U.S. v. Maksim Boiko (QQAAZZ Cyber Laundering Network)
Key Facts
- Legal Status: SENTENCED in U.S. District Court for the Western District of Pennsylvania.
- Primary Target Sector: Financial Institutions, Ransomware Victims.
- Documented Financial Loss: $20.0 million.
- 1 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Unauthorized intrusion originating from targeted infiltration directed against Financial Institutions, Ransomware Victims networks. Russian cryptocurrency trader and Instagram influencer who operated as a high-level money launderer for QQAAZZ, an all-in-one cashout network servicing Dridex, Trickbot, and BitPaymer ransomware gangs.
Operational & Financial Fallout
Laundered tens of millions of dollars stolen from corporate victims via hundreds of dummy shell bank accounts across Europe. Impacted Financial Institutions, Ransomware Victims infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Unauthorized intrusion originating from targeted infiltration directed against Financial Institutions, Ransomware Victims networks. Russian cryptocurrency trader and Instagram influencer who operated as a high-level money launderer for QQAAZZ, an all-in-one cashout network servicing Dridex, Trickbot, and BitPaymer ransomware gangs.
Adversary Kill Chain Flow
2 Documented PhasesOperatives secured access to victim infrastructure within the Financial Institutions, Ransomware Victims sector.
Russian cryptocurrency trader and Instagram influencer who operated as a high-level money launderer for QQAAZZ, an all-in-one cashout network servicing Dridex, Trickbot, and BitPaymer ransomware gangs.
Laundered tens of millions of dollars stolen from corporate victims via hundreds of dummy shell bank accounts across Europe. Impacted Financial Institutions, Ransomware Victims infrastructure and associated victim operations.
Procedural & Incident Timeline
Boiko arrested in Miami, Florida, with $3.8 million in seized cryptocurrency.
Pleads guilty to conspiracy to commit money laundering in federal court in Pittsburgh.
Sentenced to time served and ordered to forfeit over $3.8 million in illicit cryptocurrency.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Maksim Boiko | Russian Federation | sentenced | Pending | $3 | QQAAZZ cybercrime laundering network conspirator; sentenced to time served and $3.8M forfeiture. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1090 | Proxy Command and Control | "QQAAZZ used hundreds of bank accounts opened in the names of fake shell companies to rapidly layer stolen wire funds before converting them into Bitcoin." | Indictment ¶ 16, Page 9 | reviewed |