Evil Corp — Ransomware Profile
Evil Corp is an internaltional cybercrime network. In December of 2019 the US Federal Government offered a $5M bounty for information leading to the arrest and conviction of Maksim V. Yakubets for allegedly orchestrating Evil Corp operations. Responsible for stealing over $100M from businesses and consumers. The Evil Corp organization is known for utilizing custom strains of malware such as JabberZeus, Bugat and Dridex to steal banking credentials.Also tracked as
Indrik Spider, Manatee Tempest, DEV-0243, UNC2165
Tools & malware
- win.dridex Banking Trojan
- win.payloadbin Backdoor
Vendor research
- CrowdStrike Intelligence CrowdStrike
- Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware Frankoff, S., Hartley, B
- To HADES and Back: UNC2165 Shifts to LOCKBIT to Evade Sanctions Mandiant Intelligence
- How Microsoft names threat actors Microsoft
- INDRIK SPIDER Supersedes WastedLocker with Hades Ransomware to Circumvent OFAC Sanctions Podlosky, A., Feeley, B
- Treasury Sanctions Evil Corp, the Russia-Based Cybercriminal Group Behind Dridex Malware U.S. Department of Treasury