U.S. v. Vachon-Desjardins (Netwalker Ransomware)
Key Facts
- Legal Status: SENTENCED in U.S. District Court for the Middle District of Florida.
- Primary Target Sector: Healthcare, Education, Municipal Government.
- Documented Financial Loss: $21.5 million.
- 6 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Unauthorized intrusion originating from targeted infiltration directed against Healthcare, Education, Municipal Government networks. Affiliate of Netwalker ransomware responsible for attacking dozens of healthcare systems, universities, and businesses during the COVID-19 pandemic, extorting tens of millions of dollars.
Operational & Financial Fallout
Extorted $21.5 million in ransom payments; law enforcement seized 719 Bitcoin ($28 million) from his Canadian residence. Impacted Healthcare, Education, Municipal Government infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Unauthorized intrusion originating from targeted infiltration directed against Healthcare, Education, Municipal Government networks. Affiliate of Netwalker ransomware responsible for attacking dozens of healthcare systems, universities, and businesses during the COVID-19 pandemic, extorting tens of millions of dollars.
Adversary Kill Chain Flow
4 Documented PhasesThe attacker used CMSTP and eventvwr.exe registry hijack methods to bypass Windows User Account Control without user prompting.
Vachon-Desjardins obtained unauthorized access to corporate networks by purchasing stolen Remote Desktop Protocol credentials.
Vachon-Desjardins executed net start and sc query to enumerate installed antivirus services before deploying ransomware.
Defendant injected Netwalker ransomware payloads into victim enterprise environments, encrypting files and leaving extortion notes with victim-specific payment portals.
Extorted $21.5 million in ransom payments; law enforcement seized 719 Bitcoin ($28 million) from his Canadian residence. Impacted Healthcare, Education, Municipal Government infrastructure and associated victim operations.
Procedural & Incident Timeline
Federal grand jury in Tampa returns indictment charging Vachon-Desjardins with conspiracy to commit computer fraud and damage.
Vachon-Desjardins extradited from Canada to the United States.
Defendant pleads guilty to all counts in the indictment.
Sentenced to 240 months (20 years) in federal prison and ordered to forfeit $21.5 million.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Sebastien Vachon-Desjardins | Canada | sentenced | 240 mo | $21.5 million | Netwalker ransomware affiliate sentenced to 20 years in federal prison with $21.5 million forfeiture. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1486 | Data Encrypted for Impact Impact | "Defendant injected Netwalker ransomware payloads into victim enterprise environments, encrypting files and leaving extortion notes with victim-specific payment portals." | Plea Agreement ¶ 4, Page 12 | reviewed |
| T1078 | Valid Accounts Defense Evasion | "Vachon-Desjardins obtained unauthorized access to corporate networks by purchasing stolen Remote Desktop Protocol credentials." | Plea Agreement ¶ 4, Page 13 | reviewed |
| T1490 | Inhibit System Recovery Impact | "Before executing the ransomware payload, defendant disabled shadow copies and altered registry settings to prevent recovery." | Indictment ¶ 8 | reviewed |
| T1112 | Modify Registry Defense Evasion | "Netwalker modified registry keys under HKLM\SYSTEM\CurrentControlSet\Control\Lsa to weaken local security authority validation." | Plea Agreement ¶ 6, Page 14 | reviewed |
| T1548.002 | Bypass User Account Control Privilege Escalation | "The attacker used CMSTP and eventvwr.exe registry hijack methods to bypass Windows User Account Control without user prompting." | Indictment ¶ 11, Page 6 | reviewed |
| T1007 | System Service Discovery Discovery | "Vachon-Desjardins executed net start and sc query to enumerate installed antivirus services before deploying ransomware." | Plea Agreement ¶ 5, Page 13 | reviewed |