The UK, US and Australia have issued a new round of sanctions against 16 members of Evil Corp. The announcement also revealed new individuals who are now believed to be part of the organisation. Additionally, the US unveiled an indictment against Aleksandr Ryzhenkov, the right-hand man of Maksim Yakubets, the leader of Evil Corp.
Ryzhenkov has also been identified by the NCA-led Operation Cronos as a LockBit affiliate. That information came from the analysis of data on servers that were seized when LockBit’s infrastructure was seized. It is more evidence of how the actions taken against cybercrime groups can impact their operations in the long term.
The announcement by the UK National Crime Agency (NCA), also details Evil Corps link to the Russian state and other malware groups. Part of that is contained in a history of the cybercrime group. It shows how it evolved from a family-centred organisation to an organisation with links to the Russian state.
James Babbage, Director General for Threats at the NCA, said: “The action announced today has taken place in conjunction with extensive and complex investigations by the NCA into two of the most harmful cybercrime groups of all time.
“These sanctions expose further members of Evil Corp, including one who was a LockBit affiliate, and those who were critical to enabling their activity.
“Since we supported US action against Evil Corp in 2019, members have amended their tactics and the harms attributed to the group have reduced significantly. We expect these new designations to also disrupt their ongoing criminal activity.”
How the FSB protected Evil Corp
The relationship between Evil Corp and the FSB has always been close. Yakubets’ father-in-law, Eduard Benderskiy, was a former high-ranking FSB official. In its early days, Benderskiy got Evil Corp involved in acting on behalf of the Russian state. They were responsible for cyber-attacks and espionage operations against NATO.
After the first wave of indictments in 2019, that relationship protected the group from action by Russian authorities. It made them untouchable in Russia at a time when their network was being dismantled by law enforcement in other countries. It meant that they avoided arrest and sanctions but didn’t avoid the fragmentation of their network.
That break-up of Evil Corp led to the creation of new strains of ransomware and other malware. Some members even joined other cybercrime groups, such as LockBit. And that is where the story goes full circle.
The takedown of LockBit led to the identification of Ryzhenkov. France and Spain also arrested other people involved in LockBit, which provided significant intelligence to law enforcement.
Enterprise Times: What does this mean?
Evil Corp is no longer the dangerous beast it once was, but it still continues to operate, albeit under the protection of the Russian state. It is one of the best-documented relationships between any state and a cybercrime group. Importantly, it shows how the FSB saw the benefit of working with such groups and having them perform operations on their behalf.
This latest set of sanctions and indictments are likely to have limited operational impact on the remaining members of Evil Corp. For those who are now being exposed publicly it will result in them having to be more careful in where they travel and restrict what they can do. However, its state backers, won’t act to cut off the flow of funds or allow action against them in territory they control.
This is more about sending a message to the wider cybercrime community. Law enforcement agencies are saying that when we seize infrastructure, we will analyze the data. That will result in more intelligence-led operations to identify people and groups against whom action will be taken.

















