Cyber Army of Russia Reborn (CARR), also styled CyberArmyofRussia_Reborn, is a Russian state-linked, pro-Russian hacktivist group active since at least 2022. Linked to Russia’s military intelligence agency, the GRU, it conducts disruptive cyber operations in support of Russian geopolitical interests and the war against Ukraine. CARR has operational ties to Sandworm, also known as APT44. It is closely associated with the OT-focused group Z-Pentest, which has also been identified as a CARR alias in U.S. criminal proceedings. Its identified leadership includes Yuliya Pankratova, known as YUliYA, and primary hacker Denis Degtyarenko, known as Dena. CARR targets government agencies, financial institutions, media organizations, and critical infrastructure, particularly in the United States, Ukraine, and European countries supporting Ukraine. Its operations combine distributed denial-of-service attacks with compromises of industrial control systems at water, wastewater, energy, and food-processing facilities. The group exploits poorly secured internet-facing remote-access services, including Virtual Network Computing connections, to access operational technology. It enumerates exposed industrial systems and manipulates human-machine interfaces and SCADA controls, including pumps and alarms. Its activity has caused operational disruption and physical consequences, including overflowing water tanks and damage at food-processing facilities. CARR uses Telegram to coordinate activity, announce targets, claim responsibility, and publish photographs or videos of purported compromises. Its DDoS operations include the use of commercial DDoS-for-hire services. Although much of its tradecraft is relatively unsophisticated, access to inadequately secured industrial environments creates significant operational and public-safety risks. The group and its leading members have been subject to international sanctions and law-enforcement action.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Third-party group mentioned as a recipient or associate of BLACKNET-00 tool offerings.
Russia-linked hacktivist group associated in prior reporting with ICS-focused tooling and identified here as a reported purchaser of TRK-25. The reference does not establish operational use of the current BLACKNET sample by CARR.
Pro-Russian hacktivist group sanctioned in connection with cyber operations, including targeting U.S. critical infrastructure and compromising industrial control/SCADA environments.
Pro-Russian hacker collective accused of launching DDoS attacks on government resources worldwide in support of Russia’s war effort against Ukraine.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.