U.S. v. Alla Witte & Vladimir Dunaev (Trickbot Malware Group)
Key Facts
- Legal Status: SENTENCED in U.S. District Court for the Northern District of Ohio.
- Primary Target Sector: Healthcare, Banking, Local Government.
- Documented Financial Loss: $180.0 million.
- 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Adversary breached the target network via Spearphishing Attachment. Trickbot was deployed via phishing emails masquerading as legal notices containing weaponized Word documents with malicious macros.
Operational & Financial Fallout
Extorted tens of millions of dollars and caused hundreds of millions in financial damages to hospitals and municipalities. Impacted Healthcare, Banking, Local Government infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Adversary breached the target network via Spearphishing Attachment. Trickbot was deployed via phishing emails masquerading as legal notices containing weaponized Word documents with malicious macros.
Adversary Kill Chain Flow
3 Documented PhasesTrickbot was deployed via phishing emails masquerading as legal notices containing weaponized Word documents with malicious macros.
Injected modular credential harvesters that pulled domain credentials from Windows memory to pave the way for ransomware.
Trickbot acted as the primary access loader for Ryuk and Conti ransomware gangs targeting US medical facilities.
Extorted tens of millions of dollars and caused hundreds of millions in financial damages to hospitals and municipalities. Impacted Healthcare, Banking, Local Government infrastructure and associated victim operations.
Procedural & Incident Timeline
Alla Witte extradited from Suriname to the Northern District of Ohio.
Vladimir Dunaev extradited from the Republic of Korea to the Northern District of Ohio.
Alla Witte sentenced to 32 months in prison after pleading guilty.
Vladimir Dunaev sentenced to 64 months (5 years and 4 months) in federal prison.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Alla Witte | Latvia | sentenced | 32 mo | None | Trickbot ransomware management software programmer. Sentenced to 32 months in prison. |
| Vladimir Dunaev | Russian Federation | sentenced | 64 mo | None | Trickbot developer responsible for browser injection modules. Sentenced to 64 months in prison. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1566.001 | Spearphishing Attachment Initial Access | "Trickbot was deployed via phishing emails masquerading as legal notices containing weaponized Word documents with malicious macros." | Indictment ¶ 14, Page 7 | reviewed |
| T1003 | OS Credential Dumping Credential Access | "Injected modular credential harvesters that pulled domain credentials from Windows memory to pave the way for ransomware." | Indictment ¶ 19, Page 11 | reviewed |
| T1486 | Data Encrypted for Impact Impact | "Trickbot acted as the primary access loader for Ryuk and Conti ransomware gangs targeting US medical facilities." | CISA Advisory AA20-302A | reviewed |