Executive Summary
In July 2026, Spanish authorities, in collaboration with the FBI, arrested a suspected core member of pro-Russian hacktivist groups CyberArmy of Russia Reborn (CARR) and Z-Pentest in Palencia, Spain. The individual is accused of providing logistical support to a Ukrainian hacker affiliated with CARR and attempting to facilitate their escape to Russia. The suspect is also linked to coordinating cyber operations for the NoName057(16) group using encrypted messaging platforms. Seized items include multiple computers and frozen cryptocurrency wallets allegedly used to launder proceeds from stolen data sales. The suspect faces ongoing investigations for collaboration with a recognized terrorist organization and severe computer damage. (es.euronews.com)
This arrest underscores the persistent threat posed by hacktivist groups targeting critical infrastructure across the United States and Europe. The incident highlights the importance of international cooperation in combating cybercrime and the need for organizations to bolster their cybersecurity defenses against such multifaceted threats.
Why This Matters Now
The arrest of a key member of pro-Russian hacktivist groups targeting critical infrastructure emphasizes the ongoing risk these actors pose. Organizations must remain vigilant and enhance their cybersecurity measures to protect against such threats.
Attack Path Analysis
Attackers utilized the Forg365 phishing-as-a-service platform to craft AI-generated phishing emails, leading victims to enter device codes on legitimate Microsoft login pages. This granted attackers OAuth tokens, allowing them to bypass multi-factor authentication and gain unauthorized access to Microsoft 365 accounts. Subsequently, they installed the ForgCookie browser extension to maintain persistent access, enabling lateral movement within the victim's environment. The attackers established command and control by leveraging the compromised accounts to send further phishing emails, expanding their reach. They exfiltrated sensitive data stored in Microsoft 365 services such as Outlook and OneDrive. Finally, the attackers potentially disrupted operations by modifying or deleting critical data, impacting business continuity.
Kill Chain Progression
Initial Compromise
Description
Attackers used Forg365 to send AI-generated phishing emails, tricking victims into entering device codes on legitimate Microsoft login pages, thereby obtaining OAuth tokens.
MITRE ATT&CK® Techniques
Active Scanning: Vulnerability Scanning
Remote Services: VNC
Brute Force: Password Spraying
Valid Accounts
Command-Line Interface
Screen Capture
Remote Services
Exploitation of Remote Services
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 – Account Management
Control ID: AC-2
PCI DSS 4.0 – Strong Authentication for Users and Administrators
Control ID: 8.2.3
NYDFS 23 NYCRR 500 – Access Privileges
Control ID: 500.07
DORA – ICT Risk Management Framework
Control ID: Article 6
CISA ZTMM 2.0 – Identity
Control ID: Pillar 1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Law Enforcement
Direct targeting of Pakistani law enforcement networks by nation-state actors demonstrates critical infrastructure vulnerability to multi-vector espionage campaigns affecting operational security.
Government Administration
State-sponsored intrusions into government systems highlight exposure to hacktivist groups and phishing-as-a-service operations compromising sensitive administrative data and communications.
Financial Services
Business email compromise and investment fraud operations seized $293 million in assets, demonstrating sector vulnerability to social engineering and money laundering schemes.
Information Technology/IT
Microsoft 365 targeting via Forg365 PhaaS platform affects IT infrastructure through OAuth exploitation, requiring enhanced east-west traffic security and zero trust segmentation.
Sources
- The Good, the Bad and the Ugly in Cybersecurity – Week 28https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-28-8/Verified
- New Forg365 phishing platform uses AI to target Microsoft 365 accountshttps://www.bleepingcomputer.com/news/security/new-forg365-phishing-platform-uses-ai-to-target-microsoft-365-accounts/Verified
- China, India-linked hacking groups targeted Pakistani law enforcement, report sayshttps://www.investing.com/news/world-news/china-indialinked-hacking-groups-targeted-pakistani-law-enforcement-report-says-4784204Verified
- Microsoft seizes 338 websites to disrupt rapidly growing ‘RaccoonO365’ phishing servicehttps://blogs.microsoft.com/on-the-issues/2025/09/16/microsoft-seizes-338-websites-to-disrupt-rapidly-growing-raccoono365-phishing-service/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it likely limits unauthorized lateral movement and data exfiltration by enforcing strict workload segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF may not prevent initial credential compromise, it would likely limit the attacker's ability to exploit these credentials within the cloud environment.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges by enforcing strict access controls and segmenting workloads.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely limit lateral movement by enforcing strict segmentation and monitoring east-west traffic.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely limit the attacker's ability to establish command and control by monitoring and controlling outbound communications.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely limit data exfiltration by controlling and monitoring outbound data flows.
While Aviatrix CNSF may not prevent data modification or deletion, it would likely limit the attacker's ability to access critical systems, reducing the potential impact.
Impact at a Glance
Affected Business Functions
- Email Communications
- Document Management
- Collaboration Tools
Estimated downtime: 3 days
Estimated loss: $50,000
Unauthorized access to sensitive emails, documents, and internal communications.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Enforce Egress Security & Policy Enforcement to monitor and control outbound traffic.
- • Utilize Threat Detection & Anomaly Response to identify and respond to suspicious activities.
- • Deploy Inline IPS (Suricata) to detect and prevent known exploit patterns.
- • Adopt Cloud Native Security Fabric (CNSF) for real-time inspection and enforcement of security policies.



