
iQBlack conducted a direct interview with Z-Pentest Alliance, a pro-Russian hacktivist actor observed in recent years around operations, narratives, and publications associated with OT/ICS systems, critical infrastructure, access exposure, coordination with NoName057(16), and activity within the ecosystem that emerged around Cyber Army of Russia Reborn, also known as CARR.
Based on those responses, iQBlack produced an analytical piece titled Z-Pentest Alliance and ambiguity as structure: an intelligence reading of an exclusive interview. That analysis did not seek to reproduce the interview in a linear way, but to interpret what the responses revealed about how Z-Pentest attempts to project itself: as a politicized, disciplined, internationalized structure capable of managing visibility, reserving capabilities, and operating between cooperation, propaganda, technical activity, and gray zones of belonging.
This publication serves a different purpose. Here, the full interview is presented as primary material: a direct source of the actor’s self-description in its original version. The objective is to allow researchers, analysts, journalists, security teams, and specialized readers to access Z-Pentest Alliance’s responses directly and compare them with iQBlack’s analytical reading or develop their own interpretations.
The interview allows readers to observe how the actor describes its internal structure, its relationship with NoName057(16), its position regarding CARR, the role of OT/ICS within its activity, the use of visual evidence, its criteria for analytical validation, its reading of sanctions, its posture toward critical infrastructure, and its reframing of the Spanish case as a dispute between contact, journalism, collaboration, and belonging.
Editorial note on the literal publication
Z-Pentest Alliance’s responses are presented literally, with minimal formatting normalization to facilitate reading, and do not imply that iQBlack validates each statement made by the actor.
In some passages, the actor uses political, propagandistic, or confrontational language to refer to governments, Western authorities, analysts, judicial investigations, critical infrastructure, and actors linked to the Russia-Ukraine war. iQBlack decided to preserve those expressions because they are part of the interview’s documentary value and allow readers to observe how Z-Pentest interprets its own activity, its adversaries, its alliances, and the ecosystem in which it operates.
The literal publication of these responses should not be read as endorsement, legitimization, or independent confirmation. It should be read as primary material of analytical interest: an actor self-description that allows discourse, public activity, observed relationships, and pressure patterns within the pro-Russian hacktivist ecosystem to be compared.
The actor’s voice as a starting point
What follows is Z-Pentest Alliance’s direct voice, without an interleaved reading by iQBlack between questions and answers.
- The name "Alliance" suggests something more than a technical brand. How do you define this idea of an alliance: a community, a coalition of teams, an operational structure, or a shared identity?
This is not a coalition of separate teams. We are more accurately represented as a single unified structure rather than a collection of independent teams that need to be constantly coordinated with one another. Coordination certainly exists within our organization, but it happens inside one common system, not between separate teams, each operating according to its own priorities, goals, and principles. That is precisely why we function as a single entity: decisions are made based on shared interests and a common strategy, rather than through the search for compromises between independent groups.
- Z-Pentest has been publicly associated with operations or narratives linked to OT/ICS. Do you consider this to be the real core of your operational identity, or only one line within a broader repertoire?
Of course not! We conduct many operations that are not related to industrial control systems (OT/ICS) in any way. This is simply one of our areas of focus. Unfortunately, we cannot showcase most of our work. As the great Russian writer, thinker, philosopher, and publicist - a classic of world literature - once said: "Silence is a great talent."
- In OT/ICS environments, the psychological impact of demonstrating access can often be as important as actual manipulation. How do you evaluate the difference between access, demonstration, intimidation, and effective disruption?
The psychological effect is just a psychological effect. What matters far more is the actual disruption of the service. Psychological distress tends to fade over time, or it can be mitigated, for example, through therapy or medication. Yes, it is unpleasant to realize that someone has seen something they were not supposed to see. However, if an issue disrupts the operation of a service, the consequences become far more serious, and the damage can be truly enormous.
- Without describing technical procedures or active targets, what conditions make an industrial or infrastructure environment interesting for Z-Pentest: remote exposure, weak credentials, symbolic value, country, sector, or the possibility of generating a public reaction?
Probably all of the above, except for the publicity aspect. Most of our attacks are either discovered only a year later or never become public at all, so the attention and media coverage itself are not something that particularly concerns us. Of course, there are cases when disclosure and a certain level of publicity, if you will, are necessary, but those situations are extremely rare. In addition, there is information that we deliberately choose not to disclose.
- Some reports describe Z-Pentest as an actor that takes advantage of exposed remote access and poor segmentation practices. Does that reading seem accurate, incomplete, or too simplified to you?
