CASE DOSSIER sentenced

U.S. v. Alla Witte & Vladimir Dunaev (Trickbot Malware Group)

Docket: 1:20-cr-00384 Court: U.S. District Court for the Northern District of Ohio Opened: 2021-02-18 Sector: Healthcare, Banking, Local Government

Key Facts

Status
SENTENCED
Legal disposition
Loss Amount
$180.0 million
Extorted tens of millions of dollars and caused hundreds of millions in financial damages to hospitals and municipalities.
Techniques
3
Verified mappings
Defendants
2
Named in charges
  • Legal Status: SENTENCED in U.S. District Court for the Northern District of Ohio.
  • Primary Target Sector: Healthcare, Banking, Local Government.
  • Documented Financial Loss: $180.0 million.
  • 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Key software developers and coders of the transnational Trickbot cybercrime group charged with infecting millions of victim computers with banking trojans and facilitating Conti/Ryuk ransomware deployments against hospitals.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Adversary breached the target network via Spearphishing Attachment. Trickbot was deployed via phishing emails masquerading as legal notices containing weaponized Word documents with malicious macros.

Operational & Financial Fallout

Extorted tens of millions of dollars and caused hundreds of millions in financial damages to hospitals and municipalities. Impacted Healthcare, Banking, Local Government infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: SENTENCED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Adversary breached the target network via Spearphishing Attachment. Trickbot was deployed via phishing emails masquerading as legal notices containing weaponized Word documents with malicious macros.

Adversary Kill Chain Flow

3 Documented Phases
1
Phase 1: Initial Access Initial Perimeter Infiltration
MITRE ATT&CK T1566.001 →

Trickbot was deployed via phishing emails masquerading as legal notices containing weaponized Word documents with malicious macros.

Artifacts & Tooling: T1566.001 Spearphishing Attachment
2
Phase 2: Credential Access Credential Harvesting & Memory Dumping
MITRE ATT&CK T1003 →

Injected modular credential harvesters that pulled domain credentials from Windows memory to pave the way for ransomware.

Artifacts & Tooling: T1003 OS Credential Dumping
3
Phase 3: Impact Operational Disruption or Extortion Detonation
MITRE ATT&CK T1486 →

Trickbot acted as the primary access loader for Ryuk and Conti ransomware gangs targeting US medical facilities.

Artifacts & Tooling: T1486 Data Encrypted for Impact
Real-World Blast Radius & Operational Fallout

Extorted tens of millions of dollars and caused hundreds of millions in financial damages to hospitals and municipalities. Impacted Healthcare, Banking, Local Government infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2021-06-04 extradition

Alla Witte extradited from Suriname to the Northern District of Ohio.

2021-10-20 extradition

Vladimir Dunaev extradited from the Republic of Korea to the Northern District of Ohio.

2023-06-20 sentencing

Alla Witte sentenced to 32 months in prison after pleading guilty.

2024-01-24 sentencing

Vladimir Dunaev sentenced to 64 months (5 years and 4 months) in federal prison.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Alla Witte Latvia sentenced 32 mo None Trickbot ransomware management software programmer. Sentenced to 32 months in prison.
Vladimir Dunaev Russian Federation sentenced 64 mo None Trickbot developer responsible for browser injection modules. Sentenced to 64 months in prison.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1566.001 Spearphishing Attachment
Initial Access
"Trickbot was deployed via phishing emails masquerading as legal notices containing weaponized Word documents with malicious macros." Indictment ¶ 14, Page 7 reviewed
T1003 OS Credential Dumping
Credential Access
"Injected modular credential harvesters that pulled domain credentials from Windows memory to pave the way for ransomware." Indictment ¶ 19, Page 11 reviewed
T1486 Data Encrypted for Impact
Impact
"Trickbot acted as the primary access loader for Ryuk and Conti ransomware gangs targeting US medical facilities." CISA Advisory AA20-302A reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Alla Witte & Vladimir Dunaev (Trickbot Malware Group), No. 1:20-cr-00384 (U.S. District Court for the Northern District of Ohio 2021), https://cybercaselibrary.com/cases/us-v-witte-dunaev-trickbot/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-witte-dunaev-trickbot" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>