CASE DOSSIER
fugitive
U.S. v. Yakubets & Turashev (Evil Corp / Dridex Banking Malware)
Docket: 2:19-cr-00336 Court: U.S. District Court for the Western District of Pennsylvania Opened: 2019-11-14 Sector: Banking, Financial Services, Municipalities, Education
Key Facts
Status
FUGITIVE
Legal disposition
Loss Amount
$100.0 million
Caused at least $100 million in verified financial losses; State Department offered a $5 million reward under Transnational Organized Crime Rewards Program.
Techniques
7
Verified mappings
Defendants
2
Named in charges
- Legal Status: FUGITIVE in U.S. District Court for the Western District of Pennsylvania.
- Primary Target Sector: Banking, Financial Services, Municipalities, Education.
- Documented Financial Loss: $100.0 million.
- 7 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:
Case Summary
Leader and core administrator of Evil Corp charged with deploying Bugat/Dridex banking malware and ransomware, stealing dozens of millions of dollars from bank accounts of municipalities, school districts, and businesses.
Procedural & Incident Timeline
2019-11-14 indictment
Federal grand jury indicts Maksim Viktorovich Yakubets and Igor Turashev for computer fraud, wire fraud, and bank fraud.
2019-12-05 sanction
OFAC sanctions Evil Corp, Yakubets, Turashev, and 15 associated confederates.
2024-10-01 sanction
Treasury and UK authorities unseal additional sanctions targeting Evil Corp family members and LockBit collaboration.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Maksim Viktorovich Yakubets | Russian Federation | fugitive | Pending | None | Leader of Evil Corp cybercrime syndicate. Indicted in W.D. Pa. and sanctioned by OFAC. |
| Igor Olegovich Turashev | Russian Federation | fugitive | Pending | None | Chief administrator and technical coordinator of Evil Corp's Dridex operations. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1566.001 | Spearphishing Attachment Initial Access | "Defendants distributed millions of phishing emails containing malicious macros disguised as invoices to infect corporate computers with Dridex." | Indictment ¶ 19, Page 11 | reviewed |
| T1555 | Credentials from Password Stores Credential Access | "Dridex injected web forms into web browsers to capture online banking credentials, passcodes, and transaction authorization numbers." | Indictment ¶ 24, Page 14 | reviewed |
| T1486 | Data Encrypted for Impact Impact | "In later operations, conspirators deployed BitPaymer and WastedLocker ransomware against compromised networks to extort ransoms exceeding $5 million per victim." | Treasury Designation Announcement | reviewed |
| T1055 | Process Injection Defense Evasion | "Dridex injected dynamic link library code into running Internet Explorer and Chrome browser processes to intercept HTTPS traffic." | Indictment ¶ 23, Page 13 | reviewed |
| T1547.001 | Registry Run Keys / Startup Folder Persistence | "The malware wrote autorun entries into HKCU\Software\Microsoft\Windows\CurrentVersion\Run to maintain persistence across reboots." | Indictment ¶ 26, Page 15 | reviewed |
| T1053.005 | Scheduled Task Persistence | "Conspirators created scheduled tasks via schtasks.exe to trigger periodic secondary bot payload downloads." | CISA Advisory AA19-339A | reviewed |
| T1102 | Web Service: Dead Drop Resolver Command and Control | "Dridex used public social media profile pages and paste sites as dead drop resolvers to retrieve active C2 IP addresses." | CISA Technical Analysis Report | reviewed |
OFAC Sanctions Designations
Maksim Viktorovich Yakubets (Evil Corp Leader) (2019-12-05)
State Department offers reward of up to $5,000,000 for information leading to the arrest or conviction of Maksim Yakubets for banking fraud and cyber extortion.
Treasury Release ↗Maksim Viktorovich Yakubets (2019-12-05)
Leader of Evil Corp cybercriminal syndicate responsible for Dridex banking trojan and multimillion-dollar ransomware extortions.
Treasury Release ↗Cite & Embed This Case Record
Public Domain / CC0 Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Yakubets & Turashev (Evil Corp / Dridex Banking Malware), No. 2:19-cr-00336 (U.S. District Court for the Western District of Pennsylvania 2019), https://cyberattackcaselibrary.pages.dev/cases/us-v-yakubets-evil-corp-dridex/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/us-v-yakubets-evil-corp-dridex" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>