MITRE ATT&CK G0095
Aliases: Indiktor, Dridex Gang
Official Attribution Source: U.S. Department of Justice (W.D. Pa.) & OFAC Sanctions

Key Facts

Jurisdiction
Russian Federation
Geographic origin
Cases
1
Prosecution matters
Defendants
2
Indicted individuals
Sanctions
4
OFAC designations
  • Attributed Country: Russian Federation.
  • ATT&CK Group Reference: G0095 (Evil Corp).
  • Linked to 1 primary court prosecution records.
  • Identified 2 individually charged operatives.

Primary ATT&CK Techniques Employed

ATT&CK Techniques Mapped to Evil Corp Technique frequencies extracted from verified indictments for Evil Corp. T1566.001 Spearphishing Attachment 1 incidents T1555 Credentials from Password Stores 1 incidents T1486 Data Encrypted for Impact 1 incidents T1055 Process Injection 1 incidents T1547.001 Registry Run Keys / Startup Folder 1 incidents T1053.005 Scheduled Task 1 incidents T1102 Web Service: Dead Drop Resolver 1 incidents
Technique frequencies extracted from verified indictments for Evil Corp.
ATT&CK Techniques Mapped to Evil Corp
Technique Frequency
T1566.001 Spearphishing Attachment 1 incidents
T1555 Credentials from Password Stores 1 incidents
T1486 Data Encrypted for Impact 1 incidents
T1055 Process Injection 1 incidents
T1547.001 Registry Run Keys / Startup Folder 1 incidents
T1053.005 Scheduled Task 1 incidents
T1102 Web Service: Dead Drop Resolver 1 incidents

Prosecution Cases Attributed to This Actor

fugitive 2019-11-14

U.S. v. Yakubets & Turashev (Evil Corp / Dridex Banking Malware)

Leader and core administrator of Evil Corp charged with deploying Bugat/Dridex banking malware and ransomware, stealing dozens of millions of dollars from bank accounts of municipalities, school districts, and businesses.

7 techniques View case →

Treasury OFAC Sanctions Actions

Karyna Kostiantynivna 2024-10-01

Financial facilitator and confederate of Evil Corp designated in joint US-UK enforcement action.

Official Treasury Press Release ↗
Maksim Viktorovich Yakubets (Evil Corp Leader) 2019-12-05

State Department offers reward of up to $5,000,000 for information leading to the arrest or conviction of Maksim Yakubets for banking fraud and cyber extortion.

Official Treasury Press Release ↗
Maksim Viktorovich Yakubets 2019-12-05

Leader of Evil Corp cybercriminal syndicate responsible for Dridex banking trojan and multimillion-dollar ransomware extortions.

Official Treasury Press Release ↗
Evil Corp (Dridex Cybercrime Syndicate) 2019-12-05

Russian cybercrime organization that extorted over $100 million from financial institutions and healthcare providers.

Official Treasury Press Release ↗
OPERATIONAL DEFENSE

Targeted Defensive Hardening for Evil Corp

Run Stack Audit →

Primary Initial Access Defense

Enforce hardware FIDO2 multi-factor authentication across all perimeter VPN, Citrix, and cloud data portals. Prohibit SMS or push-based MFA that can be bypassed via vishing or SIM swapping.

Lateral Movement Interception

Restrict internal SMB (port 445) and RPC traversal between workstation subnets. Implement tiered Active Directory administration so domain administrator credentials are never cached on endpoints.