ECONOMIC WARFARE & FUGITIVE BOUNTIES

OFAC Sanctions & Rewards for Justice

Tracking economic sanctions designated under Executive Orders 13694 and 14024, alongside active U.S. Department of State Rewards for Justice bounties targeting leaders of state-sponsored APTs and ransomware cartels.

Total Actions: 12
Active Bounties: 4 Offers
Max Bounty Offered: $10,000,000 USD
Programs: CYBER2 · RUSSIA-EO14024 · DPRK3

State Department Rewards for Justice Bounties

Active Fugitive $10 Million Reward

Dmitry Yuryevich Khoroshev (LockBit Leader)

State Department offers reward of up to $10,000,000 for information leading to the identification or location of Dmitry Khoroshev (aka LockBitSupp).

Active Fugitive $10 Million Reward

ALPHV / BlackCat Leadership

Up to $10,000,000 reward for information leading to identification of leaders of the ALPHV/BlackCat ransomware group responsible for Change Healthcare outage.

Active Fugitive $10 Million Reward

Russian GRU Unit 74455 Cyber Officers

Up to $10,000,000 for information identifying military intelligence personnel who deployed NotPetya, KillDisk, and Olympic Destroyer malware.

Active Fugitive $5 Million Reward

Maksim Viktorovich Yakubets (Evil Corp Leader)

State Department offers reward of up to $5,000,000 for information leading to the arrest or conviction of Maksim Yakubets for banking fraud and cyber extortion.

OFAC Specially Designated Nationals (SDN) Directory

Designated Entity / Individual Sanctions Program Designation Date Notes & Role Official Release
Karyna Kostiantynivna CYBER2 2024-10-01 Financial facilitator and confederate of Evil Corp designated in joint US-UK enforcement action. Treasury PR →
Dmitry Yuryevich Khoroshev CYBER2 2024-05-07 Developer and key leader of the LockBit ransomware group, designated in coordination with the UK and Australia. Treasury PR →
Mikhail Vasiliev CYBER2 2024-02-20 Designated LockBit ransomware affiliate extradited from Canada. Treasury PR →
Tornado Cash Virtual Currency Mixer CYBER2 2022-08-08 Decentralized cryptocurrency mixer used by the Lazarus Group to launder over $455 million in stolen crypto. Treasury PR →
Main Intelligence Directorate (GRU) Unit 74455 RUSSIA-EO14024 2021-04-15 Russian military intelligence unit responsible for the NotPetya wiper, Olympic Destroyer malware, and Ukrainian power grid cyberattacks. Treasury PR →
Maksim Viktorovich Yakubets CYBER2 2019-12-05 Leader of Evil Corp cybercriminal syndicate responsible for Dridex banking trojan and multimillion-dollar ransomware extortions. Treasury PR →
Evil Corp (Dridex Cybercrime Syndicate) CYBER2 2019-12-05 Russian cybercrime organization that extorted over $100 million from financial institutions and healthcare providers. Treasury