The hacktivist who helped a hacker flee: inside Spain's arrest of a pro-Russia network operative- 286
July 8, 2026
Spanish police have arrested a man in the central city of Palencia they believe was embedded in the operational core of at least two pro-Russia hacktivist groups already flagged by Western governments as threats to critical national infrastructure — and the case reveals these groups function less like loose online collectives and more like a coordinated network capable of helping members physically escape prosecution across international borders.
The man is suspected of close ties to CyberArmy of Russia Reborn, known as CARR, and to a second group called Z-Pentest, and may also have carried out operations on behalf of a third, NoName057(16). All three were specifically named earlier this year in a UK National Cyber Security Centre advisory warning that Western critical infrastructure should not underestimate these groups, despite them being best known for relatively unsophisticated denial-of-service attacks — the NCSC's director of national resilience noted that even technically simple attacks can meaningfully disrupt the essential services people depend on daily. A month before that advisory, US officials separately stated that CARR was working with, or taking instructions from, Russia's military intelligence service, the GRU.
The arrest itself took place back in March, though Spanish police only announced it publicly this week, following a tip from the FBI in August 2025. That tip concerned something beyond ordinary hacking: the man allegedly provided logistical and support cover to help a Ukrainian hacker — a fellow CARR member — flee to Russia by routing through Poland and Belarus. Following his arrest, investigators found evidence he remained in close contact with other members across these groups, coordinating actions and providing support for their activities, including those of NoName057(16), which has operated since at least 2022 targeting NATO countries and organizations whose interests conflict with Russia's. Police seized computer equipment and cryptocurrency storage devices from his home and froze a wallet suspected of holding cybercrime proceeds.

The arrest sits inside a broader FBI effort called Operation Red Circus, launched last December specifically to disrupt Russian state-sponsored cyber threats to the US and its interests abroad, with arresting individual hacktivist-group members as one of its stated mission priorities. That pursuit has already produced results against CARR specifically: the US named Yuliya Vladimirovna Pankratova as the group's leader and Denis Olegovich Degtyarenko as its primary hacker back in 2024, sanctioning both after CARR was tied to attacks on US and European water facilities that specifically targeted the human-machine interfaces controlling water supply, hydroelectric, wastewater, and energy systems. In one case, CARR gained direct access to the SCADA control system of a US energy company, giving them the ability to manipulate alarms and pumps connected to storage tanks. Those same attacks were previously attributed by Mandiant to Sandworm, a cyber unit operating inside the GRU itself — meaning the sanctions against CARR's named leadership add real texture to just how tightly Russia's military and its ostensibly independent hacktivist community actually overlap.
The human cost of this network's prior activity is already on the record elsewhere. Victoria Eduardovna Dubranova, a 33-year-old pro-Russia Ukrainian hacktivist, was extradited to the US late last year on charges tied to attacks carried out by CARR and NoName057(16), including one against a Los Angeles meat processing facility in November 2024 that spoiled thousands of pounds of meat and triggered an on-site ammonia leak — a concrete reminder that behind the DDoS headlines, this same hacktivist ecosystem has already reached into physical industrial systems with real consequences.
