Evil Corp affiliates are using off-the
Full article545 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Researchers found a number of similarities between Evil Corp and a new group of attackers.
Hackers likely affiliated with the notorious Russian cybercrime group Evil Corp are using off-the-shelf ransomware to evade U.S. sanctions, researchers at security firm Mandiant have found.
The researchers’ observations, published Thursday, are just the latest example of how cybercriminals affiliated with Evil Corp have shifted tactics after U.S. sanctions in 2019 increased scrutiny over transactions with the group.
The group, which had already started pivoting from broader financial crimes to ransomware prior to 2019, has since been tied by multiple researchers to a number of different malware strains including WASTEDLOCKER and HADES ransomware.
But as those strains became synonymous with Evil Corp, users have had to adjust. For instance, after an October 2020 Treasury Department advisory tying WASTEDLOCKER to the group, researchers noticed a drop in activity using the malware. Researchers at Emsisoft even observed Evil Corp affiliates masquerading last year as another notorious group, REvil, to evade sanctions.
Treasury sanctioned Evil Corp in 2019 for its development and distribution of Dridex, a malware used to infiltrate hundreds of financial institutions in more than 40 countries, leading to millions of dollars in damages.
Now, affiliates whom researchers group as “UNC2165” have since taken cover with LOCKBIT, a ransomware-as-a-service with ties to a number of different threat actors.
“The adoption of existing ransomware is a natural evolution for UNC2165 to attempt to obscure their affiliation with Evil Corp,” the Mandiant researchers write. “Both the prominence of LOCKBIT in recent years and its successful use by several different threat clusters likely made the ransomware an attractive choice.”
Also in 2019, prosecutors indicted two Russian nationals, Maksim Yakubets and Igor Turashev, in connection with Evil Corp. Yakubets was accused of providing direct assistance to the Russian government.
Despite scrutiny from the U.S. government, the notorious and prolific Russian crime group has continued to go after U.S. targets. Evil Corp was accused of launching a cyberattack against U.S. media company Sinclair Broadcast Group in October.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/evil-corp-lockbit-mandiant-sanctions/