/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

The US and the UK sanction 11 more alleged Trickbot ransomware gang members, and the US DOJ unseals indictments against nine alleged Trickbot and Conti members

Authorities have sanctioned 11 alleged members of the cybercriminal groups, while the US Justice Department unsealed three federal indictments …

Wired Lily Hay Newman

Context & Ripple Effects

This follows a February round of US-UK sanctions against people tied to Conti, Ryuk, and Trickbot, extending a member-focused response rather than treating the malware brands as the only targets.

The indictments also build on the DOJ’s earlier case against an alleged TrickBot malware programmer, adding alleged participants across the Trickbot and Conti ecosystem.

First-order effects

  • The 11 sanctioned alleged Trickbot members face immediate financial and legal restrictions from the US and UK, while nine alleged Trickbot and Conti members are now publicly exposed to federal criminal cases.
  • The actions put individual operators, developers, and support personnel—not just the named malware groups—at the center of the enforcement response.

Second-order effects

  • Public indictments and sanctions can raise the operational cost of working with the alleged groups by making affiliates, infrastructure partners, and cash-out services more visible to authorities and counterparties.
  • The combined US-UK approach increases pressure on adjacent ransomware operations that share people, tooling, or financial channels with Trickbot and Conti.

Third-order effects

  • The case points toward sustained cross-border disruption campaigns aimed at the human and service layers behind malware-as-a-service and ransomware networks, alongside technical takedowns.
  • Whether such actions durably reduce attacks depends on whether authorities can continue identifying replacement operators and the groups’ supporting infrastructure.

The trend: Ransomware enforcement is increasingly targeting the individuals and operational networks behind malware ecosystems through coordinated sanctions and criminal prosecutions.

Discussion

  • @joetidy Joe Tidy on x
    This will be another blow to the cyber crime world and congrats to cops (if these sanctions are correct). But, it has to be said, a lot of the info on these individuals was already out there after the Conti leaks. See research like this from last March https://www.cyberark.com/..…
  • @udunadan @udunadan on x
    A business idea for North Korean threat actors: threat-as-a-service for security researchers to pad their CVs with “been personally targeted by APT”. They send you phishy DMs, you get to brag about it. Everyone's happy.
  • @lilyhnewman Lily Hay Newman on x
    Today US and UK officials sanctioned 11 alleged Trickbot members and DoJ unsealed 3 indictments against alleged Trickbot and Conti members. The only person indicted in all 3 is Maksim Galochkin, who @WIRED publicly identified last week in an investigation https://www.wired.com/..…
  • @samramani2 Samuel Ramani on x
    The Trickbot hacking group was involved in targeting hospitals during the pandemic, as well as US government and companies Due to heavy sanctions, the impact may be limited but the US and Britain are coordinating to stop Russian hackers from laundering money