/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Mandiant: the Russia-based cybercriminal group known as Evil Corp has shifted to a ransomware-as-a-service model in an effort to evade 2019 US sanctions

The Russia-based cybercriminal group known as Evil Corp has shifted to a ransomware-as-a-service model in an effort to skirt U.S. sanctions …

TechCrunch Carly Page

Context & Ripple Effects

The DOJ charges and Treasury sanctions of December 2019 hit Evil Corp directly, naming the group behind the Dridex banking malware and freezing its ability to be paid in US-linked dollars. Since then the gang has been iterating on deniability — Bloomberg sources tied it to the Sinclair ransomware attack under changed names — and Mandiant's new reporting describes the next step: renting out its ransomware rather than deploying it itself.

The move matters because it attacks the mechanism of the sanctions rather than the sanction itself: if affiliates collect the ransoms, the Treasury designation no longer maps cleanly onto who gets paid. The UK NCA's later claim that Evil Corp ran attacks and espionage against NATO allies on Kremlin orders raises the stakes of getting attribution right.

First-order effects

  • Evil Corp's direct operators are insulated from payment flows: affiliates running the rented ransomware collect victim payments, so money reaching the sanctioned core is harder for OFAC and banks to trace and block.
  • Victims and their negotiators now face a sharper compliance trap — paying what looks like an ordinary affiliate could still route funds to a sanctioned group, as the Sinclair case showed.

Second-order effects

  • Other sanctioned or sanction-adjacent crews have a template to copy: franchise the malware, keep the brand fluid, and let the affiliate layer absorb the legal exposure — accelerating the fragmentation Mandiant is describing.
  • Insurers, incident responders and payment processors must spend more on attribution screening before any ransom decision, raising transaction costs across the entire ransomware negotiation chain.

Third-order effects

  • Sanctions enforcement shifts from naming groups to proving attribution in near-real time — a race the state side is also running, given the NCA's claim of Kremlin-directed operations.
  • The model faces its own counter-trend: law-enforcement disruption and exit scams are already pushing criminals away from large ransomware-as-a-service platforms, so Evil Corp's pivot bets that sanction evasion outweighs the growing fragility of the RaaS market itself.

The trend: Financial sanctions are restructuring ransomware from branded operator-run extortion into distributed franchise networks designed to sever the link between who deploys the malware and who gets paid.