Cyber Army of Russia Reborn (CARR), also referred to as Z-Pentest in some reporting, is a pro-Russian hacktivist collective active since 2022 and widely assessed to operate in support of Russia’s geopolitical objectives during the war against Ukraine. Multiple government actions and sanctions have linked the group to Russian military intelligence, including assessments that it was founded, funded, or supported by the GRU and maintains a close operational relationship with Sandworm/APT44. Known members publicly identified by Western authorities include Yuliya Pankratova, described as a leader, and Denis Degtyarenko, described as a primary hacker or chief hacker. CARR has claimed responsibility for hundreds of cyberattacks worldwide. Its activity has centered on disruptive operations against countries and organizations supporting Ukraine, with repeated targeting of government agencies, public services, financial institutions, media outlets, and critical infrastructure. Reported victim environments include water and wastewater utilities, energy facilities, food and agriculture-related operations, election-related infrastructure, and other industrial control or supervisory control environments in the United States, Europe, Ukraine, and other allied countries. The group is best known for distributed denial-of-service attacks and other disruptive operations, but reporting also attributes to it intrusions into operational technology and industrial control environments. CARR has been associated with exploitation of weakly secured internet-facing remote access and human-machine interface systems, especially in critical infrastructure. Authorities have linked the group to incidents affecting water utilities and energy-sector control systems, including manipulation of industrial processes that created real-world operational and safety impacts. The group also uses Telegram extensively for coordination, propaganda, recruitment, and public claims of responsibility, often amplifying attacks as part of broader pro-Russian influence and intimidation efforts. CARR appears to combine low-complexity disruptive tradecraft with opportunistic targeting of exposed OT assets. Reported behaviors include scanning for vulnerable systems, exploiting weak authentication or exposed remote administration services, conducting DDoS attacks, accessing control interfaces, and carrying out disruptive post-compromise actions. Some reporting also links the group and its support network to the sale of stolen information and to coordination with other pro-Russian hacktivist entities, particularly NoName057(16). Overall, CARR represents a state-linked disruptive threat actor that blends hacktivist branding, propaganda, and deniable cyber operations against critical infrastructure and public-sector targets aligned against Russian interests.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Russian hacktivist group sanctioned in connection with cyber operations, including targeting U.S. critical infrastructure and compromising industrial control/SCADA environments.
Pro-Russian hacker collective accused of launching DDoS attacks on government resources worldwide in support of Russia’s war effort against Ukraine.
Hacktivist organization linked by the EU to Russian military intelligence and suspected of denial-of-service attacks against Ukraine and supporters of Kyiv.
Pro-Russia hacktivist group conducting cyber-attacks against critical infrastructure in EU member states and Ukraine.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.