Site navigation

Evil Corp Cybercriminals Hit with Fresh Sanctions

Staff Writer

,

Evil Corp sanctions
“These sanctions expose further members of Evil Corp, including one who was a LockBit affiliate, and those who were critical to enabling their activity,” said James Babbage, director general for threats at the NCA.

Cybercriminals connected to Evil Corp, once believed to be the most significant cybercrime threat in the world, have been sanctioned in the UK, with their links to the Russian state and other prolific ransomware groups, including LockBit, exposed.

Sixteen individuals have been sanctioned, including Maksim Yakubets, the alleged head of Evil Corp operations, who has a $5 million (£3.7 million) bounty on his head from the US Department of Justice. 

Yakubets has purportedly cultivated strong ties between Evil Corp and the Russian state, developing relationships with the FSB and Russian military intelligence (GRU). 

Beginning as a family-centred financial crime group in Moscow, Evil Corp has gone on to wage a campaign of destructive cyber-attacks worldwide for over a decade, using malware and ransomware to attack UK health, government and public sector institutions, as well as private commercial technology companies.

According to the government and National Crime Agency (NCA), recent investigations into Evil Corp found that the group has extorted at least $300 million from global victims.

Nine members of the criminal gang, including Yakubets, were first sanctioned by the US in 2019, and have now been sanctioned in the UK by the Foreign, Commonwealth and Development Office, along with another seven individuals, whose links to the group have not previously been exposed.

Newly linked to the cybercrime group is Aleksandr Ryzhenkov, supposedly Yakubets’ right-hand man, who the NCA claim has worked to develop some of the group’s most prolific ransomware strains. Ryzhenkov has also been identified as an affiliate of the ransomware group LockBit through Operation Cronos – the ongoing NCA-led international disruption of LockBit.

The new sanctions mean these individuals will now be subject to a series of asset freezes and travel bans, including in Australia and the US.

James Babbage, director general for threats at the NCA, said: “These sanctions expose further members of Evil Corp, including one who was a LockBit affiliate, and those who were critical to enabling their activity. We expect these new designations to also disrupt their ongoing criminal activity.

“Ransomware is the most significant cybercrime threat facing the UK and the world. The NCA is dedicated to working with our partners in the UK and overseas, sharing intelligence and working to disrupt the most sophisticated and harmful ransomware groups, no matter where they are or how long it takes.”


Recommended reading


Evil Corp officially formed as a crime group in 2014, and were responsible for the development and distribution of BitPaymer and Dridex, which they used to target banks and financial institutions in over 40 countries, stealing over $100 million (£75.2 million).

Members of the group have since gone on to develop further malware and ransomware strains, most notably WastedLocker, Hades, PhoenixLocker, PayloadBIN and Macaw. 

DIGIT Staff Writer Robot

Staff Writer

Staff Writer - DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data