/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

The US and the UK sanction 11 more alleged Trickbot ransomware gang members, and the US DOJ unseals indictments against nine alleged Trickbot and Conti members

Wired Lily Hay Newman

Context & Ripple Effects

This expands a coordinated US-UK campaign that had already targeted seven people alleged to be tied to Conti, Ryuk and Trickbot in February, following an earlier DOJ case against an alleged TrickBot programmer.

The case joins sanctions with public criminal allegations against personnel associated with both Trickbot and Conti, treating ransomware infrastructure and its operators as a connected enforcement target rather than separate incidents.

First-order effects

  • The 11 sanctioned alleged members face immediate financial and mobility constraints in jurisdictions that enforce the US and UK measures, while the nine indicted defendants face formal US criminal exposure.
  • Trickbot- and Conti-linked operators are put on notice that participation in malware distribution and ransomware operations can draw both sanctions and indictments.

Second-order effects

  • Financial institutions, infrastructure providers and counterparties must screen for the newly named individuals, making it harder for those operators to use legitimate services under their own identities.
  • The combined action raises the cost of maintaining recognizable roles and networks, encouraging ransomware groups to compartmentalize personnel and shift operational identities.

Third-order effects

  • If repeated across ransomware ecosystems, coordinated sanctions and prosecutions could make attribution-driven disruption a standing complement to technical takedowns—not merely a response after a major attack.
  • The pattern points toward enforcement focused on the human and financial layers around malware-as-a-service operations, though its durability depends on whether accused operators can be reached or deprived of usable infrastructure.

The trend: Ransomware enforcement is increasingly combining allied sanctions with criminal cases to disrupt the people, money flows and service networks behind malware operations.

Discussion

  • @udunadan @udunadan on x
    A business idea for North Korean threat actors: threat-as-a-service for security researchers to pad their CVs with “been personally targeted by APT”. They send you phishy DMs, you get to brag about it. Everyone's happy.
  • @joetidy Joe Tidy on x
    This will be another blow to the cyber crime world and congrats to cops (if these sanctions are correct). But, it has to be said, a lot of the info on these individuals was already out there after the Conti leaks. See research like this from last March https://www.cyberark.com/..…
  • @samramani2 Samuel Ramani on x
    The Trickbot hacking group was involved in targeting hospitals during the pandemic, as well as US government and companies Due to heavy sanctions, the impact may be limited but the US and Britain are coordinating to stop Russian hackers from laundering money
  • @lilyhnewman Lily Hay Newman on x
    Today US and UK officials sanctioned 11 alleged Trickbot members and DoJ unsealed 3 indictments against alleged Trickbot and Conti members. The only person indicted in all 3 is Maksim Galochkin, who @WIRED publicly identified last week in an investigation https://www.wired.com/..…