Threats

Spain Arrests Suspected Pro-Russian Hacktivist

July 8, 2026 00:11 · 8 min read
Spain Arrests Suspected Pro-Russian Hacktivist

Spanish authorities have made an arrest in connection with pro-Russian hacktivist groups, highlighting the ongoing threat of cyberattacks from these organizations. The arrested individual, who lived in Palencia, is suspected of being an active member of the CyberArmy of Russia Reborn (CARR) and Z-Pentest, two groups known for their involvement in attacks targeting critical infrastructure in the U.S. and Europe.

Background on Pro-Russian Hacktivist Groups

Although hacktivism typically refers to cyberattacks intended to promote a political or ideological message rather than cause widespread damage, the two groups have been linked to multiple attacks that pose real safety risks for people. A recent indictment of another alleged CARR member, Victoria Eduardovna Dubranova, revealed that the hacking group carried out cyberattacks against water and food-processing facilities in the U.S.

The U.S. government has previously sanctioned two more alleged members of the group, Yuliya Vladimirovna Pankratova and Denis Olegovich Degtyarenko, who were linked to attacks against the SCADA systems of an American energy firm. CARR has also been loosely linked to the Russian state-backed threat group APT44, aka “Sandworm,” which is known for masking their activities behind hacktivist collectives.

Details of the Arrest

According to the Spanish police announcement, the arrested individual provided logistical and operational support to a Ukrainian hacker who operated for CARR. The investigators say the man attempted to facilitate the hacker’s escape to Russia through Poland and Belarus. The suspect also used various encrypted messaging applications to maintain contact with other members of these terrorist groups, coordinating activities and providing support for their operations.

The Spanish police acted on information provided by the FBI and launched an investigation in August 2025. In March 2026, the authorities raided the suspect’s home in Palencia and seized computers and cryptocurrency storage devices, which will be used in the ongoing investigations. The officers also froze cryptocurrency wallets that were used to receive crime proceeds, specifically, sales of stolen data.

Current Status and Potential Charges

Currently, the arrested man is under investigation, and no specific charges have been formally filed. However, the police announcement mentions he is suspected of membership in and collaboration with a terrorist organization, glorification of terrorism, and computer damage. The investigation underscores the collaborative efforts between international law enforcement agencies to combat cybercrime and the ongoing threat posed by pro-Russian hacktivist groups.

The case highlights the importance of cybersecurity and the need for continued vigilance against threats from hacktivist groups and other malicious actors. As cybersecurity threats evolve, it is crucial for individuals and organizations to stay informed and take proactive measures to protect themselves and their assets.

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

This statistic emphasizes the challenge of detecting and responding to cyber threats effectively. It also points to the value of implementing robust cybersecurity measures, including breach and attack simulation tests, to enhance detection capabilities and prevent threats from slipping by undetected.

For those interested in learning more about how to protect against such threats, resources like the Picus whitepaper on breach and attack simulation can provide valuable insights into testing SIEM and EDR rules to stop threats from slipping by detection.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free