Spain arrests suspected member of pro-Russian hacktivist groups

Spanish authorities have made a significant arrest in their efforts to crack down on pro-Russian hacktivist groups. A man suspected of being an active member of CyberArmy of Russia Reborn (CARR) and Z-Pentest, two groups linked to multiple attacks targeting critical infrastructure in the US and Europe, has been taken into custody by Spain’s National Police.

While hacktivism is often associated with cyberattacks intended to promote a particular ideology rather than cause widespread damage, CARR and its affiliates have demonstrated a disturbing willingness to compromise public safety. A recent indictment of another alleged CARR member revealed that the group carried out attacks against water and food-processing facilities in the US, putting people’s lives at risk. The US government has previously sanctioned two other individuals linked to the group for their roles in cyberattacks targeting critical infrastructure.

CARR has been loosely associated with the Russian state-backed threat group APT44 (also known as “Sandworm”), which is notorious for using hacktivist collectives as a cover for its activities. According to Spanish authorities, the arrested individual provided logistical and operational support to a Ukrainian hacker who worked for CARR. The suspect also attempted to facilitate the hacker’s escape to Russia through Poland and Belarus.

The arrest was made possible by information provided by the FBI, which led to an investigation launched in August 2025. In March of this year, authorities raided the suspect’s home in Palencia, seizing computers and cryptocurrency storage devices that will be used in ongoing investigations. The police also froze cryptocurrency wallets used to receive proceeds from stolen data.

The arrested individual is currently under investigation for suspected membership in a terrorist organization, glorification of terrorism, and computer damage. While no specific charges have been formally filed, the arrest marks an important step in disrupting the activities of pro-Russian hacktivist groups that pose a significant threat to public safety.

For security teams, this case highlights the importance of staying vigilant against threats from all angles, including those masquerading as hacktivists. As we’ve seen with CARR and its affiliates, even attacks intended to promote an ideological message can have devastating consequences for individuals and communities. By regularly testing our defenses through breach and attack simulation exercises, we can better detect and prevent such threats before they compromise our security.


Source: Bleeping Computer — 2026-07-07