CASE DOSSIER sentenced

U.S. v. Maksim Boiko (QQAAZZ Cyber Laundering Network)

Docket: 2:20-cr-00227 Court: U.S. District Court for the Western District of Pennsylvania Opened: 2020-09-15 Sector: Financial Institutions, Ransomware Victims

Key Facts

Status
SENTENCED
Legal disposition
Loss Amount
$20.0 million
Laundered tens of millions of dollars stolen from corporate victims via hundreds of dummy shell bank accounts across Europe.
Techniques
1
Verified mappings
Defendants
1
Named in charges
  • Legal Status: SENTENCED in U.S. District Court for the Western District of Pennsylvania.
  • Primary Target Sector: Financial Institutions, Ransomware Victims.
  • Documented Financial Loss: $20.0 million.
  • 1 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Russian cryptocurrency trader and Instagram influencer who operated as a high-level money launderer for QQAAZZ, an all-in-one cashout network servicing Dridex, Trickbot, and BitPaymer ransomware gangs.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Unauthorized intrusion originating from targeted infiltration directed against Financial Institutions, Ransomware Victims networks. Russian cryptocurrency trader and Instagram influencer who operated as a high-level money launderer for QQAAZZ, an all-in-one cashout network servicing Dridex, Trickbot, and BitPaymer ransomware gangs.

Operational & Financial Fallout

Laundered tens of millions of dollars stolen from corporate victims via hundreds of dummy shell bank accounts across Europe. Impacted Financial Institutions, Ransomware Victims infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: SENTENCED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Unauthorized intrusion originating from targeted infiltration directed against Financial Institutions, Ransomware Victims networks. Russian cryptocurrency trader and Instagram influencer who operated as a high-level money launderer for QQAAZZ, an all-in-one cashout network servicing Dridex, Trickbot, and BitPaymer ransomware gangs.

Adversary Kill Chain Flow

2 Documented Phases
1
Phase 1: Infiltration Perimeter Ingress
MITRE ATT&CK T1190 →

Operatives secured access to victim infrastructure within the Financial Institutions, Ransomware Victims sector.

Artifacts & Tooling: Network perimeter logs
2
Phase 2: Execution Payload Deployment
MITRE ATT&CK T1486 →

Russian cryptocurrency trader and Instagram influencer who operated as a high-level money launderer for QQAAZZ, an all-in-one cashout network servicing Dridex, Trickbot, and BitPaymer ransomware gangs.

Artifacts & Tooling: Malicious payload
Real-World Blast Radius & Operational Fallout

Laundered tens of millions of dollars stolen from corporate victims via hundreds of dummy shell bank accounts across Europe. Impacted Financial Institutions, Ransomware Victims infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2020-03-28 arrest

Boiko arrested in Miami, Florida, with $3.8 million in seized cryptocurrency.

2021-04-12 plea

Pleads guilty to conspiracy to commit money laundering in federal court in Pittsburgh.

2021-07-16 sentencing

Sentenced to time served and ordered to forfeit over $3.8 million in illicit cryptocurrency.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Maksim Boiko Russian Federation sentenced Pending $3 QQAAZZ cybercrime laundering network conspirator; sentenced to time served and $3.8M forfeiture.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1090 Proxy
Command and Control
"QQAAZZ used hundreds of bank accounts opened in the names of fake shell companies to rapidly layer stolen wire funds before converting them into Bitcoin." Indictment ¶ 16, Page 9 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Maksim Boiko (QQAAZZ Cyber Laundering Network), No. 2:20-cr-00227 (U.S. District Court for the Western District of Pennsylvania 2020), https://cybercaselibrary.com/cases/us-v-boiko-qqaazz-laundering/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-boiko-qqaazz-laundering" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>