CASE DOSSIER fugitive

U.S. v. Yakubets & Turashev (Evil Corp / Dridex Banking Malware)

Docket: 2:19-cr-00336 Court: U.S. District Court for the Western District of Pennsylvania Opened: 2019-11-14 Sector: Banking, Financial Services, Municipalities, Education

Key Facts

Status
FUGITIVE
Legal disposition
Loss Amount
$100.0 million
Caused at least $100 million in verified financial losses; State Department offered a $5 million reward under Transnational Organized Crime Rewards Program.
Techniques
7
Verified mappings
Defendants
2
Named in charges
  • Legal Status: FUGITIVE in U.S. District Court for the Western District of Pennsylvania.
  • Primary Target Sector: Banking, Financial Services, Municipalities, Education.
  • Documented Financial Loss: $100.0 million.
  • 7 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Leader and core administrator of Evil Corp charged with deploying Bugat/Dridex banking malware and ransomware, stealing dozens of millions of dollars from bank accounts of municipalities, school districts, and businesses.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Adversary breached the target network via Spearphishing Attachment. Defendants distributed millions of phishing emails containing malicious macros disguised as invoices to infect corporate computers with Dridex.

Operational & Financial Fallout

Caused at least $100 million in verified financial losses; State Department offered a $5 million reward under Transnational Organized Crime Rewards Program. Impacted Banking, Financial Services, Municipalities, Education infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: FUGITIVE
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Adversary breached the target network via Spearphishing Attachment. Defendants distributed millions of phishing emails containing malicious macros disguised as invoices to infect corporate computers with Dridex.

Adversary Kill Chain Flow

5 Documented Phases
1
Phase 1: Initial Access Initial Perimeter Infiltration
MITRE ATT&CK T1566.001 →

Defendants distributed millions of phishing emails containing malicious macros disguised as invoices to infect corporate computers with Dridex.

Artifacts & Tooling: T1566.001 Spearphishing Attachment
2
Phase 2: Persistence Persistent Foothold Establishment
MITRE ATT&CK T1547.001 →

The malware wrote autorun entries into HKCU\Software\Microsoft\Windows\CurrentVersion\Run to maintain persistence across reboots.

Artifacts & Tooling: T1547.001 Registry Run Keys / Startup Folder
3
Phase 3: Defense Evasion Defense Evasion & Security Blindfolding
MITRE ATT&CK T1055 →

Dridex injected dynamic link library code into running Internet Explorer and Chrome browser processes to intercept HTTPS traffic.

Artifacts & Tooling: T1055 Process Injection
4
Phase 4: Credential Access Credential Harvesting & Memory Dumping
MITRE ATT&CK T1555 →

Dridex injected web forms into web browsers to capture online banking credentials, passcodes, and transaction authorization numbers.

Artifacts & Tooling: T1555 Credentials from Password Stores
5
Phase 5: Impact Operational Disruption or Extortion Detonation
MITRE ATT&CK T1486 →

In later operations, conspirators deployed BitPaymer and WastedLocker ransomware against compromised networks to extort ransoms exceeding $5 million per victim.

Artifacts & Tooling: T1486 Data Encrypted for Impact
Real-World Blast Radius & Operational Fallout

Caused at least $100 million in verified financial losses; State Department offered a $5 million reward under Transnational Organized Crime Rewards Program. Impacted Banking, Financial Services, Municipalities, Education infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2019-11-14 indictment

Federal grand jury indicts Maksim Viktorovich Yakubets and Igor Turashev for computer fraud, wire fraud, and bank fraud.

2019-12-05 sanction

OFAC sanctions Evil Corp, Yakubets, Turashev, and 15 associated confederates.

2024-10-01 sanction

Treasury and UK authorities unseal additional sanctions targeting Evil Corp family members and LockBit collaboration.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Maksim Viktorovich Yakubets Russian Federation fugitive Pending None Leader of Evil Corp cybercrime syndicate. Indicted in W.D. Pa. and sanctioned by OFAC.
Igor Olegovich Turashev Russian Federation fugitive Pending None Chief administrator and technical coordinator of Evil Corp's Dridex operations.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1566.001 Spearphishing Attachment
Initial Access
"Defendants distributed millions of phishing emails containing malicious macros disguised as invoices to infect corporate computers with Dridex." Indictment ¶ 19, Page 11 reviewed
T1555 Credentials from Password Stores
Credential Access
"Dridex injected web forms into web browsers to capture online banking credentials, passcodes, and transaction authorization numbers." Indictment ¶ 24, Page 14 reviewed
T1486 Data Encrypted for Impact
Impact
"In later operations, conspirators deployed BitPaymer and WastedLocker ransomware against compromised networks to extort ransoms exceeding $5 million per victim." Treasury Designation Announcement reviewed
T1055 Process Injection
Defense Evasion
"Dridex injected dynamic link library code into running Internet Explorer and Chrome browser processes to intercept HTTPS traffic." Indictment ¶ 23, Page 13 reviewed
T1547.001 Registry Run Keys / Startup Folder
Persistence
"The malware wrote autorun entries into HKCU\Software\Microsoft\Windows\CurrentVersion\Run to maintain persistence across reboots." Indictment ¶ 26, Page 15 reviewed
T1053.005 Scheduled Task
Persistence
"Conspirators created scheduled tasks via schtasks.exe to trigger periodic secondary bot payload downloads." CISA Advisory AA19-339A reviewed
T1102 Web Service: Dead Drop Resolver
Command and Control
"Dridex used public social media profile pages and paste sites as dead drop resolvers to retrieve active C2 IP addresses." CISA Technical Analysis Report reviewed

OFAC Sanctions Designations

Maksim Viktorovich Yakubets (Evil Corp Leader) (2019-12-05)

State Department offers reward of up to $5,000,000 for information leading to the arrest or conviction of Maksim Yakubets for banking fraud and cyber extortion.

Treasury Release ↗
Maksim Viktorovich Yakubets (2019-12-05)

Leader of Evil Corp cybercriminal syndicate responsible for Dridex banking trojan and multimillion-dollar ransomware extortions.

Treasury Release ↗

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Yakubets & Turashev (Evil Corp / Dridex Banking Malware), No. 2:19-cr-00336 (U.S. District Court for the Western District of Pennsylvania 2019), https://cybercaselibrary.com/cases/us-v-yakubets-evil-corp-dridex/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-yakubets-evil-corp-dridex" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>