/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Mandiant: Russia-based cybercriminal group Evil Corp has shifted to a ransomware-as-a-service model to evade December 2019 US sanctions for its Dridex malware

TechCrunch Carly Page

Context & Ripple Effects

The sanctions trap Mandiant describes was set in December 2019, when the DOJ charged two Evil Corp members over Dridex bank thefts exceeding $100M and Treasury sanctioned the group itself charges and sanctions that froze its direct operations. The group has been adapting since: by late 2021 sources tied the Sinclair ransomware attack to Evil Corp operating under changed names the Sinclair attack attributed to renamed Evil Corp infrastructure.

The RaaS pivot is the next evasion step — instead of deploying ransomware itself, Evil Corp rents it out, putting affiliates between the gang and the payments sanctions target. That matters because US investigators had already traced ransomware proceeds back to companies in Moscow's Federation Tower East payment trails leading to Federation Tower East, suggesting financial forensics were closing in.

First-order effects

  • Evil Corp's own operators step back from direct deployment: affiliates now execute attacks under other brands, so Treasury's 2019 designation no longer maps cleanly onto who is actually pressing the encrypt button.
  • Victims and their insurers face a harder screening problem — a Sinclair-style attack may be Evil Corp work even when the ransomware strain and negotiation brand carry no sanctioned name.

Second-order effects

  • US investigators' payment-tracing work, which already pointed at Federation Tower East companies, now has to pierce an affiliate layer before reaching the sanctioned principals, raising the cost of every attribution chain.
  • Rival ransomware crews gain cover of ambiguity: as Evil Corp launders its identity through RaaS, sanctions enforcement against any Russian-speaking crew gets more contested, pressuring Treasury to designate affiliates rather than brands.

Third-order effects

  • If the pattern holds, sanctions against cybercriminal groups push them toward franchise structures that diffuse accountability — enforcement shifts from naming groups to tracing money flows and prosecuting individual operators, as the DOJ did with the two Dridex members.
  • The Kremlin-tolerance question sharpens: with ransomware operators allegedly taking Kremlin direction against NATO targets per later UK NCA claims, criminal sanctions policy and state-level countermeasures converge into one track.

The trend: Financial sanctions are reshaping ransomware economics, driving sanctioned groups toward affiliate models that blur attribution faster than designations can keep up.

Discussion

  • @780thc @780thc on x
    Mandiant has investigated multiple LOCKBIT ransomware intrusions attributed to UNC2165, a financially motivated threat cluster that shares numerous overlaps with the threat group publicly reported as “Evil Corp.” https://www.mandiant.com/... @Mandiant
  • @ericgeller Eric Geller on x
    Ransomware attacks associated with Evil Corp are increasingly using ransomware-as-a-service malware rather than custom code, “likely to hinder attribution efforts in order to evade sanctions,” Mandiant says. https://www.mandiant.com/...
  • @bryceabdo Bryce on x
    🚨🔥 New blog from Mandiant: #UNC2165, who overlaps with “Evil Corp” 👹🏢, has been active since at least 2019. UNC2165 previously deployed HADES, and most recently used #LOCKBIT ransomware in multiple cases, to avoid OFAC sanctions imposed on them https://www.mandiant.com/...