DOJ charges a Russian hacker accused of leading Evil Corp, which oversaw the creation of banking malware Dridex, allegedly used to steal $100M+
U.S. prosecutors have brought computer hacking and fraud charges against a Russian citizen, Maksim Yakubets, who is accused of developing …
Context & Ripple Effects
This indictment lands in the middle of a coordinated week: the DOJ followed up by charging two more Evil Corp members behind Dridex, while the US Treasury sanctioned the gang itself — cutting off its financial rails rather than just naming its hackers.
Subsequent reporting traced Evil Corp's back-end operations and alleged FSB connections, framing the case less as ordinary cybercrime enforcement than as state-adjacent targeting. The DOJ has since repeated the playbook against other malware crews, from Qakbot to DanaBot.
First-order effects
- Maksim Yakubets becomes a formally named, charged fugitive with a $100M+ theft allegation attached to his name, raising the cost of travel, cash-out, and identity use outside Russia.
- Evil Corp's operations face simultaneous legal and financial pressure: criminal charges from the DOJ plus Treasury sanctions aimed at freezing the group's ability to move and spend proceeds.
Second-order effects
- The cash-out layer becomes the enforcement chokepoint — the same logic later applied when the DOJ charged operators of $1B+ money laundering services tied to Joker's Stash, targeting the plumbing malware gangs depend on rather than the malware authors alone.
- Other Russia-based malware operators (the Qakbot and DanaBot crews) can expect individualized indictments as the DOJ converts its Evil Corp template into a standing campaign against banking-malware leadership.
Third-order effects
- If the pattern holds, US enforcement against Russian cybercriminals settles into a name-and-sanction model — indictments that rarely produce arrests but constrain actors financially and diplomatically, especially where groups have alleged state ties.
- Russia's own handling of cybercriminals is becoming part of the equation: the reported arrest of Mikhail Matveev inside Russia suggests Moscow polices hackers selectively, which shapes which targets US charges can actually reach.
The trend: US cybercrime enforcement is shifting from arrest-driven prosecution toward a sanctions-plus-indictment model aimed at the finances of Russia-based malware organizations.