The White House declared a national emergency to protect the U.S. bulk-power system from risks associated with foreign-made equipment, unauthorized access, and malicious remote action. The measure was not issued in response to Z-Pentest, but it comes as the pro-Russian actor intensifies its pressure narrative against the United States while continuing to publish alleged access to systems where a digital command can alter a physical process.
DDoS can interrupt a service. Access to an industrial control system can alter the process behind it. Fifty-three OT/ICS access claims tracked by iQBlack show how NoName057(16) is pushing that distinction into increasingly sensitive territory.
Z-Pentest projects itself as a politicized structure that manages visibility, reserves capabilities, and uses ambiguity to operate between hacktivism, propaganda, transnational cooperation, and gray zones of contact, support, validation, and belonging.
Based on an exclusive interview with iQBlack, this Threat Research analyzes NoName057(16) beyond its role as a DDoSia operator. We read it as a pressure infrastructure that combines an ideologized community, intelligence tasks, propaganda, manipulation of the information cycle, functional alliances, and induced political costs.
Over the last decade, political-religious hacktivism in the Middle East has increasingly blended attack and propaganda into the same conflict space. Technical capability remains extremely important, but it no longer explains by itself how these actors gain visibility and sustain pressure around a cause.
Z-Pentest represents a form of pro-Russia-aligned hacktivism centered on exposed SCADA/OT/ICS systems, CCTV/NVR infrastructure, and automation tied to sensitive processes. Its activity reflects a mix of ideology, public intimidation, and the propagandistic use of surfaces with operational value.
More than a full merger, what is beginning to emerge is a form of functional compatibility between clusters that share enemies, platforms, and opportunities for mutual legitimation. The relevance of Cyber Islamic Resistance does not end with its anti-Israel agenda. It also helps explain how certain pro-Iranian and pro-Russian spaces can meet within the same landscape of digital agitation.
Cyber Islamic Resistance does not appear to derive its relevance solely from the intrusions it claims, but from its ability to coordinate narrative, identity, and mobilization within a pro-Iran, anti-Israel hybrid ecosystem.
The emergence of alleged leaks tied to Argentine institutions does not, on its own, confirm recent intrusions across every case. It does, however, reinforce the operational credibility of Chronus Team’s signaling and heighten reputational, institutional, and public-trust risk.
A technical and operational look at a multi-stage fraud flow built around fake-news advertorials, bridge pages, lead capture, and near-immediate phone-based conversion.