Z-Pentest uses ambiguity as structure. Not as an accidental weakness, but as a way to operate between publication and reserve, alliance and autonomy, visual proof and complete evidence, cooperation and belonging, technical activity and political message.

 

Beyond the public frame

Most public profiles of Z-Pentest tend to place the actor within three frames:

  • pro-Russian hacktivism,
  • activity linked to OT/ICS,
  • relationship with NoName057(16) or CARR.

Those frames are useful, but they can become insufficient if they merely repeat visible associations.

Public sources have described Z-Pentest within the ecosystem of pro-Russian groups that capitalize on exposures in OT environments, especially through poorly protected remote access, visible interfaces, or proof videos. It has also been mentioned in contexts involving pressure against critical infrastructure, intimidation operations, and coordination with other groups.

That perspective remains valid as a starting point because Z-Pentest appears publicly associated with OT/ICS, critical infrastructure, visual demonstrations, open dissemination channels, and relationships within the NoName057(16) ecosystem. But the interview allows that characterization to be refined without replacing it entirely.

In that sense, reading Z-Pentest as a simple sum of occasionally coordinated teams appears to be a convenient but insufficient interpretation. First, because the actor seeks to separate its identity from CARR as a living structure. Second, because it confirms cooperation with NoName057(16) without presenting itself as subordinate. Third, because it projects an image of operational discipline where public recognition sits below collective outcome.

So the question is not only whether it cooperates with other actors. The more important question is what function that cooperation serves for Z-Pentest’s real objective: adding technical capabilities, expanding geographic coverage, incorporating local knowledge, multiplying narrative legitimacy, or sustaining a flexible structure able to deny, modulate, or shift responsibilities depending on the context.

 

Alliance not as federation, but as discipline

Z-Pentest’s first response is perhaps one of the most useful in the entire interview. The actor rejects being defined as a coalition of separate teams and describes itself as a unified structure. According to its own explanation, coordination exists, but it takes place within a common system, not among independent entities with different priorities.


“It is not a coalition of separate teams. It is more accurate to represent us as a single unified structure, rather than a collection of independent teams that need to constantly coordinate with one another”


Analytically, this formulation has value because it attempts to resolve a public ambiguity. From the outside, “Alliance” may suggest a flexible network or a federation of groups with different levels of autonomy. Z-Pentest prefers to describe itself as a structure with shared strategy, common decision-making, and functional unity. As if it sought to move away from the model of a “chaotic ecosystem” and closer to an image of ordered structure.

Read between the lines, Z-Pentest is not only explaining what it is, but also suggesting what it does not want to appear to be: a sum of volunteers, an appendage of CARR, a structure dependent on constant external coordination, or an identity subordinated to the shadow of other organizations.

Relational map of Z-Pentest Alliance within the pro-Russian hacktivist ecosystem observed by iQBlack. The visualization shows the actor as an articulating node of links, cooperation, affinities, and public proximities, without implying hierarchical command, operational control, or formal membership of all connected actors.

 

OT/ICS as showcase, not boundary

Z-Pentest has been publicly associated with operations and narratives linked to OT/ICS. That frame is understandable because much of its external visibility relies on publications related to industrial infrastructure, visual access, panels, cameras, interfaces, and exposed systems. Even so, in the interview the actor rejects the idea that OT/ICS is the total core of its identity and states that it conducts many operations outside that field.

It also mentions the use of OSINT, although it places it as a significantly smaller component. That response is useful because it suggests that Z-Pentest does not want to be trapped in the category of “SCADA group”. It wants to preserve the reputational value of that field while projecting a broader repertoire.

This point connects with iQBlack’s previous work, where Z-Pentest appears linked to industrial exposure, formalized alliances, and movements within a broader ecosystem of hacktivist cooperation. In that trajectory, OT/ICS functions as an impact showcase because it allows the actor to display visual access, operational sensitivity, and pressure capability. But the interview suggests that the actor considers that showcase only one part of its reach.

One of the most useful hypotheses is not that Z-Pentest abandoned its original Serbian focus, but that internationalization forced it to transform it. An actor that intends to operate against different countries needs more than technical operators. It needs language, political reading, knowledge of institutions, understanding of local narratives, selection of symbols, and the ability to anticipate which exposure will generate real impact.

The interview does not formally confirm all those layers, but it does show that Z-Pentest perceives itself as something more complex than a group dedicated to finding exposed SCADA panels.

 

Visibility as a managed resource

One of the most interesting statements is that most of its attacks would be discovered much later or would never become public. Z-Pentest also maintains that publicity is not a main concern, although it acknowledges that disclosure is necessary in certain cases.


