22 July 2024

Spain, the US strike pro-Russian hacktivists for attacks on critical infrastructure


Spain, the US strike pro-Russian hacktivists for attacks on critical infrastructure

Spanish police have arrested three individuals allegedly linked to a pro-Russian hacking collective known as NoName057(16) targeting Spain and other NATO countries that have supported Ukraine in its fight against the Russian invasion.

The arrests took place in Mallorca, Huelva, and Seville. The three were detained on suspicion of participating in denial-of-service (DDoS) attacks aiming to disrupt web pages of public and private organizations in the government sectors, critical infrastructures and essential services. The group has used a custom DDoS service named “DDoSia” to conduct the attacks.

The police didn’t name the arrested individuals, nor it said whether they were charged. The investigation is ongoing.

In the meantime, the US authorities sanctioned Yuliya Vladimirovna Pankratova and Denis Olegovich Degtyarenko, members of the Russian hacktivist group Cyber Army of Russia Reborn (CARR), for their involvement in cyber operations against US critical infrastructure.

Pankratova leads CARR and acts as its spokesperson, while Degtyarenko, known online as Dena, is a primary hacker. Since 2022, CARR has carried out low-impact DDoS attacks in Ukraine and against entities supporting Ukraine. In late 2023, CARR claimed attacks on industrial control systems of critical infrastructure in the US and Europe, targeting water supply, hydroelectric, wastewater, and energy facilities using unsophisticated techniques.

Degtyarenko was responsible for compromising the SCADA system of a US energy company and, in May 2024, developed training materials on SCADA system compromise, potentially for distribution to other groups.


Back to the list

Latest Posts

Cyber Security Week in Review: September 6, 2024

Cyber Security Week in Review: September 6, 2024

In brief: the US charges Russian GRU hackers for attacks on Ukraine, Apache, Cisco, Zyxel patch high-risk flaws, Google fixes Android zero-day, and more.
6 September 2024
Threat actors using MacroPack Red Team framework to deploy Brute Ratel, Havoc and PhantomCore

Threat actors using MacroPack Red Team framework to deploy Brute Ratel, Havoc and PhantomCore

Some of the documents appeared to be part of legitimate Red Team exercises, while other were intended for malicious purposes.
5 September 2024
US seizes 32 domains linked to Russian Doppelganger influence campaign

US seizes 32 domains linked to Russian Doppelganger influence campaign

The domains, used to disseminate propaganda, were seized as part of a broader effort to disrupt Russia’s attempts to interfere in the 2024 US Presidential Election.
5 September 2024