Threat Actor Characterization
Degtyarenko
ID: bc0dc0b7ded7bd81aef1307a1d7350af78029| Dena | Denis Olegovich Degtyarenko | Де*********************** | — |
Actor Network Graph
Open Network GraphMITRE ATT&CK®
Denis Olegovich Degtyarenko (“Dena”) is the primary hacker of the pro-Russia hacktivist group Cyber Army of Russia Reborn (aka People’s Cyber Army). Sanctioned on 2024-07-19, he is linked by OFAC to DDoS operations and to manipulation of HMI/SCADA at U.S./European critical infrastructure, including a U.S. energy SCADA compromise.
| Technique | Technique name | Tactics | Evidence |
|---|---|---|---|
| T1498 | Network Denial of Service | TA0040 |
|
| T0831 | Manipulation of Control | TA0105 |
|
| T0858 | Change Operating Mode | TA0103 TA0104 |
|
CLASSIFICATION: Unclassified / Open Source
Executive Summary
Denis Olegovich Degtyarenko (DOB 1989-10-09), also known online as “Dena,” is publicly identified by the U.S. Department of the Treasury (OFAC) as the primary hacker of the pro-Russia hacktivist group Cyber Army of Russia Reborn (CARR), also called Cyber Army of Russia and widely referred to in Russian as “Narodnaya CyberArmiya” / People’s Cyber Army. On 2024-07-19, OFAC sanctioned Degtyarenko and CARR’s leader Yuliya Vladimirovna Pankratova, citing activity against U.S. and European critical infrastructure, including DDoS and manipulations of industrial control systems (ICS) at water, hydroelectric, wastewater, and energy facilities. OFAC states Degtyarenko was “behind the compromise of the SCADA system of a U.S. energy company” and in early May 2024 developed training materials for compromising SCADA, potentially to share with external groups. Overall confidence in these core facts: high.
- Industries/Sectors: Water and wastewater; Hydroelectric; Energy (including electric utilities); broader critical infrastructure.
- Geography (Region): United States and Europe (claims and incidents noted by OFAC); wider focus aligned with pro-Russia operations since 2022.
- Countries (if available): United States; multiple European countries (per OFAC summary).
- Timeframe: 2022–2025 (group activity since 2022; sanctions 2024-07-19; continued open-source coverage through 2025).