Evil Corp Sanctions and Maksim Yakubets Indictment
How a Moscow cybercrime family became a Russian intelligence contractor.

Evil Corp gets filed under "cybercrime gang," and that label is technically true the way calling a shark a "fish" is technically true. It undersells the teeth. The group is a family-run criminal operation based in Moscow with documented, directed ties to Russian state intelligence, which puts it somewhere no standard org chart has a box for: part mafia family, part contractor for an intelligence service.
The UK's National Crime Agency laid out the timeline in its report "Evil Corp: Behind the Screens." The roots go back to the Jabber Zeus Crew, active from around 2009, with Maksim Yakubets probably getting into cybercrime activity around 2007. The group formally organized as Evil Corp in 2014. That's close to two decades of continuous, escalating operation under different names, which is a longer run than most legitimate startups manage.
The NCA describes Evil Corp as a family-centered operation, more reminiscent of traditional organized crime than a loose collection of hackers in hoodies. Viktor Yakubets, Maksim's father, carries a long history tied to money laundering, so the family business runs in more than one direction. As of December 2019, the NCA assessed Evil Corp as the most significant cybercrime threat facing the UK. Its director general said the full cost may never be known, but the damage to UK financial infrastructure runs into the hundreds of millions.
None of that reads like a routine prosecution target, and it reads like the setup for something bigger that the next layer of evidence confirms.
Yakubets' FSB relationship
The connection between Yakubets and a state security service didn't look like a government quietly deciding not to notice a local crime boss. The U.S. Treasury Department stated that Yakubets worked for the FSB and was directed, as of 2017, to work on projects for the Russian state. Treasury also said he was in the process of obtaining a security clearance to access classified information in support of the FSB, the kind of paperwork trail that doesn't exist for a contact the agency merely tolerates.
The UK's NCA added a second data point: prior to 2019, Russian intelligence tasked Evil Corp with conducting cyberattacks and espionage operations against NATO allies. A banking trojan crew moonlighting as an intelligence asset against military alliances is a different animal than a ransomware gang shaking down hospitals for payment.
The 2024 sanctions filled in more of the cover story. Treasury's October 2024 statement noted that Yakubets also holds a position at the Russian National Engineering Corporation, known as NIK, which Treasury says he uses as cover for his ongoing criminal activity. A day job at a state-linked engineering firm, doubling as camouflage for running a cybercrime empire, is the kind of detail that would get cut from a spy novel for being too on the nose.
The family network extended the protection further. Eduard Benderskiy, Yakubets' father-in-law and a former high-ranking FSB official, was sanctioned in October 2024. The NCA stated that Benderskiy used his extensive influence with the Russian state to protect the group. Marrying into the family here comes with security services attached, not just in-laws who overstay their welcome at holidays.
Dridex as the group's primary instrument
Every criminal operation needs a tool it's actually good at, and for Evil Corp that tool was Dridex. It wasn't a piece of off-the-shelf malware the group happened to pick up. Yakubets built it, with Aleksandr Ryzhenkov and other former members of the so-called Business Club, bringing it into operation in June 2014. It became one of the most prolific banking trojans deployed up to that point, which is a bit like saying a particular lockpick became the most prolific lockpick in history: the compliment is backhanded, but the scale is undeniable.
The 2019 federal indictment described Dridex (also known by its earlier names Bugat and Cridex) as "a multifunction malware package that automates the theft of confidential personal and financial information, such as online banking credentials, from infected computers through the use of keystroke logging and web injects." It typically arrived through phishing emails, the digital equivalent of a stranger handing someone an envelope and asking them to mail it for a small fee, except the envelope empties their bank account.
HC3's technical threat profile goes deeper into the architecture, covering how Dridex delivers its payload and maintains persistence on infected machines, detail that matters less for the headline and more for understanding how sophisticated the engineering behind it actually was. Dridex wasn't a smash-and-grab script. It was infrastructure, maintained and adapted over years. That's why it sat at the center of both the 2019 and 2024 legal actions against the group.
Ryzhenkov's name sits right there at the origin point, as a co-creator of Dridex back in 2014 [1][2][3][4]. That name resurfaces a decade later in a different indictment, tied to a different kind of malware entirely, and that thread stays relevant to what follows.
The December 2019 indictment and sanctions
December 2019 marked the first time Western governments said, in formal legal language, that Evil Corp was operating in a different category than ordinary cybercrime. Yakubets was charged in federal court in both Nebraska and Pennsylvania, covering two separate computer hacking and bank fraud operations dating back to May 2009. The charges centered on conspiracy and fraud involving Bank of America and a wide range of other banks, businesses, municipalities, and organizations spread across more than a dozen U.S. states.
Igor Turashev, another senior figure in Evil Corp, was indicted and sanctioned alongside Yakubets. U.S. Attorney Scott Brady described the pair as having led "one of the most sophisticated transnational cyber-crime syndicates in the world" for over a decade, which is the kind of line that sounds like marketing copy until it's followed by actual asset freezes.
And there were plenty of those: 22 associated entities and individuals had their assets frozen. The State Department added a $5 million reward for information leading to Yakubets' arrest, the largest bounty ever placed on a cybercriminal at the time. Putting a number that size on someone's head is the government's way of saying this isn't a routine case file; it's a most-wanted poster.
The action was coordinated with the UK's National Crime Agency, giving it a multilateral shape from the start. That coordination mattered, because a single country's indictment against someone sitting comfortably in Moscow is mostly symbolic. A joint action across two governments was the first sign that this was going to be a sustained campaign.
October 2024: how the trilateral action expanded the case and mapped the full network
Five years later, the follow-up arrived, and it wasn't a rerun. The October 2024 actions added a new defendant, tied to a different strain of malware, sanctioned a former FSB official for protecting the group, and finished mapping a family and criminal network that the 2019 case had only partly exposed.
On October 1, 2024, the Department of Justice unsealed an indictment against Aleksandr Viktorovich Ryzhenkov, the same Ryzhenkov who helped build Dridex a decade earlier. The new charges covered violations of the Computer Fraud and Abuse Act and conspiracy to commit money laundering, arising from his use of a ransomware strain called BitPaymer. The co-architect of the group's original banking trojan had, by 2024, moved into ransomware deployment, and the DOJ had the paper trail to prove it.
Treasury's October 2024 statement announced sanctions against seven individuals and two entities tied to Evil Corp. The UK's NCA targeted multiple members of the same criminal syndicate, and the U.S. and Australia added further sanctions on top, including asset freezes and travel bans. This was the first time Australia joined as a formal co-sanctioning partner alongside the U.S. and UK, broadening the coalition that 2019 had started.
Benderskiy's sanctioning was the clearest single entry in the public record showing state protection operating at a personal, family level, since he is Yakubets' father-in-law as well as a former FSB official. The timing carried its own message: the announcement landed on the second day of the U.S.-hosted Counter Ransomware Initiative summit, an event coordinating dozens of countries, which made the designation as much a signal to the rest of the world as a legal filing against one man. With Benderskiy's sanctioning, all four of Yakubets' relatives connected to Evil Corp had now been designated, closing out the network map that the 2019 case had only begun to sketch.
That continuity, from Dridex's creator in 2014 to a ransomware indictment in 2024, is the hinge the rest of the story turns on.
Evil Corp's Malware Lineage: From Dridex to Ransomware to LockBit
Evil Corp's shift from banking trojans to a rotating cast of ransomware strains wasn't a natural product roadmap. It was a documented reaction to being sanctioned, with each rebrand designed to muddy attribution and keep the payments flowing.
The NCA's "Behind the Screens" report traces the sequence: the group moved away from the Dridex botnet and toward SocGholish as its initial access method, then developed and adapted a string of ransomware strains, Hades, Phoenix Locker, PayloadBIN, and Macaw, before eventually shifting to deploying LockBit ransomware against targets' networks. Each name change functioned less like a rebrand in the marketing sense and more like a snake shedding skin to slip past a predator that's learned to recognize the old pattern.
Intel 471's threat hunting case study on the group shows why the skin-shedding never fully worked. The techniques and command infrastructure stayed recognizable across every name change, even as the malware hashes and branding shifted completely. Investigators who knew what to look for could trace the same operators underneath each new label.
The uncomfortable part is that the sanctions regime, built to choke off Evil Corp's funding, ended up reinforcing the exact rebranding cycle it was meant to stop. Once OFAC designated Evil Corp, incident response firms and victims suddenly faced strict liability for any payment that reached the group, which meant attribution confusion stopped being a nuisance for defenders and became a business asset for the attackers. Mandiant has observed IR firms declining to facilitate payments once a connection to a known sanctioned entity is suspected, which gives Evil Corp a direct incentive to blur that connection every chance it gets. The sanctions worked exactly as intended on paper, and they also handed the group a built-in reason to keep changing costumes.
The strict liability problem: what OFAC sanctions mean for victims and incident responders
For the organizations actually on the receiving end of these attacks, the sanctions regime creates a legal problem, not just a technical one. OFAC sanctions against Evil Corp built a compliance trap for victim companies and the incident response firms trying to help them, because the group's rebranding strategy keeps real-time attribution murky at the exact moment decisions have to get made fast and under pressure.
OFAC operates on a strict liability standard. A ransomware payment that turns out to have gone to a Specially Designated National can expose the payer or whoever facilitated the payment to civil penalties, regardless of what they knew or intended at the time. Not knowing who's on the other end of the wallet address doesn't count as a defense. The exposure exists whether or not anyone involved had any idea who they were actually paying.
The Garmin case put that problem on full display. Following a July 2020 ransomware attack, Garmin reportedly paid to unlock its systems after being hit with WastedLocker, a strain linked to Evil Corp. The situation lined up every piece of the trap at once: a company under operational pressure to get back online, an incident response firm stuck between what the client needed and what the law allowed, and a payment pathway that may have run straight to a sanctioned entity.
Jeremy Kennelly, senior manager of financial crime analysis at Mandiant Threat Intelligence, has pointed out that the surface-level signals investigators normally rely on, the malware family, the wording on a ransom note, the shaming site listing victims, may not be enough to establish whether the money is heading toward Evil Corp or an unrelated group. Attribution has become a legal and financial risk question that has to be answered correctly before the wire transfer goes out, which is a tall order when the group on the other end has every incentive to make that answer as hard to reach as possible.
Actor-based threat intelligence as the right analytical frame for Evil Corp
Everything in Evil Corp's history, the FSB direction, the family network, the malware lineage from Dridex through BitPaymer to LockBit, points to the same conclusion: tracking this group by malware signature alone will always run a step behind. A hash can change overnight. A ransom note can borrow someone else's branding. The people, the infrastructure habits, and the command relationships persist across every new name, and those are what don't change as easily.
Actor-based threat intelligence starts from the operators. It asks who is behind the keyboard, who they answer to, and what pattern of behavior follows them from Hades to Phoenix Locker to Macaw to LockBit, rather than treating each new strain as an unrelated event requiring a fresh investigation from zero. Given a group with a documented security-service relationship, a father-in-law running protection from inside that security service, and a co-founder who resurfaces a decade later under a new ransomware indictment, the only frame that keeps the full picture in view is the one built around the actor, not the artifact.
Sources
- HC3 Threat Profile: Evil Corp
- October 2024 Evil Corp: Behind the Screens
- Treasury Sanctions Evil Corp, the Russia-Based Cybercriminal Group Behind Dridex Malware
- Dridex, Software S0384
- Treasury Sanctions Members of the Russia-Based Cybercriminal Group Evil Corp in Tri-Lateral Action with the United Kingdom and Australia
- Taking Action with Partners to Combat Russia-Based Cybercriminal Group - United States Department of State
- MAKSIM VIKTOROVICH YAKUBETS


