Cyber Army Russia Reborn (CARR) is a pro-Russian hacktivist group active since 2022 that has targeted Ukraine and countries supporting Ukraine. The group has been publicly associated with disruptive activity against critical infrastructure and has murky reported ties to the Russian military-linked actor APT44, also known as Sandworm. CARR has been linked to intrusions affecting operational technology environments, including interference with human-machine interfaces at water facilities, disruption of facility operations, compromise of industrial control systems governing water storage processes, and compromise of a SCADA environment at an energy company. Public reporting indicates the group obtained control over functions such as alarms and pumps in victim environments, although authorities assessed its limited technical sophistication constrained the scale of resulting damage. Known members publicly identified by U.S. authorities include Yuliya Vladimirovna Pankratova, also known as YUliYA, described as the group’s leader and spokesperson, and Denis Olegovich Degtyarenko, described as its primary hacker. Degtyarenko was also reported to have developed training materials on compromising SCADA systems, suggesting an interest in expanding or sharing OT intrusion tradecraft. CARR is best characterized as a disruptive, politically aligned hacktivist actor focused on critical infrastructure targets in NATO countries and other supporters of Ukraine. Its observed activity supports capabilities in initial access, post-exploitation, disruption of industrial processes, and operations against OT and ICS environments, but available information does not support classifying it as a ransomware actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.