No, of course not. The problem is that some so-called analysts often draw conclusions without having a complete understanding of the situation or access to all the relevant information. They evaluate only what is visible on the surface and frequently assume that everything works exactly the way they believe it does.
We have already been attributed all sorts of things - from the use of publicly available tools like Shodan to other methods that, in their view, form the foundation of our work. If that is their opinion, they are entitled to it. They can continue to think that way.
We do not see it as our mission to convince anyone otherwise or to reveal every detail of our activities. Some information can be shared publicly, while other aspects remain outside the scope of discussion. We are perfectly comfortable with some people having an incomplete picture based only on the data that is publicly available.
- What role does visual proof - videos, screenshots, panels, interfaces - play in your public communication? Do you consider it technical evidence, a psychological pressure tool, or a reputation mechanism within the ecosystem?
Usually, we publish what has already been mentioned earlier: videos, screenshots, and a description of the actions that were carried out. In most cases, this is more than enough for someone to independently understand the situation and get a general picture of what happened.
At the same time, we try to provide as much detail as possible about what exactly was done and which steps led to the outcome. A deeper technical analysis and verification of the details are left to the specialists on the other side - they are the ones who need to investigate what happened, identify the causes, and address the consequences.
Of course, situations like these can create additional pressure on specialists and affect their psychological state, but that is still not the primary consequence. The much more serious issue is the fact that the problem itself already exists and requires time, resources, and effort to fix what has been disrupted.
- You have been presented as part of a broader pro-Russian ecosystem, alongside actors such as NoName057(16) and CARR. How should that relationship be understood: coordination, political solidarity, operational cooperation, division of tasks, or simple narrative alignment?
For clarity, and for everyone who continues to claim that Z-Pentest Alliance = CARR, it is important to clarify: this is not the case. CARR as a separate structure has not existed for a very long time.
Yes, we coordinate our actions with our friends from NoName057(16). There is also an element of political solidarity involved. Despite the fact that our group now has a more international composition, we share their views and principles, which is why we are willing to maintain cooperation and provide support within our capabilities.
- In a joint campaign, how is it decided which actor communicates, which actor executes, which actor amplifies, and which actor keeps public credit for the operation?
Everyone contributes and takes part in different areas of work. As for achievements or personal recognition, that is not something we consider to be the main priority.
Ultimately, we are working toward a common goal and pursuing the same objective. What matters is not the contribution of an individual person or who receives more attention, but the overall result and the ability to work together effectively as a team.
- From the outside, your identity appears to include Serbian elements, historical memory, an anti-Western position, and pro-Russian alignment. Which part of that identity is cultural, which part is political, and which part is operational?
Initially, the foundation of our team was formed by a Serbian core. Over time, due to ongoing events and shared views, a large number of people from different countries joined us, and today our composition can truly be described as international.
We are united by common principles, mutual support, and the desire to operate as a single team.
We believe that modern conflicts reveal weaknesses even in the most advanced systems. Western countries have spent years emphasizing the high level of their protection and security, yet in practice they have repeatedly faced challenges in maintaining the resilience of their own digital systems and critical infrastructure.
For us, this demonstrates that it is not enough to rely solely on public statements - real resilience is measured by actions and by the ability to withstand challenges. We will continue to demonstrate our position and show that the capabilities of opposing sides should not be underestimated.
- Does Z-Pentest's national or cultural identity influence target selection, or is the main criterion the geopolitical position of the target toward Russia and its allies?
Yes, without a doubt, this has an impact. It is already clear today that the conflict has long gone beyond the framework of a purely bilateral confrontation. NATO countries and European states are actively involved in the process - from financial support and arms supplies to other forms of assistance.
For a long time, Western countries have sought to present themselves as a force possessing absolute control and superiority, but reality shows that their systems are not untouchable. Support for military and political decisions carries consequences, and responsibility for those decisions lies with those who participate in making them.
We view the actions of NATO and individual European states as direct involvement in the processes taking place. For us, this demonstrates that the role of those who actively influence the situation and shape the current environment cannot be ignored.
Time shows that even the most advanced structures have vulnerabilities, and claims of complete security and superiority do not always correspond to reality.
- What types of profiles best compose an alliance like Z-Pentest? Without mentioning personal identities, are we talking about technical operators, OSINT researchers, people with industrial knowledge, propagandists, translators, community administrators, or contacts with access?
We have a broad range of areas of focus, and each participant plays their own role. The team includes people responsible for technical aspects, analysis, and various operational tasks, as well as those who handle communications, prepare materials, and engage with the audience.
We have built a complete structure in which each member complements the others. For us, it is important not only to complete individual tasks but also to ensure overall coordination across all areas of work.
