News
Print Article

Evil Corp cybercriminals unmasked and sanctioned.

03/10/2024

Further Evil Corp cybercriminals were exposed following the NCA investigation, one of whom was unmasked as a LockBit affiliate, as the UK, US, and Australia unveiled sanctions.

Who are they?

  • Evil Corp (OR Indrik Spider) originated in Russia and is the most pervasive cybercrime group to have operated. Maksim Yakubets, who also goes by the online alias ‘Aqua’ and has a $5 million bounty for his arrest, was Evil Corp’s founder and led the group for most of its lifespan.
  • One of the first significant financial cybercrime groups, Evil Corp developed a series of malware and ransomware strains which have caused considerable harm to numerous organisations and sectors, including healthcare, critical national infrastructure and government.
  • Several law enforcement and government operations have taken place to disrupt the group since its formation, most notably in the form of sanctions and indictments in December 2019. As a result, the group has been forced to scrap its modus operandi and attempt new tactics to evade the additional scrutiny and restrictions put on it.
  • Evil Corp, characterised by its longevity, adaptability, organisational hierarchy, and close links with the Russian state, has proved a persistent threat for over a decade. Members continue to operate within the Russian Federation. However, since late 2019, their success and influence in the cybercrime ecosystem have dwindled.

SANCTIONS

  • 16 members of Evil Corp, once believed to be the most significant cybercrime threat in the world, have been sanctioned in the UK.
  • Their links to the Russian state and other ransomware groups, including LockBit, have been exposed. Australia and the we have also imposed sanctions.
  • An extensive investigation by the NCA has helped map out the history and reach of Evil Corp’s criminality, from a family-centred financial crime group in Moscow that branched out into cybercrime, going on to extort at least $300 million from victims globally.
  • Today, the head of Evil Corp, Maksim Yakubets and eight of those sanctioned by the US in 2019 have also been sanctioned in the UK by the Foreign, Commonwealth and Development Office, along with an additional seven individuals whose links and support for the group have not previously been exposed.
  • This includes Aleksandr Ryzhenkov, Yakubets’ right-hand man, who has also been identified as a LockBit affiliate as part of Operation Cronos - the ongoing NCA-led international disruption of the group.

Read the full story ➡️ https://www.nationalcrimeagency.gov.uk/news/further-evil-corp-cyber-criminals-exposed-one-unmasked-as-lockbit-affiliate.

 

 

YOUTUBE-IMAGE UNITED KINGDOM SANCTIONS

The Team

Meet the team of industry experts behind Comsure

Find out more

Latest News

Keep up to date with the very latest news from Comsure

Find out more

Gallery

View our latest imagery from our news and work

Find out more

Contact

Think we can help you and your business? Chat to us today

Get In Touch

News Disclaimer

As well as owning and publishing Comsure's copyrighted works, Comsure wishes to use the copyright-protected works of others. To do so, Comsure is applying for exemptions in the UK copyright law. There are certain very specific situations where Comsure is permitted to do so without seeking permission from the owner. These exemptions are in the copyright sections of the Copyright, Designs and Patents Act 1988 (as amended)[www.gov.UK/government/publications/copyright-acts-and-related-laws]. Many situations allow for Comsure to apply for exemptions. These include 1] Non-commercial research and private study, 2] Criticism, review and reporting of current events, 3] the copying of works in any medium as long as the use is to illustrate a point. 4] no posting is for commercial purposes [payment]. (for a full list of exemptions, please read here www.gov.uk/guidance/exceptions-to-copyright]. Concerning the exceptions, Comsure will acknowledge the work of the source author by providing a link to the source material. Comsure claims no ownership of non-Comsure content. The non-Comsure articles posted on the Comsure website are deemed important, relevant, and newsworthy to a Comsure audience (e.g. regulated financial services and professional firms [DNFSBs]). Comsure does not wish to take any credit for the publication, and the publication can be read in full in its original form if you click the articles link that always accompanies the news item. Also, Comsure does not seek any payment for highlighting these important articles. If you want any article removed, Comsure will automatically do so on a reasonable request if you email info@comsuregroup.com.