Spain arrests suspected member of pro-Russian hacktivist groups

Spanish authorities have made a significant arrest in their efforts to disrupt pro-Russian hacktivist groups. A man suspected of being an active member of CyberArmy of Russia Reborn (CARR) and Z-Pentest has been taken into custody by Spain’s National Police. These groups, while often referred to as “hacktivists,” have been linked to a series of cyberattacks targeting critical infrastructure in the US and Europe.

What sets these groups apart from other hacktivist collectives is their apparent connection to Russian state-backed threat actors. In particular, CARR has been loosely tied to APT44, also known as “Sandworm,” a group notorious for using hacktivist front groups to mask its activities. The arrest of this individual marks the latest development in an ongoing investigation that has seen multiple alleged CARR members sanctioned by the US government.

The suspect is believed to have provided logistical and operational support to a Ukrainian hacker working with CARR, as well as attempting to facilitate their escape through Poland and Belarus. Investigators say he used encrypted messaging apps to coordinate activities and provide support for the group’s operations. The individual was also allegedly involved in actions attributed to NoName057(16), a pro-Russian hacktivist collective that promotes anti-Western narratives on online platforms.

The Spanish authorities acted on information provided by the FBI, launching an investigation in August 2025. In March of this year, they raided the suspect’s home and seized computers and cryptocurrency storage devices, which are now being analyzed as part of the ongoing probe. The officers also froze cryptocurrency wallets used to receive proceeds from the sale of stolen data.

The case highlights the increasingly complex landscape of cyber threats, where state-backed actors often employ hacktivist front groups to carry out attacks. This tactic allows them to maintain plausible deniability while still achieving their goals. As a result, it’s becoming increasingly difficult for security teams and law enforcement agencies to distinguish between legitimate hacktivists and those working on behalf of nation-states.

The Spanish authorities’ efforts demonstrate the importance of international cooperation in combating cybercrime. The fact that they were able to act on information provided by the FBI underscores the need for effective communication and collaboration between law enforcement agencies across borders.

For security teams, this case serves as a reminder of the importance of staying vigilant and adapting to evolving threats. With many attacks going undetected, it’s crucial to regularly test systems and processes to ensure that detection mechanisms are adequate. This can be achieved through breach and attack simulation tests, which help identify vulnerabilities and improve overall security posture.


Source: Bleeping Computer — 2026-07-07