{
  "id": "case-boiko-qqaazz",
  "slug": "us-v-boiko-qqaazz-laundering",
  "title": "U.S. v. Maksim Boiko (QQAAZZ Cyber Laundering Network)",
  "summary": "Russian cryptocurrency trader and Instagram influencer who operated as a high-level money launderer for QQAAZZ, an all-in-one cashout network servicing Dridex, Trickbot, and BitPaymer ransomware gangs.",
  "case_number": "2:20-cr-00227",
  "court": "U.S. District Court for the Western District of Pennsylvania",
  "district": "W.D. Pa.",
  "country": "United States",
  "opened_at": "2020-09-15",
  "status": "sentenced",
  "victim_sector": "Financial Institutions, Ransomware Victims",
  "victim_country": "United States, United Kingdom, Latvia, Georgia",
  "loss_amount_usd": 20000000,
  "loss_amount_note": "Laundered tens of millions of dollars stolen from corporate victims via hundreds of dummy shell bank accounts across Europe.",
  "first_seen_at": "2016-01-01T00:00:00Z",
  "last_updated_at": "2026-07-10T14:00:00Z",
  "actor_slug": "qqaazz",
  "defendant_slugs": [
    "maksim-boiko"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1090",
      "evidence_excerpt": "QQAAZZ used hundreds of bank accounts opened in the names of fake shell companies to rapidly layer stolen wire funds before converting them into Bitcoin.",
      "evidence_locator": "Indictment \u00b6 16, Page 9",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Boiko",
      "source_url": "https://www.justice.gov/opa/pr/fourteen-alleged-members-qqaazz-cybercrime-network-charged-laundering-millions-stolen-cyber",
      "technique_name": "Proxy",
      "tactic": "Command and Control"
    }
  ],
  "events": [
    {
      "event_type": "arrest",
      "event_date": "2020-03-28",
      "description": "Boiko arrested in Miami, Florida, with $3.8 million in seized cryptocurrency."
    },
    {
      "event_type": "plea",
      "event_date": "2021-04-12",
      "description": "Pleads guilty to conspiracy to commit money laundering in federal court in Pittsburgh."
    },
    {
      "event_type": "sentencing",
      "event_date": "2021-07-16",
      "description": "Sentenced to time served and ordered to forfeit over $3.8 million in illicit cryptocurrency."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Financial Institutions, Ransomware Victims networks. Russian cryptocurrency trader and Instagram influencer who operated as a high-level money launderer for QQAAZZ, an all-in-one cashout network servicing Dridex, Trickbot, and BitPaymer ransomware gangs.",
    "blast_radius": "Laundered tens of millions of dollars stolen from corporate victims via hundreds of dummy shell bank accounts across Europe. Impacted Financial Institutions, Ransomware Victims infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Infiltration",
        "title": "Perimeter Ingress",
        "description": "Operatives secured access to victim infrastructure within the Financial Institutions, Ransomware Victims sector.",
        "technical_artifacts": [
          "Network perimeter logs"
        ],
        "mitre_technique_id": "T1190"
      },
      {
        "phase": "Phase 2: Execution",
        "title": "Payload Deployment",
        "description": "Russian cryptocurrency trader and Instagram influencer who operated as a high-level money launderer for QQAAZZ, an all-in-one cashout network servicing Dridex, Trickbot, and BitPaymer ransomware gangs.",
        "technical_artifacts": [
          "Malicious payload"
        ],
        "mitre_technique_id": "T1486"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}