Cyber Army of Russia, also referred to as Cyber Army of Russia Reborn, is a pro-Russian hacktivist-branded threat actor associated with disruptive and influence-oriented cyber activity in support of Russian wartime and geopolitical objectives. The group has been publicly linked by researchers to Sandworm, the GRU’s Unit 74455, based on reported infrastructure overlap, evidence that Sandworm helped create the persona, and repeated publication of data apparently stolen in Sandworm intrusions. The precise relationship remains unresolved: it may function as a Sandworm cover identity, a proxy persona, or a distinct but closely aligned group enabled by Sandworm. The actor is known for operations against Ukrainian interests and for claimed or demonstrated intrusions into Western critical infrastructure, especially water and wastewater environments. Reported activity includes distributed denial-of-service attacks against Ukrainian state websites, leakage of military-relevant information to Russian forces, and manipulation of industrial control or human-machine interface systems tied to water and hydroelectric facilities in the United States, Poland, and France. Publicly documented OT incidents attributed to the group often appear opportunistic, exaggerated, or operationally unsophisticated, with limited confirmed physical impact, but they are notable for direct interaction with control systems and for the actor’s stated interest in gaining experience for larger sabotage operations. Cyber Army of Russia also uses Telegram-centered propaganda and amplification tactics, including public claims of attacks, release of allegedly stolen data, and messaging closely aligned with Kremlin narratives and Russian information warfare themes. Available reporting indicates the group presents itself as an independent grassroots collective, while statements attributed to its representatives and arrests tied to alleged members suggest participation by pro-Kremlin actors and possible involvement of individuals connected to Russian security structures. Its behavior combines hacktivist branding, disruptive cyber operations, information operations, and support to Russian military objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Russian group observed accessing a French water mill control system, indicating OT-focused disruptive or demonstrative intrusions against French infrastructure.
Pro-Russia hacktivist collective referenced as targeting critical infrastructure/public-sector systems via opportunistic access and civic-duty framing; also referenced in the context of Russia’s militarized cyber ecosystem.
Hacktivist operations targeting US entities; described as pro-Russian; conducts DDoS, defacement, and data leaks.
Hacktivist-style group conducting attempted and claimed sabotage against civilian infrastructure, including water and hydro-related targets, while amplifying Russian information warfare narratives and seeking legitimacy or sponsorship.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.