CrimeRussia’s FSB protected Evil Corp gang that carried out...

Russia’s FSB protected Evil Corp gang that carried out Nato cyber-attacks

-

A prolific Russian cybercriminal gang carried out attacks against Nato countries at the behest of state intelligence services and used family links with Russia’s domestic spy agency to protect its members after being targeted by US authorities, according to the UK’s National Crime Agency.

The dramatically named Evil Corp group had an unusually close relationship with the Russian state, said the NCA.

The UK’s most senior law enforcement agency said in a briefing published on Tuesday: “Evil Corp held a privileged position, and the relationship between the Russian state and this cybercriminal group went far beyond the typical state-criminal relationship of protection, payoffs and racketeering.”

The group, which operated out of locations in Moscow including a pair of cafes, carried out cyber-attacks and espionage operations against undisclosed Nato countries before 2019 – alongside its day-to-day criminal activities such as deploying ransomware. However, when the group was put under sanctions and some of its members indicted by the US in 2019 it turned to the father-in-law of Evil Corp’s founder for protection.

The NCA said Eduard Benderskiy, the father-in-law of Evil Corp’s leader, Maksim Yakubets, was a former high-ranking official in a unit of Russia’s domestic spy agency, the FSB, and used his connections to protect the group after the US moved against it.

“Benderskiy used his extensive influence to protect the group, both by providing senior members with security and by ensuring they were not pursued by internal Russian authorities,” said the NCA.

The NCA briefing describes Evil Corp as a family-centred operation akin to a traditional organised crime gang, with Yakubets joined by his father, brother and cousins in the business.

The group’s influence has declined since 2019, when authorities released pictures to illustrate Yakubets’s multimillionaire lifestyle, including a camouflaged Lamborghini and a personalised registration plate that spelled out “thief”.

Evil Corp also split with a key member around this time and since then it has developed new strains of ransomware, a malicious form of software that is used to lock up targets’ computer systems – which can then be decrypted in exchange for a ransom payment, typically demanded in bitcoin.

The NCA said Yakubets’s right-hand man, Aleksandr Ryzhenkov – named by the NCA on Tuesday – had teamed up with fellow Russian gang LockBit to use its malware in ransomware attacks.

skip past newsletter promotion

LockBit, whose victims include Royal Mail, runs a so-called ransomware-as-a-service operation in which it leases out its software and support functions in exchange for a cut of any proceeds. The NCA said it had determined that Ryzhenkov was a “LockBit affiliate and has been involved in LockBit ransomware attacks against numerous organisations”.

The NCA and other enforcement agencies have since seized LockBit’s website and the infrastructure behind its attacks, severely affecting the group’s activities in an operation revealed in February.

LockBit has claimed more victims since then, but the NCA believes those are attacks on entities that have been hit by LockBit before – or that the gang is lying in an effort to play down the impact of the NCA operation.

0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Latest news

Four-Year-Old Boy Who Smashed Rare Bronze Age Jar Returns To Museum In Israel

A four-year-old boy who accidentally broke an ancient urn dating back to the late Bronze Age has returned for...

Donald Trump Threatens To Imprison Mark Zuckerburg For

Donald Trump has threatened to imprison Mark Zuckerberg if the Facebook founder does "anything illegal" to influence the upcoming...

Hamas Commander Killed In West Bank, Israeli Military Says

Israeli border police say they have killed a senior Hamas commander in the West Bank. The military says Wassem...

Abba Demands Donald Trump Campaign Stop Use Of Their Music – Joining Long List Of Stars

Abba has become the third musical act this month to complain about its music being used in Donald Trump's...

Justin Timberlake set to appear in person for hearing in drunk-driving case

Justin Timberlake is expected to appear personally in court...

Mouse crawling out of meal forces plane to make early landing

Airline meals hardly carry high expectations but this week...

You might also likeRELATED
Recommended to you

0
Would love your thoughts, please comment.x
()
x