Hacktivist group

Meta Yadro Legion

AlfaNet, also referenced as АльфвНет and likely overlapping with the normalized Russian spelling АльфаНет, is assessed as a Russian-speaking or pro-Russian-aligned hacktivist actor centered on information collection, document-acquisition claims, Telegram-based visibility, and strategic affiliation with the Z-Alliance / Z-Pentest ecosystem. The active Telegram account monitored for this actor is @[redacted]. A second account, @[redacted], has been observed historically but appears inactive or lower-confidence at the time of this dataset.

The strongest actor-specific reporting basis is internal monitoring. A Russian-language announcement dated 3 May 2026 stated that AlfaNet joined Z-Alliance and established a strategic partnership with Z-Pentest. The statement framed AlfaNet as an organization focused on information gathering and document extraction, while the partnership objectives reportedly included improving intelligence activity, acquiring sensitive documents, and supporting broader pro-Russian cyber operations.

AlfaNet should not be treated as a fully validated intrusion set with independently confirmed malware, infrastructure, or victim-side telemetry. The available evidence supports tracking it as a monitored hacktivist intelligence-and-claims actor with increasing ecosystem relevance. Its direct technical capability remains uncertain. Its alliance with Z-Pentest is significant because Z-Pentest and affiliated pro-Russian hacktivist actors are associated in public reporting and government advisories with OT/ICS access claims, exposed VNC/HMI targeting, defacement, hack-and-leak behavior, and propaganda-driven amplification.

Confidence is medium that AlfaNet is active or semi-active and connected to Z-Alliance / Z-Pentest as of early May 2026. Confidence is low to medium regarding independent technical capability beyond document-oriented collection and claim amplification. Any inference that AlfaNet can conduct OT/ICS operations should be treated as alliance-level exposure, not confirmed actor-specific capability.

Created by iQBlack CTI Team
Contributors 1
Last updated 2026-08-20

ATT&CK

MITRE ATT&CK

T1005Data from Local System
T1041Exfiltration Over C2 Channel
T1110.003Password Spraying
T1119Automated Collection
T1190Exploit Public-Facing Application
T1213Data from Information Repositories
T1491.002External Defacement
T1498Network Denial of Service
T1583.003Virtual Private Server
T1591Gather Victim Org Information
T1593Search Open Websites/Domains
T1595.002Vulnerability Scanning

Research

Selected OSINT