At this point, we have everything necessary to achieve our objectives: experienced people, a clear division of responsibilities, and a team capable of operating effectively as a single mechanism.
- Some alliance communiqués refer to reconnaissance, intrusion, persistence, and document acquisition as parts of a complete cycle. Does Z-Pentest see itself as an access unit, a persistence unit, an impact unit, or a combination of those functions?
We continue to work on developing and expanding our capabilities. In the near future, new areas of activity and new results will emerge, which will be even more interesting to follow.
We do not intend to stop at what we have already achieved - we are constantly improving, analyzing our experience, and moving forward. For us, it is important not only to maintain our current level but also to continue developing, strengthening the team, and expanding our capabilities.
There is still a great deal of work ahead, and we are ready for the next stages.
- When you publish or support an operation against critical infrastructure, what limits do you say you apply internally to avoid physical damage, uncontrolled civilian impact, or loss of control over the effect?
Previously, we did indeed have an internal restraint - we consciously avoided targeting the civilian infrastructure of our adversary. But the West, with its own actions, removed that restraint.
With their alleged attacks on Russian children, hospitals, schools, and civilian cities, they crossed a red line. They showed that, in their view, there are no rules and no mercy.
Now everything has changed. The restraints have been completely removed.
We will strike at everything that matters to them: military facilities, energy systems, transportation hubs, decision-making centers - without distinction and without the slightest hesitation. We are no longer interested in following one-sided restrictions that our adversary has never respected.
There are no more restrictions for us. The game has become harsh and real. Now they will experience it firsthand.
- Sanctions and official mentions are often interpreted by some actors as punishment and by others as recognition. How do they really affect Z-Pentest: do they make operations more difficult, strengthen reputation, generate cohesion, or change the way you work?
Hahaha, honestly, these sanctions have absolutely no impact on us. We do not care what measures they try to impose against our team. Every new ban or restriction from their side causes more of a smile than any real concern.
Our reputation has long spoken for itself, and if such measures are being taken against us, it only shows that the West is capable of nothing more than imposing sanctions.
Do they really think they can stop us with sanctions alone? That is quite a naive assumption. We will continue moving forward, developing, and proving our results not through words, but through actions. Such attempts at pressure only motivate us to push forward even more.
- If you could correct one mistaken interpretation about Z-Pentest Alliance, its relationship with NoName057(16), or its role within the pro-Russian ecosystem, what would it be?
In general, we would not change anything, because we are completely satisfied with our cooperation. We work together with our friends, shoulder to shoulder, moving toward a common goal. For us, the most important things are mutual support, trust, and joint efforts toward our shared objective.
Together, we are stronger, and we continue moving only forward.
- According to some publications in public channels, you have asked to contact Spanish journalists in order to show "the truth" about the arrest in Spain. What, specifically, is the main point that you consider false, incomplete, or manipulated in the version published by the authorities?
What exactly is the manipulation here? Look at the open sources where it is claimed that an "extremely dangerous hacker" from Z-Pentest Alliance was captured. In reality, the situation appears to be different: the person detained was a journalist who maintained contact with us and conducted interviews with us.
It is an unfortunate situation because ordinary communication and journalistic activity were presented in a completely different light. Instead of providing an objective analysis of the circumstances, people are immediately shown the image of a "malicious hacker" without being given the full context.
- Spanish authorities describe the arrested person as someone linked to CARR and Z-Pentest, and they also mention activities associated with NoName057(16). From your perspective, what does it really mean to be "linked" to Z-Pentest: formal membership, occasional collaboration, logistical support, ideological sympathy, or contact within the ecosystem?
Spanish authorities have once again demonstrated what we consider to be a lack of competence and are repeating the same mistakes. They detained a journalist who had interviewed us and was simply doing his job.
This creates a strange situation: European countries often speak about freedom of speech and the protection of journalists, yet a person who was sharing information and communicating with different sides is being portrayed in a completely different light.
Does this not look like a double standard? When some countries accuse others of restricting freedom of speech, while facing similar questions within their own systems. Before making loud statements, it is important to examine the facts and not replace journalistic activity with a version of events that is more convenient for someone.
- According to public information, the case includes alleged logistical assistance to facilitate the movement of a Ukrainian hacker toward Russia. Without entering into personal identities or operational routes, do you consider human and logistical support to be part of the hacktivist ecosystem, or do you see it as a narrative constructed by authorities to criminalize political contacts?
And now, does supporting someone who wants to leave the country count as a crime? In that case, it would mean that half of Europe could potentially be placed under suspicion, given that it provides asylum to Ukrainians and spends significant resources helping people who were forced to leave.
