{
  "id": "case-netwalker-vachon",
  "slug": "us-v-vachon-desjardins-netwalker",
  "title": "U.S. v. Vachon-Desjardins (Netwalker Ransomware)",
  "summary": "Affiliate of Netwalker ransomware responsible for attacking dozens of healthcare systems, universities, and businesses during the COVID-19 pandemic, extorting tens of millions of dollars.",
  "case_number": "8:20-cr-00366",
  "court": "U.S. District Court for the Middle District of Florida",
  "district": "M.D. Fla.",
  "country": "United States",
  "opened_at": "2020-12-16",
  "status": "sentenced",
  "victim_sector": "Healthcare, Education, Municipal Government",
  "victim_country": "United States, Canada",
  "loss_amount_usd": 21500000,
  "loss_amount_note": "Extorted $21.5 million in ransom payments; law enforcement seized 719 Bitcoin ($28 million) from his Canadian residence.",
  "first_seen_at": "2020-04-01T00:00:00Z",
  "last_updated_at": "2026-09-11T16:00:00Z",
  "actor_slug": "netwalker",
  "defendant_slugs": [
    "sebastien-vachon-desjardins"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1486",
      "evidence_excerpt": "Defendant injected Netwalker ransomware payloads into victim enterprise environments, encrypting files and leaving extortion notes with victim-specific payment portals.",
      "evidence_locator": "Plea Agreement \u00b6 4, Page 12",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Plea Agreement: U.S. v. Vachon-Desjardins",
      "source_url": "https://www.justice.gov/opa/pr/netwalker-ransomware-affiliate-sentenced-20-years-prison-role-international-cybercrime-scheme",
      "technique_name": "Data Encrypted for Impact",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Vachon-Desjardins obtained unauthorized access to corporate networks by purchasing stolen Remote Desktop Protocol credentials.",
      "evidence_locator": "Plea Agreement \u00b6 4, Page 13",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Plea Agreement",
      "source_url": "https://www.justice.gov/opa/pr/netwalker-ransomware-affiliate-sentenced-20-years-prison-role-international-cybercrime-scheme",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1490",
      "evidence_excerpt": "Before executing the ransomware payload, defendant disabled shadow copies and altered registry settings to prevent recovery.",
      "evidence_locator": "Indictment \u00b6 8",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Vachon-Desjardins",
      "source_url": "https://www.justice.gov/opa/pr/netwalker-ransomware-affiliate-sentenced-20-years-prison-role-international-cybercrime-scheme",
      "technique_name": "Inhibit System Recovery",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1112",
      "evidence_excerpt": "Netwalker modified registry keys under HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa to weaken local security authority validation.",
      "evidence_locator": "Plea Agreement \u00b6 6, Page 14",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Plea Agreement",
      "source_url": "https://www.justice.gov/opa/pr/netwalker-ransomware-affiliate-sentenced-20-years-prison-role-international-cybercrime-scheme",
      "technique_name": "Modify Registry",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1548.002",
      "evidence_excerpt": "The attacker used CMSTP and eventvwr.exe registry hijack methods to bypass Windows User Account Control without user prompting.",
      "evidence_locator": "Indictment \u00b6 11, Page 6",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment",
      "source_url": "https://www.justice.gov/opa/pr/netwalker-ransomware-affiliate-sentenced-20-years-prison-role-international-cybercrime-scheme",
      "technique_name": "Bypass User Account Control",
      "tactic": "Privilege Escalation"
    },
    {
      "technique_id": "T1007",
      "evidence_excerpt": "Vachon-Desjardins executed net start and sc query to enumerate installed antivirus services before deploying ransomware.",
      "evidence_locator": "Plea Agreement \u00b6 5, Page 13",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Plea Agreement",
      "source_url": "https://www.justice.gov/opa/pr/netwalker-ransomware-affiliate-sentenced-20-years-prison-role-international-cybercrime-scheme",
      "technique_name": "System Service Discovery",
      "tactic": "Discovery"
    }
  ],
  "events": [
    {
      "event_type": "indictment",
      "event_date": "2020-12-16",
      "description": "Federal grand jury in Tampa returns indictment charging Vachon-Desjardins with conspiracy to commit computer fraud and damage."
    },
    {
      "event_type": "extradition",
      "event_date": "2022-03-09",
      "description": "Vachon-Desjardins extradited from Canada to the United States."
    },
    {
      "event_type": "plea",
      "event_date": "2022-06-29",
      "description": "Defendant pleads guilty to all counts in the indictment."
    },
    {
      "event_type": "sentencing",
      "event_date": "2022-10-04",
      "description": "Sentenced to 240 months (20 years) in federal prison and ordered to forfeit $21.5 million."
    }
  ]
}