/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A look at the back-end operations of Evil Corp, the Russian gang sanctioned by the US Treasury for allegedly operating a cybercrime network with FSB connections

Brian Krebs / Krebs on Security : Tweets: @jaredhanson , @jp_koning , @techchaser , and @briankrebs Tweets: Jared Hanson / @jaredhanson : “any user could view messages sent to and from all other users simply by changing a number in the browser's address bar.” Even elite hackers fail to properly implement web authorization. https://krebsonsecurity.com/ ... #security #hacking #evilcorp John Paul Koning / @jp_koning : The FBI has a $5 million reward out for Aqua, the leader of Evil Corp, which recruited money mules to help obfuscate stolen money flows: https://krebsonsecurity.com/ ... @briankrebs has a great story about how he managed to infiltrate one of Aqua's mule recruitment sites... https://twitter.com/... @techchaser : The U.S. Justice Department this month offered a $5 million bounty for information leading to the arrest and conviction of a Russian man indicted for allegedly orchestrating a vast, international cybercrime network https://krebsonsecurity.com/ ... @briankrebs : For years, I was injected into the daily chats of a group that called itself “Evil Corp” and stole >$100M from hacked businesses. The DOJ just put up a $5M bounty for the group's alleged leader. Here's an inside look at Evil Corp & their money mule empire https://krebsonsecurity.com/ ... https://twitter.com/...

Krebs on Security Brian Krebs

Context & Ripple Effects

This Krebs deep-dive lands days after the DOJ charged two Evil Corp members and the Treasury imposed sanctions on the gang behind the Dridex banking malware, and after prosecutors named its alleged leader Aqua — now the subject of an FBI $5 million reward. The piece matters because it maps the machinery behind those charges: how the group moved stolen funds through recruited money mules and what its alleged FSB ties imply.

The sanctions angle is the load-bearing part of the story. As later Mandiant reporting showed, Evil Corp responded by [[a:979452|shifting to a ransomware-as-a-service model specifically to evade the December 2019 sanctions]] — meaning this back-end look captured the group at the moment US financial pressure began reshaping its business model.

First-order effects

  • Aqua and Evil Corp's members face direct legal and financial exposure: DOJ indictments, a $5 million FBI reward for Aqua's capture, and Treasury sanctions blocking US persons from transacting with the network.
  • The money-mule recruitment pipeline Krebs documents becomes evidence — exposing the obfuscation layer the group used to move allegedly $100M+ stolen from banks.

Second-order effects

  • Sanctions pressure forces operational change rather than dissolution: per Mandiant, Evil Corp rebranded into ransomware-as-a-service so victims' ransom payments would not touch sanctioned entities directly.
  • Other Russia-based crews watching the playbook learn that financial sanctions bite where arrests cannot reach, incentivizing brand-splitting and affiliate structures across the ecosystem.

Third-order effects

  • The episode accelerates the pattern BuzzFeed traced in Russian hacking — from credit-card schemes to organized crime to joint criminal-government teams — with sanctions now the West's primary lever against groups the FSB allegedly shelters.
  • If sanction-evasion via rebranding holds as a template, enforcement shifts from naming individual hackers to tracking the financial infrastructure — mule networks and payment flows — that survives every name change.

The trend: US financial sanctions are becoming the primary weapon against untouchable Russian cybercrime groups, pushing them toward rebranding and ransomware-as-a-service structures rather than forcing them offline.

Discussion

  • @jaredhanson Jared Hanson on x
    “any user could view messages sent to and from all other users simply by changing a number in the browser's address bar.” Even elite hackers fail to properly implement web authorization. https://krebsonsecurity.com/ ... #security #hacking #evilcorp
  • @jp_koning John Paul Koning on x
    The FBI has a $5 million reward out for Aqua, the leader of Evil Corp, which recruited money mules to help obfuscate stolen money flows: https://krebsonsecurity.com/ ... @briankrebs has a great story about how he managed to infiltrate one of Aqua's mule recruitment sites... https…
  • @techchaser @techchaser on x
    The U.S. Justice Department this month offered a $5 million bounty for information leading to the arrest and conviction of a Russian man indicted for allegedly orchestrating a vast, international cybercrime network https://krebsonsecurity.com/ ...
  • @briankrebs @briankrebs on x
    For years, I was injected into the daily chats of a group that called itself “Evil Corp” and stole >$100M from hacked businesses. The DOJ just put up a $5M bounty for the group's alleged leader. Here's an inside look at Evil Corp & their money mule empire https://krebsonsecurity.…