Denis Zayev
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Denis Zayev, also known by the alias Denis Zayev, is a Russian hacker who was apprehended by the Federal Security Service in Stavropol in January 2018 following an investigation into a fraudulent scheme that targeted electronic fuel dispensing systems. His arrest came after authorities linked him to the development and deployment of malicious software that altered the readings of gas pumps and associated cash registers to inflate charges paid by customers. The actor operated primarily within the Russian Federation, with his activities concentrated in the southern regions of the country.
The threat actor’s typical targets were electronic gas stations that relied on computerized pump controllers and point‑of‑sale terminals, indicating a focus on the retail fuel sector within Southern Russia. His strategic objective appeared to be financial gain, as the malware was designed to siphon between three and seven percent of the dispensed fuel into concealed storage tanks while simultaneously presenting customers with accurate‑inflating the displayed price per gallon. The tooling described in open sources consists of a custom program that ran on both pump hardware and cash register systems, allowing the actor and complicit station operators to manipulate transaction data and divert fuel without triggering alerts at the dispenser. Initial access to the victim environments was facilitated through the cooperation of station operators who purchased and installed the malware, suggesting an insider‑enabled infection vector rather than exploitation of remote vulnerabilities.
The most notable campaign attributed to Denis Zayev unfolded across dozens of gas stations in the Stavropol Territory, Adygea, Krasnodar Territory, Kalmykia, and several republics of the North Caucasus, where the fraudulent software was deployed as part of a coordinated effort with station staff. Operators would leave storage tanks empty during a fraud cycle, allowing the malware to reroute a portion of each customer’s purchase into the vacant tank; once the tank refilled, the stolen fuel was sold openly to conceal the illicit transactions. The scheme resulted in customers being overcharged by a measurable margin per gallon while the actors profited from both the inflated sales and the resale of diverted fuel. Public reporting does not indicate any state sponsorship or affiliation with broader criminal consortia beyond the collaborative relationship with the participating gas station operators, and the actor’s activities appear to have been confined to this financially motivated operation.
Incidents
Attributed incidents are available to members.
1 incident