CyberArmy of Russia Reborn
MITRE G1049Also known as Cyber Army of Russia Reborn, CyberArmyofRussia_Reborn, CARR, Z-Pentest
Reports
6
First seen
Jan 5, 2026
Last seen
Aug 10, 2026
Motivation
Hacktivism, Geopolitical, Sabotage
Targeting
Victim regions
Ukraine ×1
Top ATT&CK techniques
T1190 Exploit Public-Facing Application ×3T1566 Phishing ×2T1078 Valid Accounts ×2T1498 Network Denial of Service ×2T1486 Data Encrypted for Impact ×2T1047 Windows Management Instrumentation ×2T1133 External Remote Services ×2T1059 Command and Scripting Interpreter ×2T1003 OS Credential Dumping ×1T1589 Gather Victim Identity Information ×1T1046 Network Service Discovery ×1T1490 Inhibit System Recovery ×1
Indicators
cve ×13domain ×1filename ×1
Indicator values are available on Pro and via the API.
Associated CVEs
CVE-2020-12812 (exploited)CVE-2024-42009 (exploited)CVE-2025-14174 (exploited)CVE-2025-43529 (exploited)CVE-2025-55182 (exploited)CVE-2025-5777 (exploited)CVE-2025-59718 (exploited)CVE-2025-59719 (exploited)CVE-2026-15409 (exploited)CVE-2026-15410 (exploited)CVE-2026-25089 (exploited)CVE-2026-39808 (exploited)CVE-2026-48294
Recent reports
High