Cyber Army of Russia Reborn (CARR) is a pro-Russian hacktivist group active since 2022 that has conducted disruptive cyber operations in support of Russia’s geopolitical objectives, particularly in the context of the war against Ukraine. The group is widely tracked under the acronym CARR and has also been referred to as Z-Pentest in some reporting, though Z-Pentest is also described elsewhere as a closely linked associated group or offshoot. Cybersecurity and government reporting has linked CARR to Russian military intelligence, including assessments that the GRU supported its creation, direction, and tooling, and that it has maintained operational relationships with Sandworm and other GRU-linked elements. CARR has primarily targeted governments, public services, financial institutions, media organizations, and critical infrastructure in Ukraine, Europe, and North America, especially in countries supporting Ukraine. Its activity has included sustained distributed denial-of-service campaigns, disruptive intrusions, and operations affecting industrial and operational technology environments. Reported victim sectors include water and wastewater, energy, agriculture, food processing, and other industrial or public-sector environments. The group has repeatedly claimed responsibility for attacks through Telegram and other propaganda channels, using cyber operations as both a disruptive mechanism and an influence tool. The group’s tradecraft has often been characterized as opportunistic and comparatively unsophisticated, relying heavily on DDoS activity and exploitation of exposed or weakly secured internet-facing systems. At the same time, CARR has been associated with more serious activity involving industrial control and supervisory control environments, including abuse of exposed human-machine interfaces, virtual network computing access, weak credentials, and poorly secured remote administration paths. Multiple assessments note that while pro-Russian hacktivist actors frequently exaggerate impact, CARR-linked operations have nonetheless created real operational and public-safety risk in critical infrastructure environments. CARR operates within a broader ecosystem of pro-Russian state-aligned hacktivist and influence actors. It has been associated with NoName057(16), KillNet-affiliated activity, Sector16, Z-Alliance, TwoNet, and the Infrastructure Destruction Squad, and has been described as part of a wider Russian state-linked disruptive cyber and information operations landscape. Known individuals publicly tied to the group include Yuliya Pankratova, identified in sanctions and law-enforcement actions as a leader, and Denis Degtyarenko, identified as a principal hacker. Victoria Dubranova has also been charged by U.S. authorities for alleged support to CARR and NoName057(16). Cyber Army of Russia Reborn is best understood as a state-linked pro-Russian disruptive cyber actor that blends hacktivist branding, propaganda, volunteer-style mobilization, and deniable support to Russian intelligence objectives. Its significance lies less in advanced malware tradecraft than in its role as a persistent, politically aligned threat to critical infrastructure and public-sector targets, and as a bridge between overt hacktivism and covert state-directed cyber operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Russian hacker collective accused of launching DDoS attacks on government resources worldwide in support of Russia’s war effort against Ukraine.
Hacktivist organization linked by the EU to Russian military intelligence and suspected of denial-of-service attacks against Ukraine and supporters of Kyiv.
Pro-Russia hacktivist group conducting cyber-attacks against critical infrastructure in EU member states and Ukraine.
Hacktivist pro-russe lié à de multiples attaques contre des infrastructures critiques aux États-Unis et en Europe, notamment des installations de traitement d’eau et alimentaires, ainsi qu’à des attaques contre des systèmes SCADA d’une entreprise énergétique américaine.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.