CyberArmy of Russia Reborn (CARR) is a pro-Russian hacktivist threat actor active since at least 2022 and aligned with Moscow’s geopolitical objectives. The group is known for disruptive cyber operations against governments, public-sector entities, and critical infrastructure in the United States and Europe, with reported targeting that includes water, wastewater, hydroelectric, energy, food-processing, and other industrial environments. Public reporting and government actions have linked CARR to attacks affecting industrial control and SCADA-related systems, as well as broader disruptive activity intended to create operational impact and amplify pro-Russian, anti-Western narratives. CARR’s operations have included distributed denial-of-service activity and other comparatively unsophisticated disruptive techniques, but the group has also been associated with intrusions into operational technology environments and attacks against human-machine interface and industrial control assets. These incidents have been assessed as creating real public-safety risk when directed at essential services. The actor has also been described as maintaining support and coordination relationships with other pro-Russian hacktivist entities, including Z-Pentest and NoName057(16). Multiple governments and security organizations assess CARR as more than a purely independent hacktivist collective. The group has been described as having a close operational relationship with Sandworm, also known as APT44, a threat actor linked to Russia’s military intelligence apparatus. U.S. authorities have publicly stated that CARR worked with or received direction from the GRU, and sanctions and indictments against alleged members have reinforced the assessment that the group operates in support of Russian state interests while retaining a hacktivist public identity. Known alleged members publicly identified by authorities include Yuliya Vladimirovna Pankratova, described by the United States as the group’s leader, Denis Olegovich Degtyarenko, described as a primary hacker, and Victoria Eduardovna Dubranova, who has been charged in connection with attacks linked to CARR. CARR is also referred to by the abbreviation CARR. Overall, the actor represents a Russian government-aligned disruptive cyber threat focused on critical infrastructure, influence signaling, and opportunistic coordination with the broader pro-Russian hacktivist ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist pro-russe lié à de multiples attaques contre des infrastructures critiques aux États-Unis et en Europe, notamment des installations de traitement d’eau et alimentaires, ainsi qu’à des attaques contre des systèmes SCADA d’une entreprise énergétique américaine.
Pro-Russian hacktivist group allegedly supported by the suspect; U.S. authorities accused alleged members of targeting U.S. critical infrastructure, including industrial control systems at water, hydroelectric, wastewater and energy facilities. The group is also described as maintaining a close operational relationship with Sandworm.
Pro-Russian hacktivist group targeting government agencies, critical infrastructure, and industrial systems across Europe and the United States, mainly through DDoS attacks and disruptive cyber operations.
Pro-Russia hacktivist group linked to attacks on critical national infrastructure, including water and energy facilities, and described as conducting opportunistic attacks against critical infrastructure. The article says US officials stated CARR was working with, or receiving instructions from, Russian military intelligence.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.