Cyber Army of Russia Reborn (CARR) is a pro-Russian hacktivist persona and operational cluster active since 2022 that has been repeatedly linked to disruptive cyber operations against organizations in countries supporting Ukraine. The group is also known as CyberArmyofRussia_Reborn, Cyber Army of Russia, and Z-Pentest; reporting also describes Z-Pentest as either an alias, companion brand, or OT-focused offshoot formed from overlap between CARR and NoName057(16). CARR has been publicly associated with Russian state interests, and multiple government actions and advisories have assessed that it was founded, funded, or otherwise supported by Russian military intelligence, including links to the GRU and specifically early support from GRU Unit 74455. Some reporting also ties members of GRU Unit 29155 to operations involving CARR. CARR initially built its profile through Telegram-coordinated distributed denial-of-service activity and propaganda-driven claims of attacks against government agencies, public services, and private organizations in the United States, Europe, and Ukraine-related target sets. Over time, the group expanded beyond website disruption into intrusions affecting operational technology and industrial control environments. It has been associated with targeting water and wastewater systems, energy infrastructure, food and agriculture entities, and other critical infrastructure. Public reporting and law-enforcement allegations state that the group claimed responsibility for hundreds of attacks worldwide in support of Russia’s geopolitical objectives. The group’s tradecraft is generally characterized as opportunistic and lower sophistication than mature state APT units, but still capable of causing real-world disruption where defenses are weak. Advisories describe CARR and affiliated actors as commonly exploiting internet-exposed remote access services, especially VNC-connected human-machine interfaces, along with default credentials, weak passwords, reused credentials, brute-force activity, and other easily replicated access methods. Once inside OT environments, the actors have been reported manipulating HMI settings, changing parameters or device names, disabling alarms, restarting or shutting down devices, and causing temporary loss of view for operators. Their operations are frequently amplified through Telegram posts, screenshots, videos, and exaggerated impact claims intended to support psychological and information effects. CARR operates within a broader pro-Russian hacktivist ecosystem that includes NoName057(16), Sector16, and other aligned brands. Reporting indicates close collaboration with NoName057(16), including shared propaganda spaces and overlapping personnel, and assesses that dissatisfaction within CARR contributed to the emergence of Z-Pentest as a more OT-focused formation in 2024. Sector16 is also described as collaborating with this cluster on industrial-targeting activity. Representative actor mappings in public reporting have additionally linked CARR to Sandworm or APT44, particularly in the context of Russian military influence, false-front behavior, and coordination between disruptive cyber activity and information operations. Law-enforcement and sanctions actions have targeted alleged CARR members and facilitators. Public U.S. actions in 2024 identified Yuliya Vladimirovna Pankratova as the group’s leader and Denis Olegovich Degtyarenko as a primary hacker, while later indictments alleged that CARR was directed by the GRU and used cybercriminal services and DDoS-for-hire capabilities to support attacks on critical infrastructure. European authorities have also designated or arrested individuals allegedly tied to the group. Overall, Cyber Army of Russia Reborn is best understood as a state-aligned pro-Russian hacktivist front that blends deniable influence operations, disruptive cyber activity, and opportunistic OT intrusion against Western and Ukrainian-linked targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Russia hacktivist group conducting cyber-attacks against critical infrastructure in EU member states and Ukraine.
Pro-Russian hacktivist group accused of conducting multiple attacks against critical infrastructure providers and other victims in support of Russia’s geopolitical interests.
Pro-Russia hacktivist group associated with disruptive cyber operations, including claimed DDoS attacks against government agencies and public services in countries supporting Ukraine, and campaigns targeting industrial control systems and critical infrastructure sectors.
Pro-Russia hacktivist group tied to disruptive cyber operations, especially DDoS attacks, against critical infrastructure, government agencies, public services, and private organizations in the United States, Europe, and other countries supporting Ukraine. The article centers on the arrest of an alleged member as part of international law-enforcement disruption efforts.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.