Did you know one criminal organization has stolen over $100 million from businesses and individuals worldwide? This sanctioned group has evolved its tactics, shifting from banking malware to sophisticated ransomware schemes. Their operations have caused widespread financial damage, making them a top priority for global law enforcement.
Originally known for the Dridex malware, this group later rebranded to avoid sanctions. The U.S. government even placed a $5 million bounty on their leader, highlighting the severity of their crimes. Their methods have grown more aggressive, targeting critical industries with data encryption attacks.
In this article, we examine their tactics, law enforcement responses, and how to protect against such threats. Understanding their strategies helps businesses strengthen defenses against similar malicious activities.
Key Takeaways
- This group has stolen over $100 million through malware and ransomware.
- They evolved from Dridex banking malware to advanced ransomware attacks.
- U.S. sanctions forced them to rebrand operations to evade detection.
- A $5 million FBI bounty targets their leader.
- Businesses must prioritize security to prevent financial losses.
Who Is Behind the $100M Cybercrime Network?
Behind one of the most damaging cybercrime operations lies a shadowy organization with deep roots. Initially emerging in 2009, this syndicate gained infamy for deploying the Dridex malware, which siphoned millions from bank accounts globally. By 2019, the FBI indicted 16 individuals linked to its operations, exposing a well-structured hierarchy.
The Origins of a Notorious Syndicate
Starting as a banking Trojan operation, the group later rebranded to evade scrutiny. Their early schemes relied on phishing, but ambitions grew alongside profits. Sanctions forced name changes, yet their tactics remained consistent—exploiting vulnerabilities for financial gain.
Key Figures and Their Roles
Maksim Yakubets, the alleged leader, carries a $5M FBI bounty—one of the highest for cybercriminals. His 2017 wedding, costing $500K, flaunted wealth traced to illicit activities. Meanwhile, Igor Turashev managed fronts in Moscow’s Federation Tower, blending crime with corporate veneers.
Links to intelligence services surfaced through Yakubets’ father-in-law, Eduard Benderskiy. His ties to the FSB raised questions about state-level protections. Lavish assets—skyscrapers, luxury cars—highlight the group’s unchecked success until law enforcement intervened.
Early Operations: Dridex and the Rise of Indrik Spider
Between 2014 and 2016, a silent digital predator siphoned millions from banks worldwide. The Dridex malware infected over 40 countries, hiding in fake Excel attachments. Its goal? Steal banking credentials and drain accounts.

How Dridex Became a Banking Trojan Menace
Dridex evolved yearly, with updates to evade detection. Attackers sent phishing emails posing as invoices. Once opened, macros in Excel files installed the malware.
The infection chain was ruthless:
- Emails tricked users into enabling macros.
- Dridex logged keystrokes to capture login details.
- Stolen data funneled funds to offshore accounts.
By 2016, losses topped $100 million. Banks and financial institutions scrambled to block the threat.
The Shift from Phishing to Ransomware
In 2017, tactics changed. The group behind Dridex launched BitPaymer, a ransomware strain. The UK National Health Service (NHS) was its first major victim.
| Feature | Dridex | BitPaymer |
|---|---|---|
| Primary Target | Bank accounts | Enterprise systems |
| Method | Credential theft | Data encryption |
| Profit Model | Direct theft | Extortion |
The NHS attack proved ransomware’s profitability. Hospitals paid to restore critical systems. This pivot marked a new era—one where data hostage-taking replaced silent theft.
Evil Corp’s Ransomware Evolution: From BitPaymer to LockBit
A dangerous shift in tactics marked the next phase of this criminal enterprise. Moving beyond banking theft, they weaponized data encryption, crippling entire systems for ransom. Their strains grew more sophisticated, each iteration designed to evade detection.
BitPaymer and the UK National Health Service Attack
In 2017, the BitPaymer strain paralyzed the UK’s National Health Service. Attackers used PowerShell Empire to encrypt patient records and demand payment. The malware inherited anti-analysis tricks from Dridex, making mitigation harder.
