/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

As the US and allies try to sanction Evil Corp., the UK NCA says the ransomware gang conducted cyberattacks and espionage ops on NATO allies on Kremlin orders

- Evil Corp. cybercrime crew conducted espionage on NATO members  — UK, US and Australia issued sanctions against alleged hackers

Bloomberg Ryan Gallagher

Context & Ripple Effects

Evil Corp. had already been subject to US action over Dridex, while investigators later reported that the group adopted a ransomware-as-a-service model to work around earlier restrictions.

The new allegation joins a record in which the group was linked to a ransomware attack on Sinclair and shifts the emphasis from profit-driven cybercrime to alleged state-directed operations against allied targets.

First-order effects

  • The coordinated US, UK and Australian sanctions put alleged Evil Corp. operators and their financial dealings under greater scrutiny across three jurisdictions.
  • The UK NCA’s Kremlin-order allegation gives allied authorities a basis to treat activity associated with Evil Corp. as both a cybercrime and national-security concern.

Second-order effects

  • Financial institutions, exchanges and cybersecurity vendors will need to screen more carefully for Evil Corp.-linked identities, infrastructure and payments, complicating any attempt to monetize attacks through intermediaries.
  • The attribution may tighten intelligence sharing among the named allies and focus defensive monitoring on overlaps between ransomware operations and espionage activity.

Third-order effects

  • If more ransomware groups are publicly tied to state tasking, sanctions will increasingly function as a cyber-deterrence tool rather than solely as a response to financial crime.
  • The case underscores the difficulty of separating criminal and state-backed operations when a group can change brands or operating models after enforcement action.

The trend: Allied governments are increasingly framing major ransomware actors as potential instruments of state power and coordinating sanctions accordingly.

Discussion

  • @kevincolliernbc Kevin Collier on threads
    The US is sanctioning former FSB officer Eduard Benderskiy, the father-in-law of EvilCorp's leader.  This, from Treasury this morning, is the most explicit connection I've seen the US make between a top ransomware gang and Russian intelligence services.
  • @treasurydept @treasurydept on threads
    Today, @treasurydept's Office of Foreign Assets Control is sanctioning 7 individuals and two entities associated with Russia-based cybercriminal group Evil Corp. This action is in collaboration with the United Kingdom's @foreignanddevelopmentoffice & Australia's DFAT. https://ho…
  • @nca_uk @nca_uk on x
    Further Evil Corp cyber criminals exposed following NCA investigation, one unmasked as LockBit affiliate, as UK, US and Australia unveil sanctions. Read the full story ➡️ https://www.nationalcrimeagency.gov.uk/ ... [image]
  • @nca_uk @nca_uk on x
    16 members of Evil Corp, once believed to be the most significant cybercrime threat in the world have been sanctioned in the UK with their links to the Russian state and other ransomware groups, including LockBit, exposed. Sanctions have also been imposed by Australia and the US
  • @mike_eckel Mike Eckel on x
    U.S. issues new sanctions, and a new indictment, related to Evil Corp., the Russian ransomware group whose founder/leader, Maxim Yakubets, was the son-in-law of ex-FSB special forces officer, Eduard Bendersky. (h/t @pustota) [image]
  • @brettcallow Brett Callow on x
    Further Evil Corp cyber criminals exposed, one unmasked as #LockBit affiliate #ransomware. https://www.nationalcrimeagency.gov.uk/ ...
  • @alexmartin Alex Martin on x
    Eduard Benderskiy, a former high-ranking official within the Russian intelligence services, was named and sanctioned by Western law enforcement agencies on Tuesday in a paper describing him as a key enabler and protector for the Evil Corp cybercrime group. https://therecord.media…
  • @alexmartin Alex Martin on x
    Western authorities on Tuesday named Russian national Aleksandr Ryzhenkov as one of the main members of the Evil Corp cybercrime group, as well as an affiliate of the LockBit group. The US also charged him with using BitPaymer ransomware. https://therecord.media/...
  • @statedeptspox Matthew Miller on x
    In coordination with the UK and Australia, the United States is sanctioning nine individuals and entities associated with the Russia-based Evil Corp cybercriminal group. The United States is committed to safeguarding our citizens and industries from malicious cyber actors.
  • @carlypage_ Carly Page on x
    The UK has linked a long-standing affiliate of the LockBit ransomware group to Evil Corp, the notorious Russia-backed cybercrime gang. The agency believes “Beverly,” unmasked as Russian national Aleksandr Ryzhenkov, is ‘second in command’ at Evil Corp https://techcrunch.com/...
  • @aejleslie Alexander Leslie on x
    At @RecordedFuture, we've been reporting on the alleged “Dark Covenant” between the cybercriminal underground and Russian intelligence for over three years. Using Evil Corp to guide our analysis — today's news is a vindication. Dark Covenant: https://www.recordedfuture.com/ ... D…
  • @davidmwessel David Wessel on x
    Not sure that calling yourself “Evil Corp” is a good way to avoid scrutiny by US Treasury. https://home.treasury.gov/... [image]