Evil Corp
View MITRE Group Page ↗Key Facts
- Attributed Country: Russian Federation.
- ATT&CK Group Reference: G0095 (Evil Corp).
- Linked to 1 primary court prosecution records.
- Identified 2 individually charged operatives.
Primary ATT&CK Techniques Employed
| Technique | Frequency |
|---|---|
| T1566.001 Spearphishing Attachment | 1 incidents |
| T1555 Credentials from Password Stores | 1 incidents |
| T1486 Data Encrypted for Impact | 1 incidents |
| T1055 Process Injection | 1 incidents |
| T1547.001 Registry Run Keys / Startup Folder | 1 incidents |
| T1053.005 Scheduled Task | 1 incidents |
| T1102 Web Service: Dead Drop Resolver | 1 incidents |
Prosecution Cases Attributed to This Actor
U.S. v. Yakubets & Turashev (Evil Corp / Dridex Banking Malware)
Leader and core administrator of Evil Corp charged with deploying Bugat/Dridex banking malware and ransomware, stealing dozens of millions of dollars from bank accounts of municipalities, school districts, and businesses.
Treasury OFAC Sanctions Actions
Financial facilitator and confederate of Evil Corp designated in joint US-UK enforcement action.
Official Treasury Press Release ↗State Department offers reward of up to $5,000,000 for information leading to the arrest or conviction of Maksim Yakubets for banking fraud and cyber extortion.
Official Treasury Press Release ↗Leader of Evil Corp cybercriminal syndicate responsible for Dridex banking trojan and multimillion-dollar ransomware extortions.
Official Treasury Press Release ↗Russian cybercrime organization that extorted over $100 million from financial institutions and healthcare providers.
Official Treasury Press Release ↗Targeted Defensive Hardening for Evil Corp
Primary Initial Access Defense
Enforce hardware FIDO2 multi-factor authentication across all perimeter VPN, Citrix, and cloud data portals. Prohibit SMS or push-based MFA that can be bypassed via vishing or SIM swapping.
Lateral Movement Interception
Restrict internal SMB (port 445) and RPC traversal between workstation subnets. Implement tiered Active Directory administration so domain administrator credentials are never cached on endpoints.