U.S. v. Yakubets & Turashev (Evil Corp / Dridex Banking Malware)
Key Facts
- Legal Status: FUGITIVE in U.S. District Court for the Western District of Pennsylvania.
- Primary Target Sector: Banking, Financial Services, Municipalities, Education.
- Documented Financial Loss: $100.0 million.
- 7 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Adversary breached the target network via Spearphishing Attachment. Defendants distributed millions of phishing emails containing malicious macros disguised as invoices to infect corporate computers with Dridex.
Operational & Financial Fallout
Caused at least $100 million in verified financial losses; State Department offered a $5 million reward under Transnational Organized Crime Rewards Program. Impacted Banking, Financial Services, Municipalities, Education infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Adversary breached the target network via Spearphishing Attachment. Defendants distributed millions of phishing emails containing malicious macros disguised as invoices to infect corporate computers with Dridex.
Adversary Kill Chain Flow
5 Documented PhasesDefendants distributed millions of phishing emails containing malicious macros disguised as invoices to infect corporate computers with Dridex.
The malware wrote autorun entries into HKCU\Software\Microsoft\Windows\CurrentVersion\Run to maintain persistence across reboots.
Dridex injected dynamic link library code into running Internet Explorer and Chrome browser processes to intercept HTTPS traffic.
Dridex injected web forms into web browsers to capture online banking credentials, passcodes, and transaction authorization numbers.
In later operations, conspirators deployed BitPaymer and WastedLocker ransomware against compromised networks to extort ransoms exceeding $5 million per victim.
Caused at least $100 million in verified financial losses; State Department offered a $5 million reward under Transnational Organized Crime Rewards Program. Impacted Banking, Financial Services, Municipalities, Education infrastructure and associated victim operations.
Procedural & Incident Timeline
Federal grand jury indicts Maksim Viktorovich Yakubets and Igor Turashev for computer fraud, wire fraud, and bank fraud.
OFAC sanctions Evil Corp, Yakubets, Turashev, and 15 associated confederates.
Treasury and UK authorities unseal additional sanctions targeting Evil Corp family members and LockBit collaboration.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Maksim Viktorovich Yakubets | Russian Federation | fugitive | Pending | None | Leader of Evil Corp cybercrime syndicate. Indicted in W.D. Pa. and sanctioned by OFAC. |
| Igor Olegovich Turashev | Russian Federation | fugitive | Pending | None | Chief administrator and technical coordinator of Evil Corp's Dridex operations. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1566.001 | Spearphishing Attachment Initial Access | "Defendants distributed millions of phishing emails containing malicious macros disguised as invoices to infect corporate computers with Dridex." | Indictment ¶ 19, Page 11 | reviewed |
| T1555 | Credentials from Password Stores Credential Access | "Dridex injected web forms into web browsers to capture online banking credentials, passcodes, and transaction authorization numbers." | Indictment ¶ 24, Page 14 | reviewed |
| T1486 | Data Encrypted for Impact Impact | "In later operations, conspirators deployed BitPaymer and WastedLocker ransomware against compromised networks to extort ransoms exceeding $5 million per victim." | Treasury Designation Announcement | reviewed |
| T1055 | Process Injection Defense Evasion | "Dridex injected dynamic link library code into running Internet Explorer and Chrome browser processes to intercept HTTPS traffic." | Indictment ¶ 23, Page 13 | reviewed |
| T1547.001 | Registry Run Keys / Startup Folder Persistence | "The malware wrote autorun entries into HKCU\Software\Microsoft\Windows\CurrentVersion\Run to maintain persistence across reboots." | Indictment ¶ 26, Page 15 | reviewed |
| T1053.005 | Scheduled Task Persistence | "Conspirators created scheduled tasks via schtasks.exe to trigger periodic secondary bot payload downloads." | CISA Advisory AA19-339A | reviewed |
| T1102 | Web Service: Dead Drop Resolver Command and Control | "Dridex used public social media profile pages and paste sites as dead drop resolvers to retrieve active C2 IP addresses." | CISA Technical Analysis Report | reviewed |
OFAC Sanctions Designations
State Department offers reward of up to $5,000,000 for information leading to the arrest or conviction of Maksim Yakubets for banking fraud and cyber extortion.
Treasury Release ↗Leader of Evil Corp cybercriminal syndicate responsible for Dridex banking trojan and multimillion-dollar ransomware extortions.
Treasury Release ↗