LIVE · cybersecurity feed
Live wire
arrest

Spain arrests suspected member of pro-Russian hacktivist groups

Spanish authorities have arrested an individual suspected of active membership in pro-Russian hacktivist groups, reportedly including CyberArmy of Russia Reborn and Z-Pentest.

zeroday.news · 25d ago

Spain's National Police have arrested an individual suspected of involvement with pro-Russian hacktivist organizations, including CyberArmy of Russia Reborn (CARR) and Z-Pentest. The suspect, who resided in Palencia, is alleged to have provided logistical and operational support to a Ukrainian hacker operating for CARR.

While hacktivism is often characterized by politically or ideologically motivated cyberattacks, CARR and Z-Pentest have been linked to attacks that posed risks to critical infrastructure in the United States and Europe. Previous indictments and sanctions against other alleged members of CARR have connected the group to cyberattacks targeting water and food-processing facilities, as well as SCADA systems of an American energy firm. CARR has also been loosely associated with the Russian state-backed threat group APT44, also known as Sandworm, which is known to disguise its activities behind hacktivist collectives.

According to Spanish police, the arrested individual facilitated a hacker's attempted escape to Russia via Poland and Belarus. The suspect reportedly used encrypted messaging applications to communicate with other members of these groups, coordinating activities and providing operational support. Investigators also believe the suspect participated in operations attributed to the hacktivist group NoName057(16), which later claimed responsibility for these actions on websites promoting pro-Russian and anti-Western narratives.

The investigation was initiated in August 2025 following information provided by the FBI. In March 2026, authorities executed a search of the suspect's home in Palencia, seizing computers and cryptocurrency storage devices for use in the ongoing investigation. Cryptocurrency wallets believed to have been used for receiving proceeds from the sale of stolen data were also frozen.

The suspect is currently under investigation and has not been formally charged. However, police are looking into potential offenses including membership in and collaboration with a terrorist organization, glorification of terrorism, and computer damage.

arresthacktivismrussialaw enforcement
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]