CASE DOSSIER
sentenced
U.S. v. Alla Witte & Vladimir Dunaev (Trickbot Malware Group)
Docket: 1:20-cr-00384 Court: U.S. District Court for the Northern District of Ohio Opened: 2021-02-18 Sector: Healthcare, Banking, Local Government
Key Facts
Status
SENTENCED
Legal disposition
Loss Amount
$180.0 million
Extorted tens of millions of dollars and caused hundreds of millions in financial damages to hospitals and municipalities.
Techniques
3
Verified mappings
Defendants
2
Named in charges
- Legal Status: SENTENCED in U.S. District Court for the Northern District of Ohio.
- Primary Target Sector: Healthcare, Banking, Local Government.
- Documented Financial Loss: $180.0 million.
- 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:
Case Summary
Key software developers and coders of the transnational Trickbot cybercrime group charged with infecting millions of victim computers with banking trojans and facilitating Conti/Ryuk ransomware deployments against hospitals.
Procedural & Incident Timeline
2021-06-04 extradition
Alla Witte extradited from Suriname to the Northern District of Ohio.
2021-10-20 extradition
Vladimir Dunaev extradited from the Republic of Korea to the Northern District of Ohio.
2023-06-20 sentencing
Alla Witte sentenced to 32 months in prison after pleading guilty.
2024-01-24 sentencing
Vladimir Dunaev sentenced to 64 months (5 years and 4 months) in federal prison.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Alla Witte | Latvia | sentenced | 32 mo | None | Trickbot ransomware management software programmer. Sentenced to 32 months in prison. |
| Vladimir Dunaev | Russian Federation | sentenced | 64 mo | None | Trickbot developer responsible for browser injection modules. Sentenced to 64 months in prison. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1566.001 | Spearphishing Attachment Initial Access | "Trickbot was deployed via phishing emails masquerading as legal notices containing weaponized Word documents with malicious macros." | Indictment ¶ 14, Page 7 | reviewed |
| T1003 | OS Credential Dumping Credential Access | "Injected modular credential harvesters that pulled domain credentials from Windows memory to pave the way for ransomware." | Indictment ¶ 19, Page 11 | reviewed |
| T1486 | Data Encrypted for Impact Impact | "Trickbot acted as the primary access loader for Ryuk and Conti ransomware gangs targeting US medical facilities." | CISA Advisory AA20-302A | reviewed |
Cite & Embed This Case Record
Public Domain / CC0 Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Alla Witte & Vladimir Dunaev (Trickbot Malware Group), No. 1:20-cr-00384 (U.S. District Court for the Northern District of Ohio 2021), https://cyberattackcaselibrary.pages.dev/cases/us-v-witte-dunaev-trickbot/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/us-v-witte-dunaev-trickbot" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>