{
  "id": "case-trickbot-witte",
  "slug": "us-v-witte-dunaev-trickbot",
  "title": "U.S. v. Alla Witte & Vladimir Dunaev (Trickbot Malware Group)",
  "summary": "Key software developers and coders of the transnational Trickbot cybercrime group charged with infecting millions of victim computers with banking trojans and facilitating Conti/Ryuk ransomware deployments against hospitals.",
  "case_number": "1:20-cr-00384",
  "court": "U.S. District Court for the Northern District of Ohio",
  "district": "N.D. Ohio",
  "country": "United States",
  "opened_at": "2021-02-18",
  "status": "sentenced",
  "victim_sector": "Healthcare, Banking, Local Government",
  "victim_country": "United States, United Kingdom, Australia",
  "loss_amount_usd": 180000000,
  "loss_amount_note": "Extorted tens of millions of dollars and caused hundreds of millions in financial damages to hospitals and municipalities.",
  "first_seen_at": "2016-10-01T00:00:00Z",
  "last_updated_at": "2026-08-30T10:00:00Z",
  "actor_slug": "wizard-spider",
  "defendant_slugs": [
    "alla-witte",
    "vladimir-dunaev"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1566.001",
      "evidence_excerpt": "Trickbot was deployed via phishing emails masquerading as legal notices containing weaponized Word documents with malicious macros.",
      "evidence_locator": "Indictment \u00b6 14, Page 7",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Witte et al.",
      "source_url": "https://www.justice.gov/opa/pr/russian-national-sentenced-role-developing-and-deploying-trickbot-malware",
      "technique_name": "Spearphishing Attachment",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1003",
      "evidence_excerpt": "Injected modular credential harvesters that pulled domain credentials from Windows memory to pave the way for ransomware.",
      "evidence_locator": "Indictment \u00b6 19, Page 11",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment",
      "source_url": "https://www.justice.gov/opa/pr/russian-national-sentenced-role-developing-and-deploying-trickbot-malware",
      "technique_name": "OS Credential Dumping",
      "tactic": "Credential Access"
    },
    {
      "technique_id": "T1486",
      "evidence_excerpt": "Trickbot acted as the primary access loader for Ryuk and Conti ransomware gangs targeting US medical facilities.",
      "evidence_locator": "CISA Advisory AA20-302A",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA20-302A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-302a",
      "technique_name": "Data Encrypted for Impact",
      "tactic": "Impact"
    }
  ],
  "events": [
    {
      "event_type": "extradition",
      "event_date": "2021-06-04",
      "description": "Alla Witte extradited from Suriname to the Northern District of Ohio."
    },
    {
      "event_type": "extradition",
      "event_date": "2021-10-20",
      "description": "Vladimir Dunaev extradited from the Republic of Korea to the Northern District of Ohio."
    },
    {
      "event_type": "sentencing",
      "event_date": "2023-06-20",
      "description": "Alla Witte sentenced to 32 months in prison after pleading guilty."
    },
    {
      "event_type": "sentencing",
      "event_date": "2024-01-24",
      "description": "Vladimir Dunaev sentenced to 64 months (5 years and 4 months) in federal prison."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Adversary breached the target network via Spearphishing Attachment. Trickbot was deployed via phishing emails masquerading as legal notices containing weaponized Word documents with malicious macros.",
    "blast_radius": "Extorted tens of millions of dollars and caused hundreds of millions in financial damages to hospitals and municipalities. Impacted Healthcare, Banking, Local Government infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Initial Access",
        "title": "Initial Perimeter Infiltration",
        "description": "Trickbot was deployed via phishing emails masquerading as legal notices containing weaponized Word documents with malicious macros.",
        "technical_artifacts": [
          "T1566.001",
          "Spearphishing Attachment"
        ],
        "mitre_technique_id": "T1566.001"
      },
      {
        "phase": "Phase 2: Credential Access",
        "title": "Credential Harvesting & Memory Dumping",
        "description": "Injected modular credential harvesters that pulled domain credentials from Windows memory to pave the way for ransomware.",
        "technical_artifacts": [
          "T1003",
          "OS Credential Dumping"
        ],
        "mitre_technique_id": "T1003"
      },
      {
        "phase": "Phase 3: Impact",
        "title": "Operational Disruption or Extortion Detonation",
        "description": "Trickbot acted as the primary access loader for Ryuk and Conti ransomware gangs targeting US medical facilities.",
        "technical_artifacts": [
          "T1486",
          "Data Encrypted for Impact"
        ],
        "mitre_technique_id": "T1486"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}