U.S. authorities have indicted Ukrainian national Victoria Eduardovna Dubranova for her alleged involvement in cyberattacks targeting critical infrastructure worldwide, including water systems, food supply chains, election systems, and nuclear facilities. Dubranova, also known as Vika, Tory, and SovaSonya, is accused of supporting two Russian state-backed hacktivist groups: NoName057(16) and CyberArmyofRussia_Reborn (CARR). She was extradited to the United States and has pleaded not guilty to charges in two separate cases, with trials scheduled for 2026. The Justice Department asserts that these attacks were not financially motivated but were designed to disrupt essential services and cause widespread damage.
CARR has claimed responsibility for hacking drinking water systems in multiple U.S. states, resulting in major spills and system failures, as well as attacking a Los Angeles meat processing facility, which led to an ammonia leak and food spoilage. NoName057(16) is known for deploying its custom DDoS tool, DDoSia, to knock government and critical infrastructure websites offline, recruiting global volunteers and offering cryptocurrency rewards. Both groups are believed to have direct ties to Russian state entities, with CARR reportedly founded and directed by the Russian GRU and NoName057(16) partially administered by a Kremlin-established IT organization. The indictments highlight the increasing use of state-backed hacktivist groups to target Western critical infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Alongside the criminal case, U.S. authorities announced financial rewards for information on CARR and NoName057(16) members, referenced sanctions on key operatives, and issued a joint cybersecurity advisory warning critical infrastructure operators about the threat. The advisory highlighted ongoing risks to operational technology and exposed remote access systems.
After being brought to the United States, Dubranova entered a not guilty plea to the charges related to her alleged support for the Russian-aligned hacking groups. Reporting said separate trials were scheduled following the plea.
The U.S. Justice Department unsealed charges against Ukrainian national Victoria Eduardovna Dubranova and confirmed her extradition to the United States for allegedly supporting CARR and NoName057(16). She was accused of conspiracy, damaging protected systems, fraud, and identity theft tied to attacks on critical infrastructure.
In July 2025, law enforcement disrupted more than 100 servers linked to NoName057(16). Authorities also arrested two individuals in France and Spain as part of the operation.
The U.S. Treasury Department sanctioned two leading members of CyberArmyofRussia_Reborn in response to the group's attacks on critical infrastructure. The sanctions were cited by later reporting on the broader U.S. response to the campaign.
CARR carried out intrusions against public water systems and a Los Angeles-area meat processing facility, causing real-world impacts including water disruptions, pump activations, spills, spoiled food, and an ammonia leak. The activity marked an escalation from online disruption to operational technology effects.
CyberArmyofRussia_Reborn (CARR) and NoName057(16) began conducting cyberattacks in 2022 against government and critical infrastructure targets in the U.S. and allied countries. The groups were later described by U.S. authorities as backed, sanctioned, or supported by Russian government entities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcego.theregister.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourcecyberscoop.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.