Evil Corp The New Targets of the National Crime Agency

2024-10-25

Recently, the UK, US, and Australia have named and imposed sanctions on 16 individuals associated with the notorious cybercrime group Evil Corp.

These sanctions follow Operation Cronos earlier in the year, a multinational effort to disrupt LockBit ransomware operations which was spearheaded by the UK's National Crime Agency. 

Evil Corp, known for its destructive cyber-attacks and ransomware activities, has been linked to stealing around $300 million USD over the past decade.

Who are Evil Corp?

Evil Corp are a Russian cybercrime outfit known for a myriad of ransomware campaigns leveraging several different malware packages, including Dridex and BitPaymer. Through various high-profile attacks, they have managed to extort over $300 million USD in ransom payments throughout the group's lifetime.

It has emerged that Evil Corp is a family business. Though allegations had been levied in the past and denied in turn, it has been revealed that immediate and extended family has had involvement in the group's misdeeds. Some have likened their business strategy and hierarchy to a mafia.

Maksim Yakubets, the founder of Evil Corp who also goes by the alias 'Aqua', along with his father Viktor Yakubets, brother Artem, and a slew of cousins and other associates, have recently received sanctions from the governments of the UK, USA and Australia. 

Maksim had been at the top of the CIA's cybercrime most wanted list for a considerable time, and had the highest bounty ever placed for details leading to his arrest. Despite this, Maksim made little effort to go under the radar. He flaunted his wealth, drove a customised Lamborghini, and had a highly-publicised $330,000 USD wedding in 2019. A significant portion of this wealth comes from attacking victims such as hospitals, healthcare providers and crucial national infrastructure.

Russian State Involvement

Maksim's father-in-law, Eduard Bendersky, is a former special forces official of 'Vympel', known particularly for foreign sabotage. Some believe that Evil Corp's ties to the Russian government began here at the family level. In any case, Eduard is an individual with close ties to the Kremlin who was able to facilitate a much more intimate relationship between Evil Corp and the Russian Intelligence Services than is typically seen with other cybercrime organisations.

Before 2019, Evil Corp were even contracted by the Russian state to disrupt and infiltrate NATO members. That year, when the US government placed sanctions on a number of the group's members and froze some of their assets, the ties between Evil Corp and the Russian State were strained, however it is believed that Eduard's influence is what protected the group from internal law enforcement.

Consequences for the Ransomware Industry

Following the sanctions and indictments placed on Evil Corp and its members since 2019, the group have followed a similar trend to others. Chiefly, they have tried to obfuscate their operations and identities by adopting a number of different monikers, the usage of various different ransomware strains, and so on. That is because the sanctions placed on them make it very difficult for them to extort further ransom payments from their victims, so long as their victims are able to identify the group's involvement in their attack.

This does not appear to have worked, however it did cause the group to rethink their strategy. While some members may have ceased their own operations, others eventually became affiliates of the equally-notorious LockBit ransomware group. One in particular, an individual named Aleksandr Ryzhenkov and believed to be Maksim's "right hand man", was identified by the first wave of Operation Cronos as working under the alias "Beverley," and is believed to be personally responsible for over $100 million USD in ransom extortions.

Disruptions to ransomware groups are known to have a lasting effect, as seen after the defacement of LockBit's leaksite by the NCA. Many criminals hope that by working with larger ransomware outfits, they are provided enhanced safety and privacy than by working on their own - as well as access to some highly sophisticated ransomware tools. What these sanctions and operations against these groups show is that nowhere is safe.

Sources

https://www.whiteblueocean.com/newsroom/the-10-most-notorious-hacking-groups-in-recent-history/
https://www.nationalcrimeagency.gov.uk/who-we-are/publications/732-evil-corp-behind-the-screens/file
https://www.nationalcrimeagency.gov.uk/news/further-evil-corp-cyber-criminals-exposed-one-unmasked-as-lockbit-affiliate
https://www.theregister.com/2024/10/01/nca_names_alleged_evil_corp_kingpin/
https://www.rferl.org/a/in-lavish-wedding-photos-clues-to-an-alleged-russian-cyberthief-fsb-family-ties/30320440.html

https://www.nationalcrimeagency.gov.uk/the-nca-announces-the-disruption-of-lockbit-with-operation-cronos

 

The information contained in this article is provided for informational purposes only and does not constitute professional advice and is not guaranteed to be accurate, complete, reliable, current or error-free.

Protected by Copyscape

Related news

Avoid online shopping scams at Christmas
2024-12-06

The risks of online scams, including imposter scams, fake deals, and malvertising, are significantly higher during the holiday season. With so many tempting offers, shoppers are often targeted by cybercriminals. Learn some simple tips for safe online shopping and safeguard your personal and financial information.

Read more
Intel 471 Issues a Warning on RansomHub
2024-10-10

In September 2024, Intel 471's 'HUNTER', a threat detection platform, issued a widespread warning to their mailing list regarding a surge in attacks led by RansomHub, a Ransomware-as-a-Service (RaaS) operator with an apparent focus on businesses operating in Europe and North America. Discover how they recruit skilled hackers to target different types of business organizations and learn defence tecniques.

Read more
Law Abiding Netizens: How Legislation Can Counter Cybercrime
2025-01-17

Cybercrime threatens global economies, with losses expected to hit $10.5 trillion by 2025. This article explores how the EU leads the global fight against cybercrime threats through legislation like GDPR and DORA, setting global standards for data protection and cybersecurity.

Read more
Mind the Gap: Understanding Cybersecurity Gap Analysis
2025-01-10

A cybersecurity gap analysis is a process used in organisations to evaluate the organization’s current defences, identifies vulnerabilities and weaknesses in the company security framework, and guides improvements, helping businesses prioritize risks and enhance defences. It’s an essential step in building a compliant security framework and staying ahead of evolving cyber threats.

Read more
Not a Snowflake's chance
2024-12-20

The 2024 Snowflake data breaches, caused by infostealer malware and poor implementation of security policies, exposed millions of records. The case underscores the urgent need for robust authentication and improved password hygiene.

Read more
The rise of cyber attacks in Italy | White Blue Ocean
The rise of cyber attacks in Italy
2023-12-04

In the last years many countries have invested deeply in digital security. Despite being world’s 8th largest economy, Italy has been struggling with the process of digitalization and is still considered as an easy target for cyberattacks. Why is it so?

Read more
A Brief History of Ransomware | White Blue Ocean
A Brief History of Ransomware
2023-11-10

Ransomware is continuously developing and becoming more and more sophisticated. It isn’t going anywhere anytime soon, but where did it come from? Where did it go? And how has it evolved?

Read more
Cyber threat landscape: who is LockBit gang?
2022-11-03

The cyber threat landscape has undergone many shifts in the past year, from the involvement of ransomware cyber gangs in hacktivist activity during the war between Russia and Ukraine, to the disappearance from the scene of the most prolific ransomware groups. These include DarkSide, the hacker group behind the Colonial Pipeline attack, and REvil, One of the groups that has been active since 2019 and continues to grow regardless of the shifts in the cyber threat landscape is the LockBit gang.

Read more

Contacts

Let's talk

Please fill in the form below (fields with * are mandatory) and we will respond to your request as soon as possible!