{
  "id": "case-netwalker-vachon",
  "slug": "us-v-vachon-desjardins-netwalker",
  "title": "U.S. v. Vachon-Desjardins (Netwalker Ransomware)",
  "summary": "Affiliate of Netwalker ransomware responsible for attacking dozens of healthcare systems, universities, and businesses during the COVID-19 pandemic, extorting tens of millions of dollars.",
  "case_number": "8:20-cr-00366",
  "court": "U.S. District Court for the Middle District of Florida",
  "district": "M.D. Fla.",
  "country": "United States",
  "opened_at": "2020-12-16",
  "status": "sentenced",
  "victim_sector": "Healthcare, Education, Municipal Government",
  "victim_country": "United States, Canada",
  "loss_amount_usd": 21500000,
  "loss_amount_note": "Extorted $21.5 million in ransom payments; law enforcement seized 719 Bitcoin ($28 million) from his Canadian residence.",
  "first_seen_at": "2020-04-01T00:00:00Z",
  "last_updated_at": "2026-09-11T16:00:00Z",
  "actor_slug": "netwalker",
  "defendant_slugs": [
    "sebastien-vachon-desjardins"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1486",
      "evidence_excerpt": "Defendant injected Netwalker ransomware payloads into victim enterprise environments, encrypting files and leaving extortion notes with victim-specific payment portals.",
      "evidence_locator": "Plea Agreement \u00b6 4, Page 12",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Plea Agreement: U.S. v. Vachon-Desjardins",
      "source_url": "https://www.justice.gov/opa/pr/netwalker-ransomware-affiliate-sentenced-20-years-prison-role-international-cybercrime-scheme",
      "technique_name": "Data Encrypted for Impact",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Vachon-Desjardins obtained unauthorized access to corporate networks by purchasing stolen Remote Desktop Protocol credentials.",
      "evidence_locator": "Plea Agreement \u00b6 4, Page 13",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Plea Agreement",
      "source_url": "https://www.justice.gov/opa/pr/netwalker-ransomware-affiliate-sentenced-20-years-prison-role-international-cybercrime-scheme",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1490",
      "evidence_excerpt": "Before executing the ransomware payload, defendant disabled shadow copies and altered registry settings to prevent recovery.",
      "evidence_locator": "Indictment \u00b6 8",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Vachon-Desjardins",
      "source_url": "https://www.justice.gov/opa/pr/netwalker-ransomware-affiliate-sentenced-20-years-prison-role-international-cybercrime-scheme",
      "technique_name": "Inhibit System Recovery",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1112",
      "evidence_excerpt": "Netwalker modified registry keys under HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa to weaken local security authority validation.",
      "evidence_locator": "Plea Agreement \u00b6 6, Page 14",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Plea Agreement",
      "source_url": "https://www.justice.gov/opa/pr/netwalker-ransomware-affiliate-sentenced-20-years-prison-role-international-cybercrime-scheme",
      "technique_name": "Modify Registry",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1548.002",
      "evidence_excerpt": "The attacker used CMSTP and eventvwr.exe registry hijack methods to bypass Windows User Account Control without user prompting.",
      "evidence_locator": "Indictment \u00b6 11, Page 6",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment",
      "source_url": "https://www.justice.gov/opa/pr/netwalker-ransomware-affiliate-sentenced-20-years-prison-role-international-cybercrime-scheme",
      "technique_name": "Bypass User Account Control",
      "tactic": "Privilege Escalation"
    },
    {
      "technique_id": "T1007",
      "evidence_excerpt": "Vachon-Desjardins executed net start and sc query to enumerate installed antivirus services before deploying ransomware.",
      "evidence_locator": "Plea Agreement \u00b6 5, Page 13",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Plea Agreement",
      "source_url": "https://www.justice.gov/opa/pr/netwalker-ransomware-affiliate-sentenced-20-years-prison-role-international-cybercrime-scheme",
      "technique_name": "System Service Discovery",
      "tactic": "Discovery"
    }
  ],
  "events": [
    {
      "event_type": "indictment",
      "event_date": "2020-12-16",
      "description": "Federal grand jury in Tampa returns indictment charging Vachon-Desjardins with conspiracy to commit computer fraud and damage."
    },
    {
      "event_type": "extradition",
      "event_date": "2022-03-09",
      "description": "Vachon-Desjardins extradited from Canada to the United States."
    },
    {
      "event_type": "plea",
      "event_date": "2022-06-29",
      "description": "Defendant pleads guilty to all counts in the indictment."
    },
    {
      "event_type": "sentencing",
      "event_date": "2022-10-04",
      "description": "Sentenced to 240 months (20 years) in federal prison and ordered to forfeit $21.5 million."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Healthcare, Education, Municipal Government networks. Affiliate of Netwalker ransomware responsible for attacking dozens of healthcare systems, universities, and businesses during the COVID-19 pandemic, extorting tens of millions of dollars.",
    "blast_radius": "Extorted $21.5 million in ransom payments; law enforcement seized 719 Bitcoin ($28 million) from his Canadian residence. Impacted Healthcare, Education, Municipal Government infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Privilege Escalation",
        "title": "Privilege Escalation & Account Takeover",
        "description": "The attacker used CMSTP and eventvwr.exe registry hijack methods to bypass Windows User Account Control without user prompting.",
        "technical_artifacts": [
          "T1548.002",
          "Bypass User Account Control"
        ],
        "mitre_technique_id": "T1548.002"
      },
      {
        "phase": "Phase 2: Defense Evasion",
        "title": "Defense Evasion & Security Blindfolding",
        "description": "Vachon-Desjardins obtained unauthorized access to corporate networks by purchasing stolen Remote Desktop Protocol credentials.",
        "technical_artifacts": [
          "T1078",
          "Valid Accounts"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Phase 3: Discovery",
        "title": "Internal Subnet & Trust Reconnaissance",
        "description": "Vachon-Desjardins executed net start and sc query to enumerate installed antivirus services before deploying ransomware.",
        "technical_artifacts": [
          "T1007",
          "System Service Discovery"
        ],
        "mitre_technique_id": "T1007"
      },
      {
        "phase": "Phase 4: Impact",
        "title": "Operational Disruption or Extortion Detonation",
        "description": "Defendant injected Netwalker ransomware payloads into victim enterprise environments, encrypting files and leaving extortion notes with victim-specific payment portals.",
        "technical_artifacts": [
          "T1486",
          "Data Encrypted for Impact"
        ],
        "mitre_technique_id": "T1486"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}