Actor de amenaza individual

Yuliya Vladimirovna Pankratova

Yuliya Vladimirovna Pankratova is a Russian cyber actor publicly identified by U.S. and European authorities as a senior operator in the pro-Russian hacktivist ecosystem. The U.S. Department of the Treasury identified her in July 2024 as the leader of Cyber Army of Russia Reborn (CARR), stating that she commands and controls the group’s operations and has acted as its spokesperson. In July 2026, the European Union further described Pankratova as a Russian hacker who worked for CARR, founded Z-Pentest, continues to work for Z-Pentest, and acts as a primary hacker for both CARR and Z-Pentest.

Public and private-source correlation provides a stronger alias picture than the older profile. Trellix publicly connected the CARR administrator MotherOfBears to Pankratova. A restricted actor-controlled source separately states that JuliaRCAT and MotherOfBears are the same persona. The historical X handle @[redacted] publicly presented itself as the press secretary of the Z-Pentest project and, as of 2026-08-12, the same account path resolves to a profile displaying @[redacted].

INFERENCE (confidence: high): the combined official, vendor and restricted-source record supports treating JuliaRCAT, MotherOfBears, YUliYA and Yuliya Vladimirovna Pankratova as a single persona for 3C-INT correlation purposes.

The available evidence also clarifies organizational continuity. Public reporting places Z-Pentest’s observable emergence in September 2024, while a restricted actor-controlled source dates its founding to 2024-09-28 and describes the founding as having occurred during an in-person gathering in a luxury hotel in Moscow. Official EU material later characterized Z-Pentest as containing members originating from CARR and NoName057(16). This supports a model of Z-Pentest as a later structure with direct human continuity from CARR rather than a simple alias replacement.

Pankratova’s profile is strategically important because she represents an identifiable human bridge across leadership, public communications and operationally relevant group structures. Her documented role increases confidence in relationship and command-level attribution, but it does not justify assigning every CARR or Z-Pentest intrusion technique to her personally. Technical attribution remains behavior- and artifact-dependent.

Creado por iQBlack CTI Team
Colaboradores 1
Última actualización 2026-08-18

ATT&CK

MITRE ATT&CK

T1021.005VNC
T1078.001Default Accounts
T1110.001Password Guessing
T1491.002External Defacement
T1498Network Denial of Service
T1565.003Runtime Data Manipulation
T1595.002Vulnerability Scanning

Research

OSINT seleccionado