CASE DOSSIER fugitive

U.S. v. Yakubets & Turashev (Evil Corp / Dridex Banking Malware)

Docket: 2:19-cr-00336 Court: U.S. District Court for the Western District of Pennsylvania Opened: 2019-11-14 Sector: Banking, Financial Services, Municipalities, Education

Key Facts

Status
FUGITIVE
Legal disposition
Loss Amount
$100.0 million
Caused at least $100 million in verified financial losses; State Department offered a $5 million reward under Transnational Organized Crime Rewards Program.
Techniques
7
Verified mappings
Defendants
2
Named in charges
  • Legal Status: FUGITIVE in U.S. District Court for the Western District of Pennsylvania.
  • Primary Target Sector: Banking, Financial Services, Municipalities, Education.
  • Documented Financial Loss: $100.0 million.
  • 7 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Leader and core administrator of Evil Corp charged with deploying Bugat/Dridex banking malware and ransomware, stealing dozens of millions of dollars from bank accounts of municipalities, school districts, and businesses.

Procedural & Incident Timeline

2019-11-14 indictment

Federal grand jury indicts Maksim Viktorovich Yakubets and Igor Turashev for computer fraud, wire fraud, and bank fraud.

2019-12-05 sanction

OFAC sanctions Evil Corp, Yakubets, Turashev, and 15 associated confederates.

2024-10-01 sanction

Treasury and UK authorities unseal additional sanctions targeting Evil Corp family members and LockBit collaboration.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Maksim Viktorovich Yakubets Russian Federation fugitive Pending None Leader of Evil Corp cybercrime syndicate. Indicted in W.D. Pa. and sanctioned by OFAC.
Igor Olegovich Turashev Russian Federation fugitive Pending None Chief administrator and technical coordinator of Evil Corp's Dridex operations.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1566.001 Spearphishing Attachment
Initial Access
"Defendants distributed millions of phishing emails containing malicious macros disguised as invoices to infect corporate computers with Dridex." Indictment ¶ 19, Page 11 reviewed
T1555 Credentials from Password Stores
Credential Access
"Dridex injected web forms into web browsers to capture online banking credentials, passcodes, and transaction authorization numbers." Indictment ¶ 24, Page 14 reviewed
T1486 Data Encrypted for Impact
Impact
"In later operations, conspirators deployed BitPaymer and WastedLocker ransomware against compromised networks to extort ransoms exceeding $5 million per victim." Treasury Designation Announcement reviewed
T1055 Process Injection
Defense Evasion
"Dridex injected dynamic link library code into running Internet Explorer and Chrome browser processes to intercept HTTPS traffic." Indictment ¶ 23, Page 13 reviewed
T1547.001 Registry Run Keys / Startup Folder
Persistence
"The malware wrote autorun entries into HKCU\Software\Microsoft\Windows\CurrentVersion\Run to maintain persistence across reboots." Indictment ¶ 26, Page 15 reviewed
T1053.005 Scheduled Task
Persistence
"Conspirators created scheduled tasks via schtasks.exe to trigger periodic secondary bot payload downloads." CISA Advisory AA19-339A reviewed
T1102 Web Service: Dead Drop Resolver
Command and Control
"Dridex used public social media profile pages and paste sites as dead drop resolvers to retrieve active C2 IP addresses." CISA Technical Analysis Report reviewed

OFAC Sanctions Designations

Maksim Viktorovich Yakubets (Evil Corp Leader) (2019-12-05)

State Department offers reward of up to $5,000,000 for information leading to the arrest or conviction of Maksim Yakubets for banking fraud and cyber extortion.

Treasury Release ↗
Maksim Viktorovich Yakubets (2019-12-05)

Leader of Evil Corp cybercriminal syndicate responsible for Dridex banking trojan and multimillion-dollar ransomware extortions.

Treasury Release ↗

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Yakubets & Turashev (Evil Corp / Dridex Banking Malware), No. 2:19-cr-00336 (U.S. District Court for the Western District of Pennsylvania 2019), https://cyberattackcaselibrary.pages.dev/cases/us-v-yakubets-evil-corp-dridex/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/us-v-yakubets-evil-corp-dridex" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>