“Most of our attacks are discovered only a year later or never become public, so attention and media coverage in themselves are not something we particularly care about”


Z-Pentest appears to distinguish between operating and communicating. Public communication would not be, according to its account, the center of gravity of the activity. However, the actor does publish videos, screenshots, panels, and interfaces when it considers the material useful for a purpose. That combination allows us to infer that visibility is selective: it is not rejected, it is managed.

Z-Pentest maintains that an ordinary user usually cannot understand the principle or type of attack if they are simply shown console content, even when accompanied by a textual description of what is happening. That type of material requires a certain level of technical training to interpret correctly. For that reason, according to the actor, its publications emphasize visually understandable results, capable of conveying what happened to a broader audience without forcing it to go deeper into technical details.

This response is central to understanding its public communication. Z-Pentest does not only publish “proof”; it publishes visual translations of impact. It turns a technical action into an interpretable scene. Panels, interfaces, screenshots, and videos allow a non-specialized audience to understand that “something happened”, even when that audience cannot evaluate the method, scope, or consequence by itself.

This reading helps avoid a common assumption. Not all hacktivist actors seek fame in the same way. Some depend on public noise to exist. Z-Pentest, by contrast, projects a more disciplined image where individual recognition, public authorship, and media exposure are secondary to result, coordination, and shared objective.

That posture may be partially real or partially performative. Even as performance, it retains analytical value: an actor that says it does not need fame builds a different form of authority, one based on the idea of reserved capability rather than permanent spectacle.

 

Evidence, damage, and analytical validation

Z-Pentest describes its visual publications as sufficient material for third parties to understand part of what happened. At the same time, when asked what type of non-public evidence it would consider meaningful for independent analytical validation, the actor does not prioritize the aesthetics of the publication or methodological detail. It prioritizes data about the target reached, precise identification, and a detailed description of the damage caused.

For Z-Pentest, relevant evidence does not seem to revolve around revealing how an operation was carried out, but around documenting what was reached and what damage it produced. The more complete and reliable the information about results, the greater its value would be, according to its own reading, for subsequent analysis, effectiveness assessment, and documentation of what occurred.

The tension is evident. What the actor publishes for a broad audience tends to be visual, synthetic, and understandable. What it considers useful for analytical validation requires another level: identification, context, damage, result. Between both planes there is a zone of ambiguity where Z-Pentest controls what it shows, what it reserves, and what it demands from others in order to validate.

That asymmetry appears to have a strategically beneficial meaning for the actor. If the publication is credible, it obtains impact. If it is incomplete, it can maintain that it did not reveal everything. If it is questioned, it can blame analysts for looking only at the surface. Z-Pentest, in fact, criticizes those who reduce it to the use of public tools or poorly protected remote exposure.

Ambiguity, then, is not an accidental problem. It is part of the communication design. It allows the actor to project capability without necessarily exposing methodology, real scope, or limits. That logic also reminds us that intelligence and technical verification do not always operate under the same incentives or with the same exposure thresholds.

 

Internationalization and the loss of an exclusively Serbian focus

Z-Pentest acknowledges that its initial base was formed around a Serbian core, but says that people from different countries later joined and that its current composition can be described as international.

That expansion may be technical, but also contextual. In operations against European or Latin American countries, or against specific infrastructure, local knowledge can be as important as the tool used. Language, symbols, institutions, political tensions, suppliers, exposure habits, social calendars, and media sensitivity can define what material becomes useful, which target generates greater pressure, and which narrative has more chances of circulating.

iQBlack assesses with reasonable confidence that Z-Pentest’s declared internationalization is not only demographic. It also functions as an indirect explanation for the expansion of its coverage: more countries, more contexts, and greater ability to adapt messages and targets to different environments.

 

Rhetorical escalation and declared removal of limits

Another of the most revealing parts of the interview appears when Z-Pentest responds about internal limits regarding critical infrastructure. The actor states that self-imposed restrictions previously existed regarding civilian infrastructure, but argues that those restrictions were removed by actions attributed to the West against Russia. It then formulates an escalation posture against military installations, energy, transportation, and decision-making centers.


“Previously, we did indeed have an internal restriction: we consciously avoided targeting our adversary’s civilian infrastructure. But the West, through its own actions, removed that restriction”


This statement does not confirm physical-damage capability against a specific target. But it does modify risk analysis by reducing the value of assuming voluntary self-restraint.

When an actor publicly declares that it no longer recognizes limits, that declaration can serve multiple functions. It can be propaganda, deterrence, psychological pressure, or a signal to allies. But it also establishes a narrative frame that could be recycled to justify future actions.

The most important point is not whether Z-Pentest can execute everything it suggests. The point is that it abandons, at least discursively, a boundary that many actors preserve to protect legitimacy: the separation between military, state, industrial, and civilian targets.

