U.S. charges two Russians in connection with Dridex banking malware
Full article682 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Both suspects are still in Russia.
U.S. prosecutors have charged two Russian nationals, including one member of the FBI’s “Most Wanted” list, in connection with two years-long hacking and fraud campaigns that resulted in the theft of millions of dollars from American organizations.
The Department of Justice charged Maksim Yakubets and Igor Turashev with involvement in the development and distribution of the malicious software known as Bugat. Bugat is a predecessor to Dridex, a banking malware strain that has haunted international victims for more than eight years, while prosecutors said Yakubets also was involved with Zeus, another pernicious hacking tool.
Both suspects remain at large in Russia. Prosecutors unsealed the indictment against Yakubets and Turashev in conjunction with U.S. sanctions against Evil Corp, which the Treasury Department says is the criminal organization, led by Yakubets, behind the Dridex malware. Yakubets also has provided direct assistance to the Russian government’s “malicious cyber efforts, highlighting the Russian government’s enlistment of cybercriminals for its own malicious purposes,” the Treasury Department said in a statement.
“Sitting quietly at computer terminals far, far away these cybercriminals allegedly stole tens of millions of dollars,” Assistant Attorney General Brian Benczkowski said during a press conference Thursday. “Each and every one of these computer intrusions was effectively a cyber-enabled bank robbery.”
Evil Corp has used Dridex to infect computers, then collect usernames and passwords from hundreds of banks and financial institutions in more than 40 countries, the Treasury Department said. The attacks have resulted in more than $100 million in theft.
As both suspects have evaded arrest, the theft scheme remains ongoing, prosecutors said. The Dridex malware infects victims by convincing users to click malicious links in emails or banking pages, and later evolved to include ransomware. Meanwhile Zeus, Yakubets’ other alleged malware, has hit banks, nonprofit organizations and 21 U.S. municipalities, according to the criminal complaint.
The U.K.’s National Crime Agency, which has participated in the investigation, alleged that tools developed by Yakubets and Turashev have caused the equivalent of millions of dollars in losses in Britain, while the suspects have not tried to hide their activities while living in Russia. The NCA also released a trove of pictures and videos of the suspects driving in fast cars and playing with expensive toys.
Evil Corp created and deployed malware causing financial losses totalling hundreds of millions of pounds in the UK alone.
The NCA began working with multiple partners to investigate one of the group’s core malware strains, Dridex, in 2014. pic.twitter.com/gu6NR640qe
— National Crime Agency (NCA) (@NCA_UK) December 5, 2019
The U.S. is offering rewards of up to $5 million for information aiding the apprehension and/or conviction of the accused hackers. That figure is the largest reward ever offered by American authorities for a suspected cybercriminal.
The full complaint is available below.
[documentcloud url=”http://www.documentcloud.org/documents/6568857-Yakubets.html” responsive=true]
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/dridex-begat-doj-indictment-russians-arrested/