A look at the back-end operations of Evil Corp, the Russian gang sanctioned by the US Treasury for allegedly operating a cybercrime network with FSB connections
Brian Krebs / Krebs on Security : Tweets: @jaredhanson , @jp_koning , @techchaser , and @briankrebs Tweets: Jared Hanson / @jaredhanson : “any user could view messages sent to and from all other users simply by changing a number in the browser's address bar.” Even elite hackers fail to properly implement web authorization. https://krebsonsecurity.com/ ... #security #hacking #evilcorp John Paul Koning / @jp_koning : The FBI has a $5 million reward out for Aqua, the leader of Evil Corp, which recruited money mules to help obfuscate stolen money flows: https://krebsonsecurity.com/ ... @briankrebs has a great story about how he managed to infiltrate one of Aqua's mule recruitment sites... https://twitter.com/... @techchaser : The U.S. Justice Department this month offered a $5 million bounty for information leading to the arrest and conviction of a Russian man indicted for allegedly orchestrating a vast, international cybercrime network https://krebsonsecurity.com/ ... @briankrebs : For years, I was injected into the daily chats of a group that called itself “Evil Corp” and stole >$100M from hacked businesses. The DOJ just put up a $5M bounty for the group's alleged leader. Here's an inside look at Evil Corp & their money mule empire https://krebsonsecurity.com/ ... https://twitter.com/...
Context & Ripple Effects
This Krebs deep-dive lands days after the DOJ charged two Evil Corp members and the Treasury imposed sanctions on the gang behind the Dridex banking malware, and after prosecutors named its alleged leader Aqua — now the subject of an FBI $5 million reward. The piece matters because it maps the machinery behind those charges: how the group moved stolen funds through recruited money mules and what its alleged FSB ties imply.
The sanctions angle is the load-bearing part of the story. As later Mandiant reporting showed, Evil Corp responded by [[a:979452|shifting to a ransomware-as-a-service model specifically to evade the December 2019 sanctions]] — meaning this back-end look captured the group at the moment US financial pressure began reshaping its business model.
First-order effects
- Aqua and Evil Corp's members face direct legal and financial exposure: DOJ indictments, a $5 million FBI reward for Aqua's capture, and Treasury sanctions blocking US persons from transacting with the network.
- The money-mule recruitment pipeline Krebs documents becomes evidence — exposing the obfuscation layer the group used to move allegedly $100M+ stolen from banks.
Second-order effects
- Sanctions pressure forces operational change rather than dissolution: per Mandiant, Evil Corp rebranded into ransomware-as-a-service so victims' ransom payments would not touch sanctioned entities directly.
- Other Russia-based crews watching the playbook learn that financial sanctions bite where arrests cannot reach, incentivizing brand-splitting and affiliate structures across the ecosystem.
Third-order effects
- The episode accelerates the pattern BuzzFeed traced in Russian hacking — from credit-card schemes to organized crime to joint criminal-government teams — with sanctions now the West's primary lever against groups the FSB allegedly shelters.
- If sanction-evasion via rebranding holds as a template, enforcement shifts from naming individual hackers to tracking the financial infrastructure — mule networks and payment flows — that survives every name change.
The trend: US financial sanctions are becoming the primary weapon against untouchable Russian cybercrime groups, pushing them toward rebranding and ransomware-as-a-service structures rather than forcing them offline.