 

Sanctions, ego, and reputation without spectacle

Z-Pentest minimizes the impact of sanctions and official mentions. The expected response would have been to turn them into a trophy. However, the overall tone of the interview does not show the performative ego typical of some hacktivist organizations that need to present themselves as celebrities.

The actor is defiant, but not especially anxious for individual recognition. It repeats ideas of structure, cooperation, common objective, and result. In a joint campaign, it states that it does not matter who receives more attention, but rather the overall result. Its self-presentation is more institutionalized and based on team, system, structure, coordination, principles, and resilience.

In that frame, sanctions do not appear only as external pressure. They can also be absorbed by the actor as a sign of relevance. When a politicized ecosystem turns official measures, investigations, or public mentions into proof of effectiveness, the institutional response can also end up functioning as narrative input. That possibility does not invalidate sanctions or their practical effect, but it does require reading how the actor attempts to process them before its audience.

 

Spain and the gray zone between journalism, contact, and belonging

Spanish authorities announced the arrest of an alleged collaborator linked to CARR and Z-Pentest, in an investigation developed with FBI information. Spain’s Ministry of the Interior stated that the detainee was closely linked to those groups and had allegedly participated in actions attributed to NoName057(16), later disseminated through portals related to geopolitics and pro-Russian narratives. The Record also reported that the investigation linked the suspect to CARR, Z-Pentest, and NoName057(16).

Z-Pentest offers a radically different reframing: it describes the detainee as a journalist who maintained contact with them and conducted interviews, and presents the case as a criminalization of journalistic communication. It also denies selling information, presence in markets, or financial ties to data-trading platforms.

iQBlack does not automatically adopt either version. The intelligence reading lies in the gray zone. When does contact become collaboration? What distinguishes an interview, ideological affinity, logistical support, an informational relationship, or operational belonging? What evidentiary threshold do authorities use, and what narrative threshold does the actor use to deny a link?

This point is key because the pro-Russian hacktivist ecosystem does not necessarily operate with formal memberships in the traditional sense. It can function through flexible relationships, one-off support, communities, intermediaries, translators, channels, local contacts, journalists, sympathizers, facilitators, or people who perform tasks without perceiving themselves as members of an organization.

The Spanish case, therefore, is especially sensitive not only because of the detainee’s situation, but also because it exposes a dispute over the meaning of “linkage”. For authorities, certain contacts or actions may constitute collaboration, while from the actor’s perspective those same contacts can be presented as journalism, communication, or political affinity. Part of the ecosystem’s resilience plays out in that ambiguity.

 

Assessment and conclusion

Z-Pentest Alliance projects a more disciplined, less fragmented, and more strategic identity than the usual image of an occasional hacktivist alliance.

The actor does not deny its pro-Russian orientation or its cooperation with NoName057(16), but it attempts to control the interpretive frame. It rejects being equated with CARR, shifts OT/ICS toward a category of work area rather than total identity, and presents its structure as a unified system with internal coordination.

The interview suggests that Z-Pentest manages visibility as a resource. It publishes when convenient, reserves when it considers necessary, and attempts to correct public perceptions. It also shows that communication is part of its toolbox, although not necessarily its primary objective.

Visual production serves a strategic function. Z-Pentest states that console materials or technical detail are not easily interpretable by ordinary users, so it prioritizes visually understandable results. That decision turns public evidence into a form of narrative translation: it does not show everything, but it shows enough to produce reading, pressure, and reputation.

Precise identification of the target and detailed description of damage appear as central elements for more robust analytical validation. That criterion reveals that, for the actor itself, the most valuable proof is not necessarily the method, but the documented result.

The group’s declared internationalization may have expanded its knowledge coverage beyond the technical component. iQBlack assesses that the actor probably needs support capabilities linked to language, local context, symbolic selection, political reading, and narrative circulation to sustain operations or campaigns outside its initial cultural space.

The Spanish case shows how the actor reframes legal pressure as journalistic persecution and uses the ambiguity between contact, collaboration, and belonging to contest the public narrative.

Read together, the value of the interview is not in confirming already visible alliances, but in showing how Z-Pentest manages four main ambiguities: the ambiguity between alliance and structure, the ambiguity between operation and communication, the ambiguity between visual proof and full validation, and the ambiguity between contact, collaboration, and belonging.

The challenge for intelligence is not only to identify which operations are real, but to understand what function each publication, each silence, each alliance, and each denial serves within a broader architecture of pro-Russian pressure.

 

Explore 3C-INT

Expand actor, campaign and operational-link tracking through a structured intelligence layer.

View module More articles

Get new publications

Subscribe to receive new articles and public updates from iQBlack without unnecessary noise.

iQBlack | Threat Intelligence & Threat Research . © Copyright 2026. All Rights Reserved