Cyber Army of Russia Reborn (CARR), also known as Z-Pentest, is a pro-Russian hacktivist collective active since 2022 that has been publicly linked by Western governments and security agencies to Russian military intelligence, including the GRU. U.S. authorities have alleged that the group was founded, funded, and directed by the GRU, while other government assessments have linked its creation and tooling support to Russian state structures and noted a close operational relationship with Sandworm. The group has used Telegram extensively for coordination, propaganda, recruitment, and public claims of responsibility. CARR has conducted disruptive cyber operations in support of Russia’s geopolitical objectives and war effort against Ukraine. Its activity has included sustained distributed denial-of-service attacks against government resources, public services, financial institutions, media outlets, and private organizations in countries supporting Ukraine. Beyond DDoS activity, the group has also been accused of targeting operational technology and industrial control environments, including water, wastewater, hydroelectric, food-processing, and energy-sector systems. Reported incidents attributed to the group include compromises of human-machine interfaces and SCADA-related environments that created real-world operational disruption and public-safety risk. The actor’s tradecraft is frequently described as opportunistic and reliant on exposed internet-facing systems, especially weakly secured remote access services and industrial interfaces. Government advisories have assessed that pro-Russian hacktivist groups including CARR exploit minimally secured remote access to operational technology devices, scan for vulnerable exposed systems, brute-force passwords, and manipulate HMI or SCADA environments. CARR is also associated with disruptive operations against election-related infrastructure and other sensitive public-sector targets. Known members publicly identified by governments include Yuliya Pankratova, described as the group’s leader, and Denis Degtyarenko, described as a primary hacker or chief hacker. The group has at times been described as having a large online following and a broad volunteer or supporter base. Multiple law-enforcement actions, sanctions, indictments, and reward offers have targeted alleged members and facilitators of CARR, reflecting its significance within the broader Russian state-aligned hacktivist ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Third-party group mentioned as a recipient or associate of BLACKNET-00 tool offerings.
Pro-Russian hacktivist group sanctioned in connection with cyber operations, including targeting U.S. critical infrastructure and compromising industrial control/SCADA environments.
Pro-Russian hacker collective accused of launching DDoS attacks on government resources worldwide in support of Russia’s war effort against Ukraine.
Hacktivist organization linked by the EU to Russian military intelligence and suspected of denial-of-service attacks against Ukraine and supporters of Kyiv.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.