/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Sources: the recent ransomware attack against Sinclair is linked to Russian group Evil Corp., which changed names to avoid 2019 US sanctions

- Evil Corp. said to change names to avoid 2019 U.S. sanctions  — Broadcaster hit with new ransomware strain called Macaw Tweets: @williamturton , @caseynewton , @williamturton , @williamturton , and @williamturton See also Mediagazer Tweets: William Turton / @williamturton : SCOOP: Evil Corp is back. The infamous Russian ransomware gang is behind the hack that hit Sinclair Broadcasting Group this weekend. https://www.bloomberg.com/... Casey Newton / @caseynewton : If you are a tech giant considering a rebrand please note that Evil Corp. is now available https://t.co/nyNrSv8Q0o William Turton / @williamturton : Also...here is the ascii art that Macaw Locker uses in its ransom note. Appears Evil Corp has a thing for ascii art, Phoenix Locker also used it. https://www.bloomberg.com/... https://twitter.com/... William Turton / @williamturton : A previous iteration also believed to be linked to Evil Corp is Phoenix Locker, who struck insurer CNA in March. CNA paid a $40 million ransom, the largest ever publicly reported. https://www.bloomberg.com/... William Turton / @williamturton : Evil Corp was sanctioned by the U.S. in 2019. In response, the group has changed the name of its ransomware product in an attempt to avoid sanctions. This time, they're back with a new ransomware variant called “Macaw.” https://www.bloomberg.com/... See also Mediagazer

Bloomberg William Turton

Context & Ripple Effects

The Treasury sanctioned Evil Corp in December 2019 for its Dridex cybercrime operation, and reporting at the time traced the gang's back-end operations to an FSB-connected network. The Sinclair attribution shows what happened next: rather than disbanding, sources say the group relaunched under new names with a new ransomware strain, Macaw, aimed squarely at staying outside the sanctions perimeter.

That evasion playbook has since become the group's defining feature — Mandiant documented its move into a ransomware-as-a-service model specifically to launder attribution away from sanctioned actors, and by last year the UK NCA was alleging Kremlin-directed attacks on NATO allies, collapsing the distance between criminal brand and state interest.

First-order effects

  • Sinclair is hit by a strain whose operators are under active US sanctions, meaning any ransom negotiation carries legal exposure on top of operational disruption.
  • The Macaw branding lets Evil Corp resume attacks while complicating victim-side screening, since compliance checks keyed to sanctioned names won't flag the new labels.

Second-order effects

  • Enforcement now has to chase brands instead of people: each rename resets the matching work for Treasury, insurers, and incident responders who rely on family-name attribution.
  • The Mandiant-documented shift to ransomware-as-a-service gives the group affiliate cover, pushing other sanctioned or near-sanctioned crews toward the same franchise structure.

Third-order effects

  • If renaming-plus-RaaS keeps defeating list-based sanctions, policy drifts toward treating ransomware crews as state proxies rather than criminals — the direction the NCA's Kremlin-orders allegation already points.
  • For buyers, attribution stops being a due-diligence checkbox and becomes a live sanctions-compliance problem embedded in every ransomware incident.

The trend: Sanctioned ransomware groups are surviving enforcement through continuous rebranding and affiliate outsourcing, turning sanctions evasion into the organizing principle of the ransomware economy.