A monthslong investigation exposes the secrets of Russian ransomware gang Trickbot, which thrived despite global disruption efforts, and a key member's identity
A WIRED investigation into a cache of documents posted by an unknown figure lays bare the Trickbot ransomware gang's secrets, including the identity of a central member. Mastodon: @mattburgess@infosec.exchange , @campuscodi@mastodon.social , @couts@mastodon.social , and @lhn@mastodon.online X: @maxwsmeets , @snlyngaas , and @alenapopova Mastodon: Matt Burgess / @mattburgess@infosec.exchange : New: In early 2022, a mysterious leaker published a huge cache of information from inside the Russian cybercrime group Trickbot. For months, me and @lhn have worked to uncover the real world identity of one of the gang's central members, putting a face to the anonymous activity. … Catalin Cimpanu / @campuscodi@mastodon.social : Wired has published an exposé on Bentley, a Russian national named Maksim Sergeevich Galochkin, who leads a software development team inside the Trickbot cybercrime group: https://www.wired.com/... … Andrew Couts / @couts@mastodon.social : NEW: A monthslong WIRED investigation into a trove of documents known as Trickleaks reveals the real-world identity of one of the central players in the Trickbot cybercrime gang. Excellent, excellent work here by @mattburgess and @lhn https://www.wired.com/... Lily Hay Newman / @lhn@mastodon.online : The Trickleaks data from inside Trickbot got dumped online in the fraught and significant weeks after Russia's invasion of Ukraine. But @mattburgess immediately recognized the trove's significance for insight into the notorious group and Russian cybercrime more broadly. … X: Max Smeets / @maxwsmeets : For more context on the Trickbot leaks I also recommend Joe Wrieden's often-overlooked analysis @Cyjax_Ltd https://www.cyjax.com/... Sean Lyngaas / @snlyngaas : Nice unmasking of Trickbot member by @mattburgess1 & @lilyhnewman. One thing I have in common with Maksim is that I'm “f—king addicted” to Metalllica. https://www.wired.com/... Alena Popova / @alenapopova : Excellent work on exposing Russian ransomware gang's secrets. https://www.wired.com/...
Context & Ripple Effects
Trickleaks adds a named individual to an already detailed picture of Trickbot: earlier internal messages described the group’s structure, targets, and expansion plans. The new investigation ties Maksim Sergeevich Galochkin, known as Bentley, to a software-development leadership role.
The disclosure also underscores the limits of purely technical disruption. Prior disruption efforts left some TrickBot command-and-control servers online, while later US and UK sanctions connected Russian individuals to the Conti, Ryuk, and Trickbot ecosystem.
First-order effects
- The identification of Galochkin gives investigators, defenders, and potential legal authorities a specific alleged operator to assess alongside the leaked operational material.
- The leak makes Trickbot’s internal organization and development function more legible, potentially helping defenders map its methods and relationships.
Second-order effects
- Operators associated with Trickbot may face greater pressure to compartmentalize identities, infrastructure, and development work after internal records can be correlated with real-world identities.
- Threat-intelligence teams can combine the leak with prior disruption and sanctions reporting to distinguish persistent personnel and operational links from disposable infrastructure.
Third-order effects
- If repeated leaks and identity attribution continue to expose ransomware organizations, enforcement may increasingly target the people and roles that sustain criminal operations rather than treating each botnet or campaign as an isolated technical incident.
- The pattern points to cybercrime groups behaving like durable organizations whose resilience depends on personnel, management, and redevelopment capacity even after infrastructure disruption.
The trend: Ransomware disruption is shifting from takedowns alone toward attribution that connects leaked internal evidence, operational roles, and real-world actors.