{
  "id": "case-trickbot-witte",
  "slug": "us-v-witte-dunaev-trickbot",
  "title": "U.S. v. Alla Witte & Vladimir Dunaev (Trickbot Malware Group)",
  "summary": "Key software developers and coders of the transnational Trickbot cybercrime group charged with infecting millions of victim computers with banking trojans and facilitating Conti/Ryuk ransomware deployments against hospitals.",
  "case_number": "1:20-cr-00384",
  "court": "U.S. District Court for the Northern District of Ohio",
  "district": "N.D. Ohio",
  "country": "United States",
  "opened_at": "2021-02-18",
  "status": "sentenced",
  "victim_sector": "Healthcare, Banking, Local Government",
  "victim_country": "United States, United Kingdom, Australia",
  "loss_amount_usd": 180000000,
  "loss_amount_note": "Extorted tens of millions of dollars and caused hundreds of millions in financial damages to hospitals and municipalities.",
  "first_seen_at": "2016-10-01T00:00:00Z",
  "last_updated_at": "2026-08-30T10:00:00Z",
  "actor_slug": "wizard-spider",
  "defendant_slugs": [
    "alla-witte",
    "vladimir-dunaev"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1566.001",
      "evidence_excerpt": "Trickbot was deployed via phishing emails masquerading as legal notices containing weaponized Word documents with malicious macros.",
      "evidence_locator": "Indictment \u00b6 14, Page 7",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Witte et al.",
      "source_url": "https://www.justice.gov/opa/pr/russian-national-sentenced-role-developing-and-deploying-trickbot-malware",
      "technique_name": "Spearphishing Attachment",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1003",
      "evidence_excerpt": "Injected modular credential harvesters that pulled domain credentials from Windows memory to pave the way for ransomware.",
      "evidence_locator": "Indictment \u00b6 19, Page 11",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment",
      "source_url": "https://www.justice.gov/opa/pr/russian-national-sentenced-role-developing-and-deploying-trickbot-malware",
      "technique_name": "OS Credential Dumping",
      "tactic": "Credential Access"
    },
    {
      "technique_id": "T1486",
      "evidence_excerpt": "Trickbot acted as the primary access loader for Ryuk and Conti ransomware gangs targeting US medical facilities.",
      "evidence_locator": "CISA Advisory AA20-302A",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA20-302A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-302a",
      "technique_name": "Data Encrypted for Impact",
      "tactic": "Impact"
    }
  ],
  "events": [
    {
      "event_type": "extradition",
      "event_date": "2021-06-04",
      "description": "Alla Witte extradited from Suriname to the Northern District of Ohio."
    },
    {
      "event_type": "extradition",
      "event_date": "2021-10-20",
      "description": "Vladimir Dunaev extradited from the Republic of Korea to the Northern District of Ohio."
    },
    {
      "event_type": "sentencing",
      "event_date": "2023-06-20",
      "description": "Alla Witte sentenced to 32 months in prison after pleading guilty."
    },
    {
      "event_type": "sentencing",
      "event_date": "2024-01-24",
      "description": "Vladimir Dunaev sentenced to 64 months (5 years and 4 months) in federal prison."
    }
  ]
}