Evil Corp — Ransomware Profile
Evil Corp is an internaltional cybercrime network. In December of 2019 the US Federal Government offered a $5M bounty for information leading to the arrest and conviction of Maksim V. Yakubets for allegedly orchestrating Evil Corp operations. Responsible for stealing over $100M from businesses and consumers. The Evil Corp organization is known for utilizing custom strains of malware such as JabberZeus, Bugat and Dridex to steal banking credentials.Also tracked as
Indrik Spider, Manatee Tempest, DEV-0243, UNC2165, Gold Drake
IntelFusions coverage (2)
- Eduard Benderskiy Named: The Former KGB Officer Who Shielded Evil Corp from Russian Law Enforcement 2026-02-16 · Cyber Incidents
- Hades Ransomware: How INDRIK SPIDER Reinvented Its Toolchain to Evade OFAC Sanctions 2026-02-16 · Ransomware
Tools & malware
- BitPaymer malware
- Cobalt Strike tool
- Hades malware
- Phoenix CryptoLocker malware
- WastedLocker malware
- win.dridex Banking Trojan
- win.payloadbin Backdoor
Vendor research
- GOLD DRAKE Threat Profile Secureworks
- CrowdStrike Intelligence CrowdStrike
- How Microsoft names threat actors Microsoft
- Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware Frankoff, S., Hartley, B
- Treasury Sanctions Evil Corp, the Russia-Based Cybercriminal Group Behind Dridex Malware U.S. Department of Treasury
- INDRIK SPIDER Supersedes WastedLocker with Hades Ransomware to Circumvent OFAC Sanctions Podlosky, A., Feeley, B
- To HADES and Back: UNC2165 Shifts to LOCKBIT to Evade Sanctions Mandiant Intelligence