Hospitals faced chaos. Critical care systems froze, forcing staff to revert to paper records. The attack exposed vulnerabilities in public infrastructure, prompting global scrutiny.
WastedLocker, Hades, and the Code Rebranding Game
By 2020, the group launched WastedLocker, followed by Hades in 2021. Forensic analysis revealed identical encryption routines—proof of a copy-paste rebrand. These strains targeted Fortune 500 companies, demanding multimillion-dollar payouts.
Rebranding served two purposes: evading sanctions and renewing fear. Despite new names, their code betrayed their origins.
The Move to Ransomware-as-a-Service (RaaS)
In 2022, they adopted LockBit’s RaaS model. Affiliates paid to use their tools, diluting attribution. Mandiant linked the activity to UNC2165, their latest alias.
LockBit’s PR team denied ties, but forensic evidence pointed to shared infrastructure. The RaaS pivot let them profit while hiding behind layers of plausible deniability.
Notable Attacks and Financial Impact
The financial devastation caused by this cybercrime network spans continents and industries, with losses exceeding $100 million. Their shift from banking theft to ransomware expanded their targets—hospitals, schools, and Fortune 500 firms faced crippling disruptions.

The $100 Million Heist: Targeting Financial Institutions
Between 2010 and 2019, Dridex drained accounts across 40+ banks. Phishing emails disguised as invoices tricked employees into enabling macros, unleashing malware that stole credentials. The FBI traced $100 million to offshore accounts, marking one of the largest banking thefts in history.
Key tactics included:
- Fake Excel attachments with malicious macros.
- Keystroke logging to capture login details.
- Funds funneled through cryptocurrency mixers.
High-Profile Victims and Global Disruptions
In 2020, Garmin paid $10 million to decrypt its systems after a ransomware attack paralyzed operations. Schools and hospitals faced similar fates, with attackers exploiting weak security protocols.
| Target | Year | Impact |
|---|---|---|
| UK NHS | 2017 | Patient records encrypted |
| Garmin | 2020 | $10M ransom paid |
| US School Districts | 2023 | Class cancellations |
The FBI’s 2021 Bitcoin seizures recovered partial funds, but CrowdStrike’s 2024 report warns of ongoing attacks via fake browser updates. Over 60% of recent victims are US-based, with healthcare and education sectors at highest risk.
Evil Corp’s Tactics: How They Hack and Evade Detection
Digital criminals constantly refine their methods to bypass security measures. This organization employs multi-stage techniques that adapt to countermeasures. Their approach combines social engineering with advanced malware deployment.

Initial Access: Fake Software Updates and Phishing
The FakeUpdates campaign remains their primary initial access method. Victims see pop-ups urging browser updates, which deliver malicious JavaScript. This triggers a download chain:
- JS file retrieves a ZIP archive
- Archive contains disguised EXE payload
- Executable installs backdoor access
Parallel phishing operations use the SocGholish framework. Compromised websites redirect visitors to fake login pages. Stolen credentials provide alternative network entry points.
Lateral Movement: PowerShell Empire vs. Cobalt Strike
After gaining initial access, attackers pivot using different tools. Their 2020 shift from PowerShell to Cobalt Strike improved evasion:
| Feature | PowerShell Empire | Cobalt Strike |
|---|---|---|
| Detection Rate | High | Low |
| Lateral Movement | Basic | Advanced |
| Command Control | Manual | Automated |
Cobalt Strike’s beaconing techniques mimic normal traffic. This makes lateral movement harder to detect during security audits.
Sanctions and the Cat-and-Mouse Game with Law Enforcement
2019 sanctions forced operational changes. The Hades ransomware variant incorporated new anti-forensic measures:
- Memory-only payload execution
- Encrypted configuration files
- Randomized API calls
Infrastructure shifted from dedicated servers to compromised IoT devices. These adjustments demonstrate their adaptive response to sanctions and increased scrutiny.
