Close Menu
Technology Mag

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    UN Plastics Treaty Talks Once Again End in Failure

    August 19, 2025

    UK drops demand for backdoor into Apple encryption

    August 19, 2025

    Amazon’s Fallout season two heads to New Vegas

    August 18, 2025
    Facebook X (Twitter) Instagram
    Subscribe
    Technology Mag
    Facebook X (Twitter) Instagram YouTube
    • Home
    • News
    • Business
    • Games
    • Gear
    • Reviews
    • Science
    • Security
    • Trending
    • Press Release
    Technology Mag
    Home » Notorious Evil Corp Hackers Targeted NATO Allies for Russian Intelligence
    Security

    Notorious Evil Corp Hackers Targeted NATO Allies for Russian Intelligence

    News RoomBy News RoomOctober 4, 20244 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email

    International law enforcement has worked for years to disrupt the cybercriminal gang Evil Corp and its egregious global crime spree. But in a crowded field of prolific Russian cybercriminals, Evil Corp is most notable for its singular relationship with Russian intelligence.

    On Tuesday, the United Kingdom’s National Crime Agency released new details about the real-world identities of alleged Evil Corp members, the group’s connection to the LockBit platform, and the gang’s ties to the Russian state. Researchers have increasingly established that there are loose, quid pro quo connections between Russian cybercriminals and the country’s government. But NCA officials emphasize that Evil Corp is an unusual example of a gang that has direct relationships with multiple Russian intelligence agencies—including Russia’s Federal Security Service, or FSB; Foreign Intelligence Service, or SVR; and military intelligence agency known as the GRU. And the NCA reports that before 2019, Evil Corp was specifically “tasked” by Russia’s intelligence services with conducting espionage operations and cyberattacks against unidentified “NATO allies.”

    For more than a decade, Evil Corp has used its Dridex malware and other hacking tools to compromise thousands of bank accounts around the world and steal funds. In 2017, the group expanded into ransomware, using strains like Hades and PhoenixLocker, and then using the LockBit platform as an affiliate beginning in 2022. The group has extorted at least $300 million from victims on tops of its other spoils, and the United States Department of State is offering a $5 million reward for information leading to the arrest of the gang’s alleged leader, Maksim Yakubets.

    “Evil Corp’s story is a prime example of the evolving threat posed by cybercriminals and ransomware operators,” the NCA wrote on Tuesday in a joint report with the FBI and Australian Federal Police. “In their case, the activities of the Russian state played a particularly significant role, sometimes even co-opting this cybercrime group for its own malicious cyber activity.”

    Unlike many Russian cybercrime groups that have evolved a distributed leadership structure online, NCA officials say that Evil Corp is organized like a more traditional crime syndicate around Yakubets’ family and friends. His father, Viktor Yakubets, allegedly has a background in money laundering, and Maksim’s brother Artem, along with cousins Kirill and Dmitry Slobodskoy, are all allegedly involved with the group. Officials also allege that the group has operated out of physical locations, including Chianti Café and Scenario Café in Moscow.

    Officials say that Maksim Yakubets has always been the primary liaison between Evil Corp and Russian intelligence. But other members, including his father-in-law, Eduard Benderskiy, also allegedly contribute to the relationships. Benderskiy is reportedly a former FSB official who worked in the mysterious ‘Vympel’ unit and, according to Bellingcat, may have been involved in a series of overseas assassinations. NCA officials say that after the US’s 2019 sanctions and indictments against Evil Corp members, Benderskiy worked to protect the gang’s senior members within Russia.

    In spite of its longtime dominance, Evil Corp has had to continue evolving to keep making money. While it denies a relationship, the group seemed to have used the notorious ransomware-as-a-service platform LockBit to conduct attacks since 2022. And Yakubets’ alleged second in command, whom NCA officials named on Tuesday as Aleksandr Ryzhenkov, was apparently overseeing this work. After international law enforcement launched a major disruption of LockBit in February, the gang has been operating in a diminished capacity, according to the NCA.

    “Born out of a coalescing of elite cybercriminals, Evil Corp’s sophisticated business model made them one of the most pervasive and persistent cybercrime adversaries to date,” the NCA wrote. “After being hampered by the December 2019 sanctions and indictments, the group have been forced to diversify their tactics as they attempt to continue causing harm whilst adapting to the changing cybercrime ecosystem.”

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleChatGPT’s ‘canvas’ interface makes it easier to write and code
    Next Article Epic and Disney want to make ‘what every Disney fan has ever wanted’

    Related Posts

    Inside the Multimillion-Dollar Gray Market for Video Game Cheats

    August 13, 2025

    How to Protect Yourself From Portable Point-of-Sale Scams

    August 12, 2025

    Leak Reveals the Workaday Lives of North Korean IT Scammers

    August 11, 2025

    The US Court Records System Has Been Hacked

    August 11, 2025

    Ex-NSA Chief Paul Nakasone Has a Warning for the Tech World

    August 10, 2025

    Hackers Went Looking for a Backdoor in High-Security Safes—and Now Can Open Them in Seconds

    August 9, 2025
    Our Picks

    UK drops demand for backdoor into Apple encryption

    August 19, 2025

    Amazon’s Fallout season two heads to New Vegas

    August 18, 2025

    Google Home adds scheduling for older Nest thermostats

    August 18, 2025

    Nvidia’s GeForce Now is upgrading to RTX 5080 GPUs and opening a floodgate of new games

    August 18, 2025
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    News

    Nvidia gives fake Harrison Ford better hair using spheres

    By News RoomAugust 18, 2025

    Indiana Jones and the Great Circle will be the first game to get Nvidia’s new…

    Nvidia’s app gets global DLSS override and more control panel features

    August 18, 2025

    ‘Play Instantly on Discord’: Fortnite will be Nvidia and Discord’s first instant game demo

    August 18, 2025

    AI Is Designing Bizarre New Physics Experiments That Actually Work

    August 18, 2025
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2025 Technology Mag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.