Domain Systems
Back to Insights
Article
December 13, 2025

The Dubranova Cyber Campaign: Russian-Linked Breaches Against Critical Infrastructure

S
By Sudon't • 12 min read
Cyber Crime
Critical Infrastructure
SCADA

An analysis of the federal indictments against Victoria Eduardovna Dubranova, revealing the operational anatomy of Russian state-linked cyberattacks against U.S. critical infrastructure, including SCADA intrusions, DDoS campaigns, and the tools and methods used by CyberArmyofRussia_Reborn and NoName057.

The Dubranova Cyber Campaign: Russian-Linked Breaches Against Critical Infrastructure

This article breaks down the federal indictments against Victoria Eduardovna Dubranova, a 33-year-old Ukrainian national extradited to the United States on charges of facilitating cyberattacks in support of Russian state-linked hacking groups. It walks through the operational details described in the court filings: the tools, methods, and objectives behind a major series of breaches of U.S. critical infrastructure.

The core of this story lies in two distinct but interconnected operations: CyberArmyofRussia_Reborn (CARR) and NoName057(16), cyber units backed, directed, and sustained by Russian military and intelligence apparatuses, according to U.S. prosecutors and the Department of Justice.


Who Is Victoria Dubranova?

Victoria Eduardovna Dubranova, 33-year-old Ukrainian national extradited to the United States on charges of facilitating cyberattacksVictoria Eduardovna Dubranova, 33-year-old Ukrainian national extradited to the United States on charges of facilitating cyberattacks

Victoria "Vika" Dubranova is accused of serving as a coordinator, propagandist, and operational facilitator for two Russian-aligned cyber collectives. Dubranova's role was not peripheral: she allegedly tracked, selected, and researched targets; advised co-conspirators on attack timing and method; produced and disseminated propaganda videos claiming responsibility for successful incursions; and coordinated teams inside encrypted channels.

These indictments attribute to her direct involvement in attacks spanning from denial-of-service (DDoS) campaigns against government and infrastructure websites to indirect interference with industrial control systems governing water and food supply facilities.


The Two Groups at the Core

CyberArmyofRussia_Reborn (CARR)

More than a hacktivist group, CARR was a cyber organization that, prosecutors allege, was founded, funded, and directed by the GRU, Russia's main military intelligence directorate.

CARR’s operations reflected an emerging doctrine blending political provocation with digital disruption. According to the indictment:

  • Distributed denial of service (DDoS) attacks were routine tools, flooding victim infrastructure with network traffic to force outages.
  • The group allegedly engaged in SCADA intrusions into public utility systems, tampering with industrial control components that regulate water pumps, storage tanks, and environmental settings.
  • Dubranova and others compiled, edited, and posted video content of their actions on public Telegram channels, sometimes explicitly linking outcomes (such as spoiled food or spilled water) to the group’s exploits.

This was no amateur operation. The organizational structure incorporated handlers, coordinators, recruiters, and propagandists. At times, CARR reportedly had over 100 identified members and broadcast channels followed by tens of thousands.

State-Backed Operations: According to U.S. prosecutors, CARR was not merely a hacktivist group but a cyber organization founded, funded, and directed by the GRU, Russia's main military intelligence directorate. This represents a significant escalation in the blurring of lines between state and non-state cyber actors.

NoName057(16)

NoName emerged as a secondary, hacktivist-leaning collective that specialized in DDoS campaigns. It used a proprietary tool known as DDoSia, which, unlike simple rented "stresser" services, enabled coordinated, high-volume traffic bursts against diverse targets.

Key attributes of NoName included:

  • More than 1,500 DDoS attacks attributed to the group, targeting NATO member states and critical services.
  • An open recruitment strategy, incentivizing volunteers globally with leaderboards and cryptocurrency rewards.
  • Infrastructure supported by elements of the Russian information technology organization CISM, linking volunteers and resources into a broader state-aligned campaign.

Dubranova is charged with providing support to both CARR and NoName in separate indictments. In the NoName matter, she faces charges of conspiracy to damage protected computers, a count carrying up to five years imprisonment if convicted.


Anatomy of the Attacks

Target Reconnaissance and Selection

The indictment enumerates dozens of specific overt acts revealing how targets were selected. For example, the court documents detail:

UNITED STATES DISTRICT COURT FOR THE EASTERN DISTRICT OF VIRGINIA
OVERT ACTS

In furtherance of the conspiracy and to effect its illegal objects, the following overt acts, among others, were committed in the Eastern District of Virginia and elsewhere:

On or about  , DUBRANOVA researched and identified websites belonging to U.S. government entities, including the Nuclear Regulatory Commission, the Department of Defense, and state election systems, for potential distributed denial-of-service attacks.

On or about  , DUBRANOVA instructed co-conspirators to identify and compile lists of DDoS targets, including airports, foreign government portals, academic institutions, and critical infrastructure facilities located in the United States, Japan, Belgium, and Moldova.

On or about  , DUBRANOVA coordinated with other members of the conspiracy to select specific targets based on their perceived strategic value and potential for maximum disruption to essential services.

These overt acts demonstrate the systematic nature of the target selection process. The indictment reveals that Dubranova and her associates didn't simply launch random attacks, but rather engaged in deliberate reconnaissance and strategic planning. The documents show that targets included:

  • U.S. government entities, including nuclear regulators, the Department of Defense, and election systems
  • Airports, foreign government portals, academic institutions, and even blood donation organizations
  • Critical infrastructure facilities across multiple countries, with DDoS targets identified as far afield as Japan, Belgium, and Moldova

DDoS and SCADA Manipulation Tools

Two principal methods emerged.

Killweb and DDoSia

The indictment revealed internal development and deployment of:

  • Killweb, a custom DDoS script developed for CARR.
  • DDoSia, a tool widely used by NoName to orchestrate global high-volume attacks.

These tools were more sophisticated than off-the-shelf stressers and at times required coordination across multiple nodes to generate saturation. Traffic signatures included both Layer 4 (transport level) and Layer 7 (application level) attack vectors.

Industrial Control System Intrusions

In at least two cases, CARR operatives compromised SCADA systems:

  • A public water system in Texas, where altered set points caused massive water overflows.
  • A Dutch children’s water park, where temperature and chlorination controls were tampered with.

These attacks shifted beyond simple outages, demonstrating a capability to manipulate physical infrastructure through logical breaches.

Critical Infrastructure at Risk: The SCADA intrusions into public water systems represent a dangerous precedent. Unlike traditional cyberattacks that target data, these operations demonstrated the ability to cause physical damage and disrupt essential services that millions depend on daily.

Propaganda and Recruitment

The technical attacks were amplified by coordinated media and messaging operations designed to maximize psychological impact and operational reach:

  • Dubranova created and edited videos showing "proof of compromise," often exaggerating effects to attract new participants and donors.
  • Public Telegram channels served as recruitment hubs, amplifying claims of operational success and mobilizing wider support.

This dual approach, combining actual cyberattacks with strategic information operations, enabled these groups to project influence far beyond their technical capabilities, turning individual breaches into broader campaigns of disruption and intimidation.


Real-World Impact

The consequences of these campaigns were tangible and immediate:

  • Public water systems in multiple U.S. states lost control of operational settings, causing large losses of drinking water and potential contamination risks.
  • A meat processing facility in Los Angeles suffered a refrigeration failure that spoiled thousands of pounds of product and caused an ammonia leak, forcing evacuation of workers and nearby residents.
  • Election-related services were targeted with planned DDoS activity in the run-up to U.S. elections, threatening the integrity of democratic processes.

The indictment suggests these effects were not collateral but strategic, aiming to degrade public confidence and disrupt essential services. The attacks demonstrated that cyber operations could extend beyond digital disruption to cause physical harm and economic damage.


Legal and National Security Implications

Charges and Potential Sentence: Dubranova faces multiple counts including conspiracy to damage protected computers, tampering with public water systems, access device fraud, and aggravated identity theft. Collectively, these charges could bring a sentence exceeding 27 years if convictions are secured.

The U.S. State Department has also offered rewards for information leading to members of these groups: up to $2 million for CARR and $10 million for NoName operatives, a signal of how seriously these campaigns are taken at the highest levels of national security.


Conclusion

The Dubranova indictments reveal a chilling evolution in cyber conflict: state-aligned groups that combine traditional intrusion tactics, industrial control exploitation, and sophisticated propaganda strategies. What was once dismissed by defenders as unsophisticated hacktivism now looks like a coordinated auxiliary of state power, blurring the line between civilian actors and intelligence-backed cyber operators.

Looking Ahead: As these cases proceed to trial in 2026, defenders, policymakers, and infrastructure operators worldwide will be watching closely: not just for the verdict, but for the lessons this campaign teaches about defending modern society's most vulnerable digital and physical systems. The integration of hardware-enforced network segmentation, such as data diodes, becomes increasingly critical in protecting industrial control systems from similar attacks.


This article is based on publicly available court documents and reporting as of December 2025. All technical details are drawn from the indictment and government releases.

References