Mandiant: the Russia-based cybercriminal group known as Evil Corp has shifted to a ransomware-as-a-service model in an effort to evade 2019 US sanctions
The Russia-based cybercriminal group known as Evil Corp has shifted to a ransomware-as-a-service model in an effort to skirt U.S. sanctions …
Context & Ripple Effects
The DOJ charges and Treasury sanctions of December 2019 hit Evil Corp directly, naming the group behind the Dridex banking malware and freezing its ability to be paid in US-linked dollars. Since then the gang has been iterating on deniability — Bloomberg sources tied it to the Sinclair ransomware attack under changed names — and Mandiant's new reporting describes the next step: renting out its ransomware rather than deploying it itself.
The move matters because it attacks the mechanism of the sanctions rather than the sanction itself: if affiliates collect the ransoms, the Treasury designation no longer maps cleanly onto who gets paid. The UK NCA's later claim that Evil Corp ran attacks and espionage against NATO allies on Kremlin orders raises the stakes of getting attribution right.
First-order effects
- Evil Corp's direct operators are insulated from payment flows: affiliates running the rented ransomware collect victim payments, so money reaching the sanctioned core is harder for OFAC and banks to trace and block.
- Victims and their negotiators now face a sharper compliance trap — paying what looks like an ordinary affiliate could still route funds to a sanctioned group, as the Sinclair case showed.
Second-order effects
- Other sanctioned or sanction-adjacent crews have a template to copy: franchise the malware, keep the brand fluid, and let the affiliate layer absorb the legal exposure — accelerating the fragmentation Mandiant is describing.
- Insurers, incident responders and payment processors must spend more on attribution screening before any ransom decision, raising transaction costs across the entire ransomware negotiation chain.
Third-order effects
- Sanctions enforcement shifts from naming groups to proving attribution in near-real time — a race the state side is also running, given the NCA's claim of Kremlin-directed operations.
- The model faces its own counter-trend: law-enforcement disruption and exit scams are already pushing criminals away from large ransomware-as-a-service platforms, so Evil Corp's pivot bets that sanction evasion outweighs the growing fragility of the RaaS market itself.
The trend: Financial sanctions are restructuring ransomware from branded operator-run extortion into distributed franchise networks designed to sever the link between who deploys the malware and who gets paid.