Italian hacker arrested in Palencia: worked for pro-Russian groups CARR and Z-Pentest
A 34-year-old Italian hacker has been arrested in Spain following a tip-off from the FBI. He allegedly worked for pro-Russian collectives CARR and Z-Pentest, perpetrators of hundreds of DDoS attacks in Italy.

Italian hacker detained in Palencia: the 34-year-old operated for the pro-Russian network
A 34-year-old Italian hacker has been arrested in Palencia, in central Spain, on suspicion of terrorist association, incitement to terrorism and computer fraud. As reported by Repubblica, the man had been hiding in Spain whilst working for two of the most well-known hacktivisit collectives in the pro-Russian constellation: CyberArmy of Russia Reborn (CARR) and Z-Pentest.
The name of the suspect has not been made public. The arrest took place last March, after Spanish police received a report from the US FBI.
His role in pro-Russian hacktivism
According to the charges, the 34-year-old was not simply an affiliate. American federal agents maintain that he was an active member of the collective, in constant contact with other members via encrypted messaging applications. He allegedly also helped coordinate the groups' actions and provide logistical support to their operations.
Investigators attribute to him an even more serious episode: the 34-year-old allegedly facilitated the escape of a Ukrainian hacker from CARR with pro-Russian sympathies, helping him leave Ukraine via Poland and Belarus to reach Russia.
Computers, IT devices, digital files and a cryptocurrency wallet, subsequently frozen, were seized from his residence in Palencia.
Hundreds of DDoS attacks against Italy
CARR and Z-Pentest are frequently involved in campaigns organised jointly with the collective NoName057(16). Their method of operation has always been the same: through software shared on Telegram channels, they built networks of zombie computers—so-called botnets—that saturated targeted institutional websites with requests, rendering them inaccessible for hours or even days.
Targets in Italy, from 2023 to 2025, have been numerous: websites of ministries and the Office of the Prime Minister, portals of ports and airports, platforms operated by the Carabinieri, Police, Financial Police, Army and Navy, as well as banks and local public transport companies. The hacker now detained in Palencia allegedly participated in these attacks as well.
The collectives describe themselves as hacktivists—political activists who use hacking as a tool of pressure—and deny being on the Kremlin's payroll. Investigators from several countries, however, remain sceptical, noting consistent alignment with the Russian propaganda machine.
In February 2025, following one of the attacks, the groups published a message on Telegram that read: "Italian cybersecurity remains a sieve! It is clear that funds allocated to cybersecurity defence are being diverted elsewhere," declaring themselves "in solidarity" with "reasonable Italian citizens outraged that their taxes are not being used to solve internal problems, but to finance the terrorist Zelensky."
The impact of DDoS attacks
Jonathan Ellison, director of the British National Cyber Security Centre (NCSC), had commented on the scope of these offensives during the latest campaign: "Although denial-of-service attacks can be technically simple, their impact can be significant. By overloading important websites and online systems, they can prevent people from accessing essential services they depend on every day."
International investigations
The Palencia arrest is part of a broader investigative framework involving the intelligence services of multiple countries. In 2025, Operation Eastwood—coordinated by the Rome Prosecutor's Office with the National Anti-Mafia and Anti-Terrorism Directorate and supported by Europol and Eurojust—had already led to searches and arrests in Italy.
In 2024, meanwhile, US authorities had identified Yuliya Vladimirovna Pankratova as leader of CARR and Denis Olegovich Degtyarenko as its principal hacker. The investigation into the Italian hacker detained in Spain represents one of the most recent results of this transnational investigative activity, which aims to dismantle the network of collectives linked to pro-Russian hacktivism.
Source: la Repubblica