NCA reveals sanctions on 16 members of Evil Corp (Image Credit: NCA)The UK, US and Australia have issued a new round of sanctions against 16 members of Evil Corp. The announcement also revealed new individuals who are now believed to be part of the organisation. Additionally, the US unveiled an indictment against Aleksandr Ryzhenkov, the right-hand man of Maksim Yakubets, the leader of Evil Corp.

Ryzhenkov has also been identified by the NCA-led Operation Cronos as a LockBit affiliate. That information came from the analysis of data on servers that were seized when LockBit’s infrastructure was seized. It is more evidence of how the actions taken against cybercrime groups can impact their operations in the long term.

The announcement by the UK National Crime Agency (NCA), also details Evil Corps link to the Russian state and other malware groups. Part of that is contained in a history of the cybercrime group. It shows how it evolved from a family-centred organisation to an organisation with links to the Russian state.

James Babbage, Director General for Threats at the NCA, said: “The action announced today has taken place in conjunction with extensive and complex investigations by the NCA into two of the most harmful cybercrime groups of all time.

“These sanctions expose further members of Evil Corp, including one who was a LockBit affiliate, and those who were critical to enabling their activity.

“Since we supported US action against Evil Corp in 2019, members have amended their tactics and the harms attributed to the group have reduced significantly. We expect these new designations to also disrupt their ongoing criminal activity.

How the FSB protected Evil Corp

The relationship between Evil Corp and the FSB has always been close. Yakubets’ father-in-law, Eduard Benderskiy, was a former high-ranking FSB official. In its early days, Benderskiy got Evil Corp involved in acting on behalf of the Russian state. They were responsible for cyber-attacks and espionage operations against NATO.

After the first wave of indictments in 2019, that relationship protected the group from action by Russian authorities. It made them untouchable in Russia at a time when their network was being dismantled by law enforcement in other countries. It meant that they avoided arrest and sanctions but didn’t avoid the fragmentation of their network.

That break-up of Evil Corp led to the creation of new strains of ransomware and other malware. Some members even joined other cybercrime groups, such as LockBit. And that is where the story goes full circle.

The takedown of LockBit led to the identification of Ryzhenkov. France and Spain also arrested other people involved in LockBit, which provided significant intelligence to law enforcement.

Enterprise Times: What does this mean?

Evil Corp is no longer the dangerous beast it once was, but it still continues to operate, albeit under the protection of the Russian state. It is one of the best-documented relationships between any state and a cybercrime group. Importantly, it shows how the FSB saw the benefit of working with such groups and having them perform operations on their behalf.

This latest set of sanctions and indictments are likely to have limited operational impact on the remaining members of Evil Corp. For those who are now being exposed publicly it will result in them having to be more careful in where they travel and restrict what they can do. However, its state backers, won’t act to cut off the flow of funds or allow action against them in territory they control.

This is more about sending a message to the wider cybercrime community. Law enforcement agencies are saying that when we seize infrastructure, we will analyze the data. That will result in more intelligence-led operations to identify people and groups against whom action will be taken.

Previous articleA conversation with Klient at Dreamforce 2024
Next articleThreatQuotient enables customers to scale security ops
Ian Murphy
Ian Murphy is an enterprise technology journalist, podcaster, editor and industry analyst with more than 40 years' experience covering enterprise IT, cybersecurity, networking, cloud and artificial intelligence. His career combines hands-on technology experience with long-term industry analysis and journalism. In the 1980s, Ian authored an industry report on expert systems, an early application of artificial intelligence, and founded an IT training company delivering accredited training on enterprise software. He later became a Microsoft Certified Trainer, helping professionals understand and apply business technologies. Alongside his work as a freelance journalist and analyst, Ian developed software, deployed enterprise networks and managed software and technical support teams. That practical experience informs his writing, providing insight into not only what technologies promise, but how they are implemented and used in real enterprise environments. Ian has written thousands of articles, produced industry research, hosted podcasts and interviewed technology leaders across enterprise software, infrastructure, cybersecurity and AI. His work focuses on helping CIOs, IT leaders and technology professionals understand the opportunities, challenges and real-world impact of emerging technologies.

LEAVE A REPLY

Please enter your comment!
Please enter your name here