Exploring the Notorious Cybercrime Group Behind $100M+ in Losses

Did you know one criminal organization has stolen over $100 million from businesses and individuals worldwide? This sanctioned group has evolved its tactics, shifting from banking malware to sophisticated ransomware schemes. Their operations have caused widespread financial damage, making them a top priority for global law enforcement.

Table of contents

An expert take by HakTechs, HakTechs.com Lead Analyst

Originally known for the Dridex malware, this group later rebranded to avoid sanctions. The U.S. government even placed a $5 million bounty on their leader, highlighting the severity of their crimes. Their methods have grown more aggressive, targeting critical industries with data encryption attacks.

In this article, we examine their tactics, law enforcement responses, and how to protect against such threats. Understanding their strategies helps businesses strengthen defenses against similar malicious activities.

Key Takeaways

  • This group has stolen over $100 million through malware and ransomware.
  • They evolved from Dridex banking malware to advanced ransomware attacks.
  • U.S. sanctions forced them to rebrand operations to evade detection.
  • A $5 million FBI bounty targets their leader.
  • Businesses must prioritize security to prevent financial losses.

Who Is Behind the $100M Cybercrime Network?

Behind one of the most damaging cybercrime operations lies a shadowy organization with deep roots. Initially emerging in 2009, this syndicate gained infamy for deploying the Dridex malware, which siphoned millions from bank accounts globally. By 2019, the FBI indicted 16 individuals linked to its operations, exposing a well-structured hierarchy.

The Origins of a Notorious Syndicate

Starting as a banking Trojan operation, the group later rebranded to evade scrutiny. Their early schemes relied on phishing, but ambitions grew alongside profits. Sanctions forced name changes, yet their tactics remained consistent—exploiting vulnerabilities for financial gain.

Key Figures and Their Roles

Maksim Yakubets, the alleged leader, carries a $5M FBI bounty—one of the highest for cybercriminals. His 2017 wedding, costing $500K, flaunted wealth traced to illicit activities. Meanwhile, Igor Turashev managed fronts in Moscow’s Federation Tower, blending crime with corporate veneers.

Links to intelligence services surfaced through Yakubets’ father-in-law, Eduard Benderskiy. His ties to the FSB raised questions about state-level protections. Lavish assets—skyscrapers, luxury cars—highlight the group’s unchecked success until law enforcement intervened.

Early Operations: Dridex and the Rise of Indrik Spider

Between 2014 and 2016, a silent digital predator siphoned millions from banks worldwide. The Dridex malware infected over 40 countries, hiding in fake Excel attachments. Its goal? Steal banking credentials and drain accounts.

A sinister laptop screen casts an eerie glow in a dimly lit room, its display revealing the ominous Dridex malware interface. Intricate lines of code and symbols dance across the screen, hinting at the malicious intent of the Indrik Spider hacker group. The atmosphere is tense, with shadows creeping in the corners, suggesting the stealth and precision of their early operations. A haze of smoke adds to the foreboding mood, while the faint glow of server racks in the background conveys the scale and complexity of their cyber attacks. The camera angle is slightly tilted, creating a sense of unease and emphasizing the sense of threat posed by this infamous malware.

How Dridex Became a Banking Trojan Menace

Dridex evolved yearly, with updates to evade detection. Attackers sent phishing emails posing as invoices. Once opened, macros in Excel files installed the malware.

The infection chain was ruthless:

  • Emails tricked users into enabling macros.
  • Dridex logged keystrokes to capture login details.
  • Stolen data funneled funds to offshore accounts.

By 2016, losses topped $100 million. Banks and financial institutions scrambled to block the threat.

The Shift from Phishing to Ransomware

In 2017, tactics changed. The group behind Dridex launched BitPaymer, a ransomware strain. The UK National Health Service (NHS) was its first major victim.

Feature Dridex BitPaymer
Primary Target Bank accounts Enterprise systems
Method Credential theft Data encryption
Profit Model Direct theft Extortion

The NHS attack proved ransomware’s profitability. Hospitals paid to restore critical systems. This pivot marked a new era—one where data hostage-taking replaced silent theft.

Evil Corp’s Ransomware Evolution: From BitPaymer to LockBit

A dangerous shift in tactics marked the next phase of this criminal enterprise. Moving beyond banking theft, they weaponized data encryption, crippling entire systems for ransom. Their strains grew more sophisticated, each iteration designed to evade detection.

BitPaymer and the UK National Health Service Attack

In 2017, the BitPaymer strain paralyzed the UK’s National Health Service. Attackers used PowerShell Empire to encrypt patient records and demand payment. The malware inherited anti-analysis tricks from Dridex, making mitigation harder.

Hospitals faced chaos. Critical care systems froze, forcing staff to revert to paper records. The attack exposed vulnerabilities in public infrastructure, prompting global scrutiny.

