{
  "id": "case-evil-corp-yakubets",
  "slug": "us-v-yakubets-evil-corp-dridex",
  "title": "U.S. v. Yakubets & Turashev (Evil Corp / Dridex Banking Malware)",
  "summary": "Leader and core administrator of Evil Corp charged with deploying Bugat/Dridex banking malware and ransomware, stealing dozens of millions of dollars from bank accounts of municipalities, school districts, and businesses.",
  "case_number": "2:19-cr-00336",
  "court": "U.S. District Court for the Western District of Pennsylvania",
  "district": "W.D. Pa.",
  "country": "United States",
  "opened_at": "2019-11-14",
  "status": "fugitive",
  "victim_sector": "Banking, Financial Services, Municipalities, Education",
  "victim_country": "United States, United Kingdom",
  "loss_amount_usd": 100000000,
  "loss_amount_note": "Caused at least $100 million in verified financial losses; State Department offered a $5 million reward under Transnational Organized Crime Rewards Program.",
  "first_seen_at": "2011-05-01T00:00:00Z",
  "last_updated_at": "2026-09-10T12:00:00Z",
  "actor_slug": "evil-corp",
  "defendant_slugs": [
    "maksim-yakubets",
    "igor-turashev"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1566.001",
      "evidence_excerpt": "Defendants distributed millions of phishing emails containing malicious macros disguised as invoices to infect corporate computers with Dridex.",
      "evidence_locator": "Indictment \u00b6 19, Page 11",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Yakubets",
      "source_url": "https://www.justice.gov/opa/pr/russian-national-indicted-charges-related-massive-cyber-attacks-stealing-tens-millions-dollars",
      "technique_name": "Spearphishing Attachment",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1555",
      "evidence_excerpt": "Dridex injected web forms into web browsers to capture online banking credentials, passcodes, and transaction authorization numbers.",
      "evidence_locator": "Indictment \u00b6 24, Page 14",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Yakubets",
      "source_url": "https://www.justice.gov/opa/pr/russian-national-indicted-charges-related-massive-cyber-attacks-stealing-tens-millions-dollars",
      "technique_name": "Credentials from Password Stores",
      "tactic": "Credential Access"
    },
    {
      "technique_id": "T1486",
      "evidence_excerpt": "In later operations, conspirators deployed BitPaymer and WastedLocker ransomware against compromised networks to extort ransoms exceeding $5 million per victim.",
      "evidence_locator": "Treasury Designation Announcement",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "OFAC Sanctions Action",
      "source_url": "https://home.treasury.gov/news/press-releases/sm845",
      "technique_name": "Data Encrypted for Impact",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1055",
      "evidence_excerpt": "Dridex injected dynamic link library code into running Internet Explorer and Chrome browser processes to intercept HTTPS traffic.",
      "evidence_locator": "Indictment \u00b6 23, Page 13",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Yakubets",
      "source_url": "https://www.justice.gov/opa/pr/russian-national-indicted-charges-related-massive-cyber-attacks-stealing-tens-millions-dollars",
      "technique_name": "Process Injection",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1547.001",
      "evidence_excerpt": "The malware wrote autorun entries into HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run to maintain persistence across reboots.",
      "evidence_locator": "Indictment \u00b6 26, Page 15",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Yakubets",
      "source_url": "https://www.justice.gov/opa/pr/russian-national-indicted-charges-related-massive-cyber-attacks-stealing-tens-millions-dollars",
      "technique_name": "Registry Run Keys / Startup Folder",
      "tactic": "Persistence"
    },
    {
      "technique_id": "T1053.005",
      "evidence_excerpt": "Conspirators created scheduled tasks via schtasks.exe to trigger periodic secondary bot payload downloads.",
      "evidence_locator": "CISA Advisory AA19-339A",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA19-339A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa19-339a",
      "technique_name": "Scheduled Task",
      "tactic": "Persistence"
    },
    {
      "technique_id": "T1102",
      "evidence_excerpt": "Dridex used public social media profile pages and paste sites as dead drop resolvers to retrieve active C2 IP addresses.",
      "evidence_locator": "CISA Technical Analysis Report",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Technical Report",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa19-339a",
      "technique_name": "Web Service: Dead Drop Resolver",
      "tactic": "Command and Control"
    }
  ],
  "events": [
    {
      "event_type": "indictment",
      "event_date": "2019-11-14",
      "description": "Federal grand jury indicts Maksim Viktorovich Yakubets and Igor Turashev for computer fraud, wire fraud, and bank fraud."
    },
    {
      "event_type": "sanction",
      "event_date": "2019-12-05",
      "description": "OFAC sanctions Evil Corp, Yakubets, Turashev, and 15 associated confederates."
    },
    {
      "event_type": "sanction",
      "event_date": "2024-10-01",
      "description": "Treasury and UK authorities unseal additional sanctions targeting Evil Corp family members and LockBit collaboration."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Adversary breached the target network via Spearphishing Attachment. Defendants distributed millions of phishing emails containing malicious macros disguised as invoices to infect corporate computers with Dridex.",
    "blast_radius": "Caused at least $100 million in verified financial losses; State Department offered a $5 million reward under Transnational Organized Crime Rewards Program. Impacted Banking, Financial Services, Municipalities, Education infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Initial Access",
        "title": "Initial Perimeter Infiltration",
        "description": "Defendants distributed millions of phishing emails containing malicious macros disguised as invoices to infect corporate computers with Dridex.",
        "technical_artifacts": [
          "T1566.001",
          "Spearphishing Attachment"
        ],
        "mitre_technique_id": "T1566.001"
      },
      {
        "phase": "Phase 2: Persistence",
        "title": "Persistent Foothold Establishment",
        "description": "The malware wrote autorun entries into HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run to maintain persistence across reboots.",
        "technical_artifacts": [
          "T1547.001",
          "Registry Run Keys / Startup Folder"
        ],
        "mitre_technique_id": "T1547.001"
      },
      {
        "phase": "Phase 3: Defense Evasion",
        "title": "Defense Evasion & Security Blindfolding",
        "description": "Dridex injected dynamic link library code into running Internet Explorer and Chrome browser processes to intercept HTTPS traffic.",
        "technical_artifacts": [
          "T1055",
          "Process Injection"
        ],
        "mitre_technique_id": "T1055"
      },
      {
        "phase": "Phase 4: Credential Access",
        "title": "Credential Harvesting & Memory Dumping",
        "description": "Dridex injected web forms into web browsers to capture online banking credentials, passcodes, and transaction authorization numbers.",
        "technical_artifacts": [
          "T1555",
          "Credentials from Password Stores"
        ],
        "mitre_technique_id": "T1555"
      },
      {
        "phase": "Phase 5: Impact",
        "title": "Operational Disruption or Extortion Detonation",
        "description": "In later operations, conspirators deployed BitPaymer and WastedLocker ransomware against compromised networks to extort ransoms exceeding $5 million per victim.",
        "technical_artifacts": [
          "T1486",
          "Data Encrypted for Impact"
        ],
        "mitre_technique_id": "T1486"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}