Sources: the recent ransomware attack against Sinclair is linked to Russian group Evil Corp., which changed names to avoid 2019 US sanctions
- Evil Corp. said to change names to avoid 2019 U.S. sanctions — Broadcaster hit with new ransomware strain called Macaw Tweets: @williamturton , @caseynewton , @williamturton , @williamturton , and @williamturton See also Mediagazer Tweets: William Turton / @williamturton : SCOOP: Evil Corp is back. The infamous Russian ransomware gang is behind the hack that hit Sinclair Broadcasting Group this weekend. https://www.bloomberg.com/... Casey Newton / @caseynewton : If you are a tech giant considering a rebrand please note that Evil Corp. is now available https://t.co/nyNrSv8Q0o William Turton / @williamturton : Also...here is the ascii art that Macaw Locker uses in its ransom note. Appears Evil Corp has a thing for ascii art, Phoenix Locker also used it. https://www.bloomberg.com/... https://twitter.com/... William Turton / @williamturton : A previous iteration also believed to be linked to Evil Corp is Phoenix Locker, who struck insurer CNA in March. CNA paid a $40 million ransom, the largest ever publicly reported. https://www.bloomberg.com/... William Turton / @williamturton : Evil Corp was sanctioned by the U.S. in 2019. In response, the group has changed the name of its ransomware product in an attempt to avoid sanctions. This time, they're back with a new ransomware variant called “Macaw.” https://www.bloomberg.com/... See also Mediagazer
Context & Ripple Effects
The Treasury sanctioned Evil Corp in December 2019 for its Dridex cybercrime operation, and reporting at the time traced the gang's back-end operations to an FSB-connected network. The Sinclair attribution shows what happened next: rather than disbanding, sources say the group relaunched under new names with a new ransomware strain, Macaw, aimed squarely at staying outside the sanctions perimeter.
That evasion playbook has since become the group's defining feature — Mandiant documented its move into a ransomware-as-a-service model specifically to launder attribution away from sanctioned actors, and by last year the UK NCA was alleging Kremlin-directed attacks on NATO allies, collapsing the distance between criminal brand and state interest.
First-order effects
- Sinclair is hit by a strain whose operators are under active US sanctions, meaning any ransom negotiation carries legal exposure on top of operational disruption.
- The Macaw branding lets Evil Corp resume attacks while complicating victim-side screening, since compliance checks keyed to sanctioned names won't flag the new labels.
Second-order effects
- Enforcement now has to chase brands instead of people: each rename resets the matching work for Treasury, insurers, and incident responders who rely on family-name attribution.
- The Mandiant-documented shift to ransomware-as-a-service gives the group affiliate cover, pushing other sanctioned or near-sanctioned crews toward the same franchise structure.
Third-order effects
- If renaming-plus-RaaS keeps defeating list-based sanctions, policy drifts toward treating ransomware crews as state proxies rather than criminals — the direction the NCA's Kremlin-orders allegation already points.
- For buyers, attribution stops being a due-diligence checkbox and becomes a live sanctions-compliance problem embedded in every ransomware incident.
The trend: Sanctioned ransomware groups are surviving enforcement through continuous rebranding and affiliate outsourcing, turning sanctions evasion into the organizing principle of the ransomware economy.