Mandiant: Russia-based cybercriminal group Evil Corp has shifted to a ransomware-as-a-service model to evade December 2019 US sanctions for its Dridex malware
Context & Ripple Effects
The sanctions trap Mandiant describes was set in December 2019, when the DOJ charged two Evil Corp members over Dridex bank thefts exceeding $100M and Treasury sanctioned the group itself charges and sanctions that froze its direct operations. The group has been adapting since: by late 2021 sources tied the Sinclair ransomware attack to Evil Corp operating under changed names the Sinclair attack attributed to renamed Evil Corp infrastructure.
The RaaS pivot is the next evasion step — instead of deploying ransomware itself, Evil Corp rents it out, putting affiliates between the gang and the payments sanctions target. That matters because US investigators had already traced ransomware proceeds back to companies in Moscow's Federation Tower East payment trails leading to Federation Tower East, suggesting financial forensics were closing in.
First-order effects
- Evil Corp's own operators step back from direct deployment: affiliates now execute attacks under other brands, so Treasury's 2019 designation no longer maps cleanly onto who is actually pressing the encrypt button.
- Victims and their insurers face a harder screening problem — a Sinclair-style attack may be Evil Corp work even when the ransomware strain and negotiation brand carry no sanctioned name.
Second-order effects
- US investigators' payment-tracing work, which already pointed at Federation Tower East companies, now has to pierce an affiliate layer before reaching the sanctioned principals, raising the cost of every attribution chain.
- Rival ransomware crews gain cover of ambiguity: as Evil Corp launders its identity through RaaS, sanctions enforcement against any Russian-speaking crew gets more contested, pressuring Treasury to designate affiliates rather than brands.
Third-order effects
- If the pattern holds, sanctions against cybercriminal groups push them toward franchise structures that diffuse accountability — enforcement shifts from naming groups to tracing money flows and prosecuting individual operators, as the DOJ did with the two Dridex members.
- The Kremlin-tolerance question sharpens: with ransomware operators allegedly taking Kremlin direction against NATO targets per later UK NCA claims, criminal sanctions policy and state-level countermeasures converge into one track.
The trend: Financial sanctions are reshaping ransomware economics, driving sanctioned groups toward affiliate models that blur attribution faster than designations can keep up.