CyberArmy of Russia Reborn (CARR) is a pro-Russian hacktivist threat actor active since at least 2022 and aligned with Moscow’s geopolitical objectives. The group is known for disruptive cyber operations against governments, public-sector entities, and critical infrastructure in the United States and Europe, with reported targeting that includes water, wastewater, hydroelectric, energy, food-processing, and other industrial environments. Public reporting and government actions have linked CARR to attacks affecting industrial control and SCADA-related systems, as well as broader disruptive activity intended to create operational impact and amplify pro-Russian, anti-Western narratives. CARR’s operations have included distributed denial-of-service activity and other comparatively unsophisticated disruptive techniques, but the group has also been associated with intrusions into operational technology environments and attacks against human-machine interface and industrial control assets. These incidents have been assessed as creating real public-safety risk when directed at essential services. The actor has also been described as maintaining support and coordination relationships with other pro-Russian hacktivist entities, including Z-Pentest and NoName057(16). Multiple governments and security organizations assess CARR as more than a purely independent hacktivist collective. The group has been described as having a close operational relationship with Sandworm, also known as APT44, a threat actor linked to Russia’s military intelligence apparatus. U.S. authorities have publicly stated that CARR worked with or received direction from the GRU, and sanctions and indictments against alleged members have reinforced the assessment that the group operates in support of Russian state interests while retaining a hacktivist public identity. Known alleged members publicly identified by authorities include Yuliya Vladimirovna Pankratova, described by the United States as the group’s leader, Denis Olegovich Degtyarenko, described as a primary hacker, and Victoria Eduardovna Dubranova, who has been charged in connection with attacks linked to CARR. CARR is also referred to by the abbreviation CARR. Overall, the actor represents a Russian government-aligned disruptive cyber threat focused on critical infrastructure, influence signaling, and opportunistic coordination with the broader pro-Russian hacktivist ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this threat actor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.