LIVE · cybersecurity feed
Live wire
hacktivismmedium

Spain arrests suspected hacker linked to Russian hacktivist campaign

Spanish police, with assistance from the FBI, have arrested an individual suspected of supporting the pro-Russian hacktivist group Cyber Army of Russia Reborn. The arrest, which occurred in March but was announced recently, is part of a broader international effort to combat cybercrime. The suspect allegedly provided logistical support to another hacker and participated in activities aimed at spreading pro-Russian narratives.

zeroday.news · 25d ago

Spanish authorities have arrested a man suspected of involvement in pro-Russian hacktivist campaigns, including activities linked to Cyber Army of Russia Reborn and NoName. The arrest, which occurred in March but was announced on a Monday, was the result of an investigation initiated by a tip from the FBI in August 2025.

The individual was detained at his home in Palencia. Spanish officials stated that the suspect allegedly provided logistical support to a Ukrainian hacker associated with Cyber Army of Russia Reborn, also known as Z-Pentest. This support reportedly facilitated the Ukrainian hacker's escape to Russia by transiting through Poland and Belarus.

In addition to these alleged actions, the arrested individual is also accused of participating in operations attributed to the hacktivist group NoName057(16). These operations have been documented on geopolitical news sites and are characterized by Spanish authorities as efforts to disseminate pro-Russian and anti-Western narratives.

The FBI's Los Angeles field office coordinated with Spanish law enforcement in the operation, which is part of a broader global initiative called Operation Riptide. This ongoing campaign aims to target cybercriminals and the financial and infrastructural networks they utilize for fraudulent activities.

During the investigation, Spanish police searched the suspect's residence, seizing computers and cryptocurrency storage devices. A cryptocurrency wallet, believed to have been used for receiving payments related to his alleged criminal activities, was also frozen. While the investigation concluded recently, specific charges have not yet been formally announced. However, the suspect is accused of collaborating with a terrorist organization, glorifying terrorism, and damaging computer systems.

Cyber Army of Russia Reborn has been a focus for authorities since 2022, with alleged members targeted for years. The U.S. Treasury Department sanctioned individuals identified as the group's alleged leader and primary hacker, Yuliya Vladimirovna Pankratova and Denis Olegovich Degtyarenko, in July 2024.

Further actions against individuals linked to these groups include an indictment by the Department of Justice in December 2025 against Victoria Eduardovna Dubranova, a Ukrainian national accused of participating in attacks supporting Russia's geopolitical interests through Cyber Army of Russia Reborn and NoName057(16). Dubranova was extradited to the United States and has since pleaded guilty in two federal cases.

The U.S. State Department has offered substantial rewards for information on individuals associated with these hacktivist organizations. Rewards of up to $2 million are available for information on individuals linked to Cyber Army of Russia Reborn, and up to $10 million for information concerning individuals tied to NoName.

NoName057(16) was reportedly established in October 2018, according to the Department of Justice. In December 2025, multiple federal agencies and international partners issued a joint cybersecurity advisory highlighting the threats posed by pro-Russian hacktivist groups, including Cyber Army of Russia Reborn and NoName.

hacktivismarrestcybercrimerussiaspain
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.