International Law Enforcement Actions Against Evil Corp
Coordinated strikes by multiple nations target the financial backbone of sophisticated ransomware operators. Recent years saw unprecedented collaboration between agencies to disrupt this criminal ecosystem. Sanctions, arrests, and infrastructure seizures form a multi-pronged strategy.
U.S. Sanctions and the $5 Million Bounty
The U.S. Treasury’s 2019 sanctions froze assets tied to 17 individuals and entities. These measures blocked ransom payments to designated wallets, cutting a key revenue stream. Maksim Yakubets’ $5M FBI bounty remains active—the largest for any cybercriminal.
Viktor Yakubets laundered profits through a cattle feed company, according to FinCEN filings. Investigators traced $15 million to agricultural equipment purchases. This front operation collapsed after sanctions exposed its true purpose.
Operation Cronos: Arrests and Server Takedowns
2024’s Operation Cronos resulted in:
- 4 arrests across Germany, Spain, and the Netherlands
- Seizure of 28 servers in France and Poland
- Disruption of 60+ LockBit ransomware variants
Aleksandr Ryzhenkov, a key affiliate, was sanctioned for developing UNC2165 tools. The UK’s NCA linked him to customized builds targeting healthcare providers.
| Action | Impact | Year |
|---|---|---|
| Treasury Sanctions | Froze $40M in assets | 2019 |
| Europol Takedowns | Disabled 200+ C2 servers | 2023 |
| Operation Cronos | Recovered decryption keys | 2024 |
Intelligence Connections and Ongoing Challenges
FSB links complicate extradition efforts for detained members. Protected individuals reportedly received advance warnings about raids. Despite progress, experts warn rebranding continues under new aliases.
Europol’s executive director noted: “These operations show our collective resolve, but the threat evolves faster than legislation.” Recent advisories highlight shifted infrastructure to compromised IoT devices in Asia.
How to Defend Against Evil Corp’s Cyber Attacks
Protecting against modern ransomware requires layered security strategies. Organizations must prioritize both technological safeguards and employee awareness to mitigate risks. Below are critical measures to counter evolving threats.
Email Security and Phishing Prevention
Advanced email filtering blocks malicious attachments like .js or .zip files. Solutions like IRONSCALES automate detection of impersonation attempts. Train staff to recognize fake update scams—common entry points for phishing campaigns.
Key steps include:
- Enabling DMARC/DKIM to verify sender authenticity.
- Isolating suspicious emails in sandbox environments.
- Regularly updating spam filters with new threat signatures.
Multi-Factor Authentication and Credential Protection
MFA is essential for Office 365 and Azure environments. Attackers often bypass single-factor credentials via brute-force attacks. Implement biometric or hardware token options for high-risk accounts.
Additional safeguards:
- Enforce password rotation policies.
- Monitor for leaked credentials on dark web forums.
- Restrict admin access based on job roles.
Anomaly Detection and Early Threat Identification
Endpoint Detection and Response (EDR) tools track unusual network activity. Mandiant’s guidance highlights Cobalt Strike beacon patterns—like irregular PowerShell execution. Segment networks to limit lateral movement during breaches.
Proactive measures:
- Deploy AI-driven behavior analysis.
- Conduct red-team exercises to test defenses.
- Audit logs for failed login spikes.
Conclusion
Over 15 years, this criminal network transformed from banking theft to global ransomware schemes. Their latest campaigns, like fake browser updates, prove their adaptability remains a top threat.
Global collaboration is critical. Law enforcement actions have disrupted operations, but persistent rebranding demands stronger alliances between governments and private sectors.
Businesses must prioritize security upgrades. AI-driven tools and employee training can counter phishing traps. Solutions like IRONSCALES offer automated defense against evolving tactics.
Staying ahead requires vigilance. Book a demo today to fortify your defenses against these relentless threats.