CASE DOSSIER fugitive

U.S. v. Aleksandr Sikerin & Yevgeniy Polyanin (REvil Operations)

Docket: 3:21-cr-00315 Court: U.S. District Court for the Northern District of Texas Opened: 2021-11-08 Sector: Local Government, Healthcare, Manufacturing

Key Facts

Status
FUGITIVE
Legal disposition
Loss Amount
$13.0 million
Extorted $13 million; federal seizure warrants recovered $6.1 million from crypto deposit wallets.
Techniques
1
Verified mappings
Defendants
1
Named in charges
  • Legal Status: FUGITIVE in U.S. District Court for the Northern District of Texas.
  • Primary Target Sector: Local Government, Healthcare, Manufacturing.
  • Documented Financial Loss: $13.0 million.
  • 1 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

International enforcement action against REvil ransomware money exchangers and operators, recovering $6.1 million in ransomware proceeds extorted from businesses and local governments across the United States.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Unauthorized intrusion originating from targeted infiltration directed against Local Government, Healthcare, Manufacturing networks. International enforcement action against REvil ransomware money exchangers and operators, recovering $6.1 million in ransomware proceeds extorted from businesses and local governments across the United States.

Operational & Financial Fallout

Extorted $13 million; federal seizure warrants recovered $6.1 million from crypto deposit wallets. Impacted Local Government, Healthcare, Manufacturing infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: FUGITIVE
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Unauthorized intrusion originating from targeted infiltration directed against Local Government, Healthcare, Manufacturing networks. International enforcement action against REvil ransomware money exchangers and operators, recovering $6.1 million in ransomware proceeds extorted from businesses and local governments across the United States.

Adversary Kill Chain Flow

1 Documented Phases
1
Phase 1: Impact Operational Disruption or Extortion Detonation
MITRE ATT&CK T1486 →

Polyanin deployed Sodinokibi/REvil ransomware against dozens of municipal government agencies across Texas, encrypting servers and demanding ransoms in Monero.

Artifacts & Tooling: T1486 Data Encrypted for Impact
Real-World Blast Radius & Operational Fallout

Extorted $13 million; federal seizure warrants recovered $6.1 million from crypto deposit wallets. Impacted Local Government, Healthcare, Manufacturing infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2021-11-08 indictment

DOJ unseals indictment against Polyanin and announces recovery of $6.1 million in extorted funds.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Yevgeniy Polyanin Russian Federation fugitive Pending $6.1 million REvil affiliate indicted in N.D. Tex.; $6.1 million in ransom proceeds recovered by DOJ.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1486 Data Encrypted for Impact
Impact
"Polyanin deployed Sodinokibi/REvil ransomware against dozens of municipal government agencies across Texas, encrypting servers and demanding ransoms in Monero." Indictment ¶ 14, Page 7 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Aleksandr Sikerin & Yevgeniy Polyanin (REvil Operations), No. 3:21-cr-00315 (U.S. District Court for the Northern District of Texas 2021), https://cybercaselibrary.com/cases/us-v-sikerin-polyanin-revil-affiliates/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-sikerin-polyanin-revil-affiliates" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>