The situation appears rather strange and far-fetched. A person from Italy was trying to help a person from Ukraine leave the country - even if that person was indeed involved in hacking activities, does the mere act of helping someone automatically make another person a criminal?
The story appears highly ambiguous and raises many questions. Where is the line between a crime and ordinary humanitarian assistance? Does this interpretation of the situation seem too convenient for creating a particular narrative?
- The investigation mentions encrypted messaging applications, coordination with other members, and a wallet allegedly linked to proceeds from the sale of information. How does Z-Pentest, within its own structure, separate public communication, operational coordination, third-party support, and any economic activity associated with information or access?
Z-Pentest Alliance has never sold and does not sell any information. We do not have accounts or a presence on any forums, marketplaces, or other similar platforms.
We have never engaged in the sale of data, cooperated with such resources, or paid anyone for activities of this kind.
Any claims about the sale of information or any financial connections with such platforms are inaccurate. Our activities are not related to data trading or generating profit through such means.
- Did the arrest in Spain change anything in the way Z-Pentest manages trust, incorporates collaborators, contacts sympathizers, or relates to allied groups such as CARR and NoName057(16)?
I think that if the arrest of an ordinary journalist who simply interviewed us and has no connection to our activities becomes a reason for pressure on journalistic work, it creates a dangerous precedent. It would mean that anyone who communicates with us, conducts an interview, or attempts to obtain information could automatically become a subject of suspicion.
From there, anyone could be accused based solely on contacts: today it is an interview, tomorrow someone discovers "connections," and then new allegations appear.
For us, nothing has changed: we continue communicating with various groups and individuals just as we did before. We only express our regret regarding the situation involving Chris Barlati, who publicly expressed views that differed from the prevailing Western perspective.
The question remains the same: where is the line between journalism, freedom of speech, and attempts to portray any form of interaction as something suspicious?
- You mentioned that an important part of your activity remains private and that only a portion can be published. Without naming targets, exposing access, or revealing operational methods, what type of non-public evidence would you consider significant for independent analytical validation: redacted screenshots, timelines, technical context, access categories, affected sectors, or some other type of material?
Of course, the most relevant data would be information about the target reached, including its precise identification and a detailed description of the damage caused. The more complete and reliable the information about the results of the attack, the greater its value for subsequent analysis, effectiveness assessment, and documentation of what occurred.
- When you say that Z-Pentest is not limited to OT/ICS, should that be understood mainly as a technical expansion toward other systems, or also as a broader support structure that includes political analysis, local context, language knowledge, documentation, relationships, information validation, or impact interpretation?
In this context, we were referring to the fact that our activity is not limited exclusively to the OT/ICS domain. If it can be put that way, we have a wide variety of work vectors, and OT/ICS is only one of them. We also use OSINT methods; however, this area represents a significantly smaller part of our activity and is not our main one.
- How do you decide what remains private, what can be shared with journalists or analysts, and what ends up being published on your own channels? In other words, where do you draw the line between operational security, strategic communication, reputation, and signaling toward your audience?
An ordinary user, as a rule, will not be able to understand the principle and type of attack simply by being shown console content, even with a textual description of what is happening. This type of material requires a certain level of technical training for proper interpretation. That is precisely why publications emphasize visually understandable results, allowing a broader audience to assess what is happening without needing to go deeper into the technical details.
Editorial closing
This interview is published as a documentary record of a direct interaction with Z-Pentest Alliance. Its reading allows the actor’s self-description to be contrasted with its public activity, with the editorial analysis developed by iQBlack, and with the evolution of a pro-Russian hacktivist ecosystem where OT/ICS, critical infrastructure, functional alliances, narrative pressure, visual activity, and disputes over belonging also form part of the terrain of confrontation.
The value of this publication does not lie in assuming that every statement made by the actor is verified, but in preserving its voice as primary material. Throughout the interview, Z-Pentest describes its own view of the alliance’s structure, cooperation with NoName057(16), the distance it attempts to establish from CARR, the role of OT/ICS in its repertoire, the difference between public proof and analytical validation, and the use of ambiguity as a resource to operate between visibility, reserve, contact, support, and belonging.
This publication also reflects part of the work iQBlack develops within [Cyber]Crime Characterization for Intelligence (3C-INT), where actors such as Z-Pentest Alliance are observed, characterized, and linked within a broader ecosystem of relationships, public activity, cooperation between actors, operational propaganda, pressure against infrastructure, and intelligence signals.
The full content of that characterization remains reserved for private and contractual workflows; here, only editorial material suitable for public consultation is published.
Explore 3C-INT
Expand actor, campaign and operational-link tracking through a structured intelligence layer.
Get new publications
Subscribe to receive new articles and public updates from iQBlack without unnecessary noise.