As the US and allies try to sanction Evil Corp., the UK NCA says the ransomware gang conducted cyberattacks and espionage ops on NATO allies on Kremlin orders
- Evil Corp. cybercrime crew conducted espionage on NATO members — UK, US and Australia issued sanctions against alleged hackers
BloombergRyan Gallagher
Context & Ripple Effects
Evil Corp. had already been subject to US action over Dridex, while investigators later reported that the group adopted a ransomware-as-a-service model to work around earlier restrictions.
The new allegation joins a record in which the group was linked to a ransomware attack on Sinclair and shifts the emphasis from profit-driven cybercrime to alleged state-directed operations against allied targets.
First-order effects
The coordinated US, UK and Australian sanctions put alleged Evil Corp. operators and their financial dealings under greater scrutiny across three jurisdictions.
The UK NCA’s Kremlin-order allegation gives allied authorities a basis to treat activity associated with Evil Corp. as both a cybercrime and national-security concern.
Second-order effects
Financial institutions, exchanges and cybersecurity vendors will need to screen more carefully for Evil Corp.-linked identities, infrastructure and payments, complicating any attempt to monetize attacks through intermediaries.
The attribution may tighten intelligence sharing among the named allies and focus defensive monitoring on overlaps between ransomware operations and espionage activity.
Third-order effects
If more ransomware groups are publicly tied to state tasking, sanctions will increasingly function as a cyber-deterrence tool rather than solely as a response to financial crime.
The case underscores the difficulty of separating criminal and state-backed operations when a group can change brands or operating models after enforcement action.
The trend: Allied governments are increasingly framing major ransomware actors as potential instruments of state power and coordinating sanctions accordingly.
The US is sanctioning former FSB officer Eduard Benderskiy, the father-in-law of EvilCorp's leader. This, from Treasury this morning, is the most explicit connection I've seen the US make between a top ransomware gang and Russian intelligence services.
Today, @treasurydept's Office of Foreign Assets Control is sanctioning 7 individuals and two entities associated with Russia-based cybercriminal group Evil Corp. This action is in collaboration with the United Kingdom's @foreignanddevelopmentoffice & Australia's DFAT. https://ho…
Further Evil Corp cyber criminals exposed following NCA investigation, one unmasked as LockBit affiliate, as UK, US and Australia unveil sanctions. Read the full story ➡️ https://www.nationalcrimeagency.gov.uk/ ... [image]
16 members of Evil Corp, once believed to be the most significant cybercrime threat in the world have been sanctioned in the UK with their links to the Russian state and other ransomware groups, including LockBit, exposed. Sanctions have also been imposed by Australia and the US
U.S. issues new sanctions, and a new indictment, related to Evil Corp., the Russian ransomware group whose founder/leader, Maxim Yakubets, was the son-in-law of ex-FSB special forces officer, Eduard Bendersky. (h/t @pustota) [image]
Eduard Benderskiy, a former high-ranking official within the Russian intelligence services, was named and sanctioned by Western law enforcement agencies on Tuesday in a paper describing him as a key enabler and protector for the Evil Corp cybercrime group. https://therecord.media…
Western authorities on Tuesday named Russian national Aleksandr Ryzhenkov as one of the main members of the Evil Corp cybercrime group, as well as an affiliate of the LockBit group. The US also charged him with using BitPaymer ransomware. https://therecord.media/...
In coordination with the UK and Australia, the United States is sanctioning nine individuals and entities associated with the Russia-based Evil Corp cybercriminal group. The United States is committed to safeguarding our citizens and industries from malicious cyber actors.
The UK has linked a long-standing affiliate of the LockBit ransomware group to Evil Corp, the notorious Russia-backed cybercrime gang. The agency believes “Beverly,” unmasked as Russian national Aleksandr Ryzhenkov, is ‘second in command’ at Evil Corp https://techcrunch.com/...
At @RecordedFuture, we've been reporting on the alleged “Dark Covenant” between the cybercriminal underground and Russian intelligence for over three years. Using Evil Corp to guide our analysis — today's news is a vindication. Dark Covenant: https://www.recordedfuture.com/ ... D…