In a shocking revelation, British police have revealed that the notorious cybercrime group Evil Corp was protected by a former high-ranking officer of the Russian intelligence agency FSB. This link between the group and the Kremlin raises serious questions about the role of cybercrime in the geopolitical context.

Important findings

  • Evil Corp is accused of conducting cyberattacks and espionage operations on behalf of the Kremlin.
  • Evil Corp leader Maksim Yakubets has been active since 2014 and has made the group one of the most feared actors in cybercrime.
  • The British National Crime Agency (NCA) has documented in detail the links between Evil Corp and Russian intelligence agencies.
  • The group has captured at least $100 million through ransomware attacks.
  • Sanctions were imposed on Yakubets and his family to restrict the group’s activities.

Connection to the Kremlin

According to the NCA, Evil Corp was commissioned by Russian intelligence agencies to carry out cyberattacks on NATO members. This information was released during a coordination of arrests and server seizures, which coincided with an international meeting to combat ransomware.

The group, known for its use of banking Trojans like Dridex, has proven to be an important tool for the Kremlin. The NCA highlights that relations between Evil Corp and the Russian intelligence agencies were promoted by former FSB officer Eduard Benderskiy.

Eduard Benderskiy: The Key Player

Benderskiy, regarded as a senior FSB officer, is seen as a key factor in the close relationship between Evil Corp and Russian intelligence services. He is said to have protected the group from prosecution and facilitated its activities.

  • Benderskiy’s influence: He used his contacts to protect the group. He runs several private security companies associated with the name “Vympel”, a secret KGB unit.

Sanctions and their impact

The US and UK have imposed sanctions on Yakubets and his family to restrict Evil Corp’s activities. These measures have forced the group to change its tactics and hide more.

  • Consequences of the sanctions: Forced restructuring of the group. Members breaking away and the development of new ransomware types.

The Future of Evil Corp

Despite sanctions and international attention, Evil Corp remains active. The group has changed its tactics and now focuses on larger targets to extort higher ransoms. The NCA warns that the threat from such groups persists and that international cooperation is essential to combat them.

Overall, this case shows how closely cybercrime and geopolitical interests are interwoven and how important it is to understand these links in order to take effective action.

Sources

  • Evil Corp Protected by Ex-Senior FSB Official, Police Say, BankInfoSecurity.