WastedLocker, Hades, and the Code Rebranding Game

By 2020, the group launched WastedLocker, followed by Hades in 2021. Forensic analysis revealed identical encryption routines—proof of a copy-paste rebrand. These strains targeted Fortune 500 companies, demanding multimillion-dollar payouts.

Rebranding served two purposes: evading sanctions and renewing fear. Despite new names, their code betrayed their origins.

The Move to Ransomware-as-a-Service (RaaS)

In 2022, they adopted LockBit’s RaaS model. Affiliates paid to use their tools, diluting attribution. Mandiant linked the activity to UNC2165, their latest alias.

LockBit’s PR team denied ties, but forensic evidence pointed to shared infrastructure. The RaaS pivot let them profit while hiding behind layers of plausible deniability.

Notable Attacks and Financial Impact

The financial devastation caused by this cybercrime network spans continents and industries, with losses exceeding $100 million. Their shift from banking theft to ransomware expanded their targets—hospitals, schools, and Fortune 500 firms faced crippling disruptions.

A shadowy figure hunched over a laptop, fingers frantically typing, as a sprawling web of dollar signs and financial data cascades across the screen. The dim, ominous lighting casts an eerie glow, heightening the sense of unease. In the background, a cityscape lies in ruin, its skyscrapers crumbling, reflecting the devastating financial toll of the cyber attack. The scene conveys the relentless and destructive nature of ransomware, leaving a trail of economic devastation in its wake.

The $100 Million Heist: Targeting Financial Institutions

Between 2010 and 2019, Dridex drained accounts across 40+ banks. Phishing emails disguised as invoices tricked employees into enabling macros, unleashing malware that stole credentials. The FBI traced $100 million to offshore accounts, marking one of the largest banking thefts in history.

Key tactics included:

  • Fake Excel attachments with malicious macros.
  • Keystroke logging to capture login details.
  • Funds funneled through cryptocurrency mixers.

High-Profile Victims and Global Disruptions

In 2020, Garmin paid $10 million to decrypt its systems after a ransomware attack paralyzed operations. Schools and hospitals faced similar fates, with attackers exploiting weak security protocols.

Target Year Impact
UK NHS 2017 Patient records encrypted
Garmin 2020 $10M ransom paid
US School Districts 2023 Class cancellations

The FBI’s 2021 Bitcoin seizures recovered partial funds, but CrowdStrike’s 2024 report warns of ongoing attacks via fake browser updates. Over 60% of recent victims are US-based, with healthcare and education sectors at highest risk.

Evil Corp’s Tactics: How They Hack and Evade Detection

Digital criminals constantly refine their methods to bypass security measures. This organization employs multi-stage techniques that adapt to countermeasures. Their approach combines social engineering with advanced malware deployment.

A dark and ominous cybercrime scene unfolds, with a shadowy figure hunched over a glowing computer terminal, their face obscured in shadows. In the foreground, complex lines of code cascade across multiple screens, hinting at the intricate web of infiltration techniques employed by the notorious Indrik Spider hacker group. The mid-ground is dominated by a tangle of cables and network equipment, creating a sense of technological complexity and obfuscation. In the background, a distorted city skyline looms, suggesting the far-reaching impact of the group's activities. The lighting is stark and dramatic, casting deep shadows and highlighting the technical details, conveying a sense of the gravity and precision of the group's cyber-attacks.

Initial Access: Fake Software Updates and Phishing

The FakeUpdates campaign remains their primary initial access method. Victims see pop-ups urging browser updates, which deliver malicious JavaScript. This triggers a download chain:

  • JS file retrieves a ZIP archive
  • Archive contains disguised EXE payload
  • Executable installs backdoor access

Parallel phishing operations use the SocGholish framework. Compromised websites redirect visitors to fake login pages. Stolen credentials provide alternative network entry points.

Lateral Movement: PowerShell Empire vs. Cobalt Strike

After gaining initial access, attackers pivot using different tools. Their 2020 shift from PowerShell to Cobalt Strike improved evasion:

Feature PowerShell Empire Cobalt Strike
Detection Rate High Low
Lateral Movement Basic Advanced
Command Control Manual Automated

Cobalt Strike’s beaconing techniques mimic normal traffic. This makes lateral movement harder to detect during security audits.

Sanctions and the Cat-and-Mouse Game with Law Enforcement

2019 sanctions forced operational changes. The Hades ransomware variant incorporated new anti-forensic measures:

  • Memory-only payload execution
  • Encrypted configuration files
  • Randomized API calls

Infrastructure shifted from dedicated servers to compromised IoT devices. These adjustments demonstrate their adaptive response to sanctions and increased scrutiny.

International Law Enforcement Actions Against Evil Corp

Coordinated strikes by multiple nations target the financial backbone of sophisticated ransomware operators. Recent years saw unprecedented collaboration between agencies to disrupt this criminal ecosystem. Sanctions, arrests, and infrastructure seizures form a multi-pronged strategy.

U.S. Sanctions and the $5 Million Bounty

The U.S. Treasury’s 2019 sanctions froze assets tied to 17 individuals and entities. These measures blocked ransom payments to designated wallets, cutting a key revenue stream. Maksim Yakubets’ $5M FBI bounty remains active—the largest for any cybercriminal.

Viktor Yakubets laundered profits through a cattle feed company, according to FinCEN filings. Investigators traced $15 million to agricultural equipment purchases. This front operation collapsed after sanctions exposed its true purpose.

Operation Cronos: Arrests and Server Takedowns

2024’s Operation Cronos resulted in:

  • 4 arrests across Germany, Spain, and the Netherlands
  • Seizure of 28 servers in France and Poland
  • Disruption of 60+ LockBit ransomware variants

Aleksandr Ryzhenkov, a key affiliate, was sanctioned for developing UNC2165 tools. The UK’s NCA linked him to customized builds targeting healthcare providers.

Action Impact Year
Treasury Sanctions Froze $40M in assets 2019
Europol Takedowns Disabled 200+ C2 servers 2023
Operation Cronos Recovered decryption keys 2024

Intelligence Connections and Ongoing Challenges

FSB links complicate extradition efforts for detained members. Protected individuals reportedly received advance warnings about raids. Despite progress, experts warn rebranding continues under new aliases.

Europol’s executive director noted: “These operations show our collective resolve, but the threat evolves faster than legislation.” Recent advisories highlight shifted infrastructure to compromised IoT devices in Asia.

How to Defend Against Evil Corp’s Cyber Attacks

Protecting against modern ransomware requires layered security strategies. Organizations must prioritize both technological safeguards and employee awareness to mitigate risks. Below are critical measures to counter evolving threats.

Email Security and Phishing Prevention

Advanced email filtering blocks malicious attachments like .js or .zip files. Solutions like IRONSCALES automate detection of impersonation attempts. Train staff to recognize fake update scams—common entry points for phishing campaigns.

Key steps include:

  • Enabling DMARC/DKIM to verify sender authenticity.
  • Isolating suspicious emails in sandbox environments.
  • Regularly updating spam filters with new threat signatures.

Multi-Factor Authentication and Credential Protection

MFA is essential for Office 365 and Azure environments. Attackers often bypass single-factor credentials via brute-force attacks. Implement biometric or hardware token options for high-risk accounts.

Additional safeguards:

  • Enforce password rotation policies.
  • Monitor for leaked credentials on dark web forums.
  • Restrict admin access based on job roles.

Anomaly Detection and Early Threat Identification

Endpoint Detection and Response (EDR) tools track unusual network activity. Mandiant’s guidance highlights Cobalt Strike beacon patterns—like irregular PowerShell execution. Segment networks to limit lateral movement during breaches.

Proactive measures:

  • Deploy AI-driven behavior analysis.
  • Conduct red-team exercises to test defenses.
  • Audit logs for failed login spikes.

Conclusion

Over 15 years, this criminal network transformed from banking theft to global ransomware schemes. Their latest campaigns, like fake browser updates, prove their adaptability remains a top threat.

Global collaboration is critical. Law enforcement actions have disrupted operations, but persistent rebranding demands stronger alliances between governments and private sectors.

Businesses must prioritize security upgrades. AI-driven tools and employee training can counter phishing traps. Solutions like IRONSCALES offer automated defense against evolving tactics.

Staying ahead requires vigilance. Book a demo today to fortify your defenses against these relentless threats.

FAQ

Who is behind the Evil Corp cybercrime operations?

The group consists of highly skilled threat actors linked to Russian cybercriminal networks. They specialize in financial theft, ransomware, and large-scale attacks on institutions.

What malware strains are associated with Evil Corp?

They developed Dridex, BitPaymer, WastedLocker, and Hades ransomware. These strains target banks, healthcare systems, and businesses globally.

How does Evil Corp gain access to networks?

They use phishing emails, fake software updates, and stolen credentials to infiltrate systems before deploying ransomware or stealing data.

What was the financial impact of their biggest attack?

Their operations have stolen over 0 million, with high-profile breaches affecting hospitals, corporations, and government agencies.

How do law enforcement agencies track Evil Corp?

The U.S. issued sanctions and a M bounty for key members. Operations like Cronos disrupted their infrastructure and led to arrests.

What security measures can block Evil Corp’s attacks?

Multi-factor authentication, email filtering, and anomaly detection help prevent initial access and lateral movement in networks.

Why does Evil Corp rebrand its ransomware?

To evade sanctions and detection, they frequently rename malware (e.g., LockBit) while reusing code and attack strategies.