Spanish police, with FBI support, arrested a man in Palencia suspected of supporting the pro-Russia hacktivist groups Cyber Army of Russia Reborn (CARR) and **Z-Pentest`, authorities said. Investigators believe the suspect had close ties to the groups, may have carried out attacks on behalf of NoName057(16), and was linked to cyber operations targeting critical national infrastructure in countries backing Ukraine. Police searched his home, seized computer equipment and cryptocurrency storage devices, and froze a wallet suspected of holding proceeds tied to cybercrime.
Authorities also said the suspect helped a Ukrainian CARR member flee toward Russia through Poland and Belarus after an FBI tip-off in August 2025. The arrest forms part of wider US-European efforts to identify and disrupt politically motivated pro-Russia cyber actors, including Operation Riptide and the FBI’s Operation Red Circus. Officials have not publicly identified the suspect or disclosed specific charges, and the investigation remains ongoing.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Spanish National Police arrested the Palencia resident in July 2026 as part of an investigation into alleged support for pro-Russian hacktivist groups including CARR, Z-Pentest, and NoName057(16). Authorities said no formal charges had yet been filed and that he was being investigated for terrorism-related offenses and computer damage.
The FBI launched Operation Red Circus in December 2025 as a campaign to counter Russian state-sponsored cyber threats. Later reporting said the March 2026 Spanish arrest aligned with this broader effort and with Operation Riptide.
During the Palencia operation, investigators seized computer equipment and cryptocurrency storage devices from the suspect's home. Authorities also froze a wallet suspected of holding proceeds from cybercrime.
Spanish police arrested a man in Palencia in March 2026 on suspicion of supporting pro-Russia hacktivist groups linked to attacks on critical national infrastructure. Authorities said he had close ties to Cyber Army of Russia Reborn and Z-Pentest and may also have conducted attacks for NoName057(16).
After an FBI tip-off in August 2025, a Ukrainian member of Cyber Army of Russia Reborn was helped to flee toward Russia via Poland and Belarus, according to investigators. Authorities allege the Palencia suspect assisted in that escape.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
9 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcetherecord.media
Open sourcecyberscoop.com
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcetheregister.com
Open sourcehackread.com
Open sourcerewardsforjustice.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.