Security1 distinct publisher3 min readUpdated
The 36th round since March 2022 pulls named CARR hackers, an alleged bulletproof hosting operator and a GRU unit commander into New Zealand law, and into NZ screening files.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
New Zealand has designated 33 Russian, DPRK and Iranian individuals and entities over support for Russia's war against Ukraine, with explicit emphasis on cyber actors, on people linked to the forced relocation and re-education of Ukrainian children, and on entities supporting the Russian military-industrial complex [1][2][3]. Two of the names are Cyber Army of Russia Reborn operators the US Treasury sanctioned in 2024, so for anyone with New Zealand exposure the question is no longer whether these people are listed somewhere but whether your screening feed reads the New Zealand list at all [5].
According to US officials, Yuliya Pankratova, who uses the alias "YUliYA", led CARR, and Denis Degtyarenko, known as "Dena", was one of its primary hackers [6]. American officials alleged Degtyarenko compromised an industrial control system at a US energy company and developed training material for compromising SCADA systems [7]. Pankratova has also been associated with Z-Pentest, another pro-Russian group accused of targeting critical infrastructure [8].
New Zealand also designated Aleksandr Volosovik, known online as "Yalishanda", whom US prosecutors accuse of helping operate Media Land, a Russian bulletproof hosting provider allegedly used by criminals against hospitals, schools and banks [9]. In July the US Justice Department unsealed charges against Volosovik and two other Russian nationals, alleging activity that caused more than $62 million in losses to victims in the United States and elsewhere [10].
The package includes Andrey Averyanov, a senior Russian military intelligence officer who previously commanded GRU Unit 29155 [11]. Western governments have tied that unit to cyberattacks, sabotage and covert operations, and its cyber division has been accused of targeting governments, defence organisations and think tanks in Ukraine and NATO countries [12]. New Zealand had already sanctioned members of the unit [13].
On the information side, the Internet Development Institute and its director Alexey Goreslavsky were designated; the institute finances digital media and content promoting Russian state narratives [14]. The British government has said IRI was established by Russia's presidential administration, received hundreds of millions of dollars in state funding, and backed films and video games carrying Kremlin-aligned narratives [15]. The IT services firm LANIT, already sanctioned by the United States, Canada and Ukraine, was added over work for Russia's Defence Ministry and sanctioned defence companies including Rostec [16].
The mechanics matter more than the headcount. This is the 36th round under the Russia Sanctions Act, which took effect in March 2022, and New Zealand has now listed more than 2,000 Russian individuals, entities and vessels [17][18]. The 33 new names are roughly 1.6 percent of that total [21]. Measures generally mean asset freezes, travel bans, and a prohibition on New Zealanders making funds or other assets available to designated parties [19]. That prohibition is the operative clause: an extortion payment, a hosting invoice or a reseller settlement that lands with a designated CARR operator or with Media Land is now a New Zealand legal problem, not just a reputational one [22]. At least three of these designations duplicate existing US, Canadian or Ukrainian listings, which makes this alignment rather than fresh attribution [23].
Foreign Minister Winston Peters said cyber activity has real-world consequences and that cyber actors are increasingly used to gather intelligence and enable sanctions evasion [20]. On the child-relocation element he said children should never be used as instruments of war [4].
Watch how quickly the 33 names propagate into commercial screening data, and whether NZ-facing subsidiaries treat the list as in scope rather than deferring to a US-only feed.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
New Zealand announced a new round of sanctions targeting 33 individuals and entities accused of supporting Moscow's war against Ukraine.
The package places particular focus on cyber actors, individuals linked to the forced relocation and re-education of Ukrainian children, and entities supporting Russia's military-industrial complex.
Foreign Minister Winston Peters said the package also targets individuals involved in creating and spreading anti-Ukraine propaganda, as well as actors from the DPRK and Iran providing support to Moscow.
Peters said: "Children should never be used as instruments of war," expressing concern over efforts to abduct and re-educate Ukrainian children through state-directed programmes.
Yuliya Pankratova and Denis Degtyarenko are members of the pro-Russian hacktivist group Cyber Army of Russia Reborn (CARR); the US Treasury sanctioned both in 2024 over alleged cyber operations targeting US critical infrastructure.
US officials identified Pankratova, who uses the alias "YUliYA", as CARR's leader, and described Degtyarenko, known as "Dena", as one of its primary hackers.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single trade-press relay of an official announcement, specific but uncorroborated
Claims are specific - named designees, aliases, a $62 million DOJ loss figure, round and cumulative counts - and the reporting consistently attributes underlying allegations to US officials, prosecutors and the British government. But the cluster contains exactly one source, no primary New Zealand instrument or ministerial release is cited in the supplied material, the full list of 33 is not published, and one link (Pankratova to Z-Pentest) is stated only in hedged, unattributed terms.
Designations in force and aligned with allied lists; enforcement effect unobserved
This is regulatory rather than technology adoption, and it is concretely evidenced: the designations take legal effect in New Zealand as asset freezes, travel bans and a funds-availability prohibition, they sit within a sustained 36-round programme covering more than 2,000 parties, and at least three names replicate existing US, Canadian and Ukrainian listings. What is not observed is downstream uptake - no enforcement actions, screening-system updates, financial-institution responses or measured effect on the designated parties appear in the supplied material.
Mildly overstated novelty, accurate on mechanics
The reporting is descriptive and avoids inflated language about impact, but framing the round around headline cyber names understates how incremental it is: the 33 additions are roughly 1.6 percent of New Zealand's cumulative total, and at least three of them - the two CARR operators and LANIT - were already designated by the United States, Canada or Ukraine, making this largely alignment with allied lists rather than new attribution. No claim of measured disruption to the named actors is made or supported, so the gap is small and positive rather than large.
Government announcement pipeline with ministerial framing; no commercial interest visible
The factual spine is a state sanctions announcement carried with ministerial quotation, so the primary actor has a clear interest in projecting resolve and alignment with allies - visible in the emphasis on Ukrainian children, propaganda and DPRK/Iran involvement. The publisher is a cybersecurity trade outlet with an audience-building interest in named threat actors, but no vendor sponsorship, product promotion or investment position is evident in the supplied material, and the underlying allegations are attributed to third-party authorities rather than the announcing government alone.
Consistent and specific, but one publisher and no primary documents
Internal consistency is high and the specifics (aliases, dates, monetary figure, round count) are checkable in principle, and several elements are corroborated by reference to prior US, Canadian, Ukrainian and British actions. Confidence is held below high because the cluster has a single publisher, the primary designation instrument is not cited, the DOJ charge date is given only as 'July' without a year, and no independent verification of the 33-name list is available in the supplied material.
security
Bulletproof hosting got smaller, not scarcer: what fragmentation costs your blocklist1 distinct publisher
invest
A 2022 oracle hack starts moving again, three days after Pando shut its books1 distinct publisher
invest
Bitcoin's $72,000 Break Was Mostly Forced Covering, Not Fresh Bids1 distinct publisher
invest
The ballroom case is really about whether the executive can spend without Congress1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 10, 2026