Cyber Army of Russia, also referred to as Cyber Army of Russia Reborn, is a pro-Kremlin hacktivist-branded threat actor associated with disruptive and influence-oriented cyber activity in support of Russian geopolitical objectives. The group has been publicly linked by multiple analysts to Russia’s military intelligence ecosystem, with reporting indicating ties to Sandworm, the GRU unit widely tracked as Unit 74455. The precise relationship remains unresolved, but available evidence supports at minimum operational collaboration, enablement, or use as a cover or amplification persona for Russian state-directed activity. The actor is known for targeting Ukraine and countries perceived as supporting Ukraine, as well as Western critical infrastructure. Reported victimology includes Ukrainian state entities, European organizations, and water, wastewater, hydroelectric, and other operational technology environments in the United States and Europe. The group has also been cited in broader pro-Russian hacktivist campaigns against French entities and other Western targets. Its observed operations include distributed denial-of-service attacks, intrusion activity against industrial control and operational technology systems, propaganda and psychological operations, and public leakage or amplification of stolen information. In OT-related incidents, the group has claimed and publicized unauthorized access to human-machine interfaces and control environments associated with water and utility operations. Publicly released videos have shown direct manipulation of control interfaces, although the real-world operational impact has in several cases been limited or unclear. This willingness to publicize hands-on interaction with industrial processes distinguishes the actor from many purely nuisance-oriented hacktivist groups. Cyber Army of Russia uses overtly political branding and pro-Russian messaging, presenting itself as an independent patriotic collective while aligning with Russian wartime narratives. Ukrainian authorities have alleged that members or affiliates conducted DDoS attacks against Ukrainian government websites and passed targeting information on Ukrainian military positions and air defense assets to Russian forces. Such reporting indicates that the group’s activity extends beyond symbolic hacktivism into support for kinetic military operations and intelligence collection. The actor fits within the broader ecosystem of Russian proxy and pseudo-hacktivist operations that provide deniability while advancing state interests. It overlaps conceptually with other pro-Russian disruptive collectives, but Cyber Army of Russia is particularly notable for its association with critical infrastructure targeting and its suspected linkage to Sandworm. Security professionals should treat it not as a conventional grassroots hacktivist movement, but as a politically aligned threat actor capable of disruptive cyber operations, information operations, and opportunistic OT intrusion in support of Russian objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Russian group observed accessing a French water mill control system, indicating OT-focused disruptive or demonstrative intrusions against French infrastructure.
Pro-Russia hacktivist collective referenced as targeting critical infrastructure/public-sector systems via opportunistic access and civic-duty framing; also referenced in the context of Russia’s militarized cyber ecosystem.
Hacktivist operations targeting US entities; described as pro-Russian; conducts DDoS, defacement, and data leaks.
Pro-Kremlin hacker group allegedly involved in DDoS attacks against Ukrainian state websites and leaking sensitive Ukrainian military location information to the Russian military.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.