/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A monthslong investigation exposes the secrets of Russian ransomware gang Trickbot, which thrived despite global disruption efforts, and a key member's identity

A WIRED investigation into a cache of documents posted by an unknown figure lays bare the Trickbot ransomware gang's secrets, including the identity of a central member. Mastodon: @mattburgess@infosec.exchange , @campuscodi@mastodon.social , @couts@mastodon.social , and @lhn@mastodon.online X: @maxwsmeets , @snlyngaas , and @alenapopova Mastodon: Matt Burgess / @mattburgess@infosec.exchange : New: In early 2022, a mysterious leaker published a huge cache of information from inside the Russian cybercrime group Trickbot.  For months, me and @lhn have worked to uncover the real world identity of one of the gang's central members, putting a face to the anonymous activity. … Catalin Cimpanu / @campuscodi@mastodon.social : Wired has published an exposé on Bentley, a Russian national named Maksim Sergeevich Galochkin, who leads a software development team inside the Trickbot cybercrime group: https://www.wired.com/... … Andrew Couts / @couts@mastodon.social : NEW: A monthslong WIRED investigation into a trove of documents known as Trickleaks reveals the real-world identity of one of the central players in the Trickbot cybercrime gang.  Excellent, excellent work here by @mattburgess and @lhn https://www.wired.com/... Lily Hay Newman / @lhn@mastodon.online : The Trickleaks data from inside Trickbot got dumped online in the fraught and significant weeks after Russia's invasion of Ukraine.  But @mattburgess immediately recognized the trove's significance for insight into the notorious group and Russian cybercrime more broadly. … X: Max Smeets / @maxwsmeets : For more context on the Trickbot leaks I also recommend Joe Wrieden's often-overlooked analysis @Cyjax_Ltd https://www.cyjax.com/... Sean Lyngaas / @snlyngaas : Nice unmasking of Trickbot member by @mattburgess1 & @lilyhnewman. One thing I have in common with Maksim is that I'm “f—king addicted” to Metalllica. https://www.wired.com/... Alena Popova / @alenapopova : Excellent work on exposing Russian ransomware gang's secrets. https://www.wired.com/...

Wired

Context & Ripple Effects

Trickleaks adds a named individual to an already detailed picture of Trickbot: earlier internal messages described the group’s structure, targets, and expansion plans. The new investigation ties Maksim Sergeevich Galochkin, known as Bentley, to a software-development leadership role.

The disclosure also underscores the limits of purely technical disruption. Prior disruption efforts left some TrickBot command-and-control servers online, while later US and UK sanctions connected Russian individuals to the Conti, Ryuk, and Trickbot ecosystem.

First-order effects

  • The identification of Galochkin gives investigators, defenders, and potential legal authorities a specific alleged operator to assess alongside the leaked operational material.
  • The leak makes Trickbot’s internal organization and development function more legible, potentially helping defenders map its methods and relationships.

Second-order effects

  • Operators associated with Trickbot may face greater pressure to compartmentalize identities, infrastructure, and development work after internal records can be correlated with real-world identities.
  • Threat-intelligence teams can combine the leak with prior disruption and sanctions reporting to distinguish persistent personnel and operational links from disposable infrastructure.

Third-order effects

  • If repeated leaks and identity attribution continue to expose ransomware organizations, enforcement may increasingly target the people and roles that sustain criminal operations rather than treating each botnet or campaign as an isolated technical incident.
  • The pattern points to cybercrime groups behaving like durable organizations whose resilience depends on personnel, management, and redevelopment capacity even after infrastructure disruption.

The trend: Ransomware disruption is shifting from takedowns alone toward attribution that connects leaked internal evidence, operational roles, and real-world actors.

Discussion

  • @campuscodi@mastodon.social Catalin Cimpanu on mastodon
    Wired has published an exposé on Bentley, a Russian national named Maksim Sergeevich Galochkin, who leads a software development team inside the Trickbot cybercrime group: https://www.wired.com/... …
  • @couts@mastodon.social Andrew Couts on mastodon
    NEW: A monthslong WIRED investigation into a trove of documents known as Trickleaks reveals the real-world identity of one of the central players in the Trickbot cybercrime gang.  Excellent, excellent work here by @mattburgess and @lhn https://www.wired.com/...
  • @lhn@mastodon.online Lily Hay Newman on mastodon
    The Trickleaks data from inside Trickbot got dumped online in the fraught and significant weeks after Russia's invasion of Ukraine.  But @mattburgess immediately recognized the trove's significance for insight into the notorious group and Russian cybercrime more broadly. …
  • @maxwsmeets Max Smeets on x
    For more context on the Trickbot leaks I also recommend Joe Wrieden's often-overlooked analysis @Cyjax_Ltd https://www.cyjax.com/...
  • @snlyngaas Sean Lyngaas on x
    Nice unmasking of Trickbot member by @mattburgess1 & @lilyhnewman. One thing I have in common with Maksim is that I'm “f—king addicted” to Metalllica. https://www.wired.com/...
  • @alenapopova Alena Popova on x
    Excellent work on exposing Russian ransomware gang's secrets. https://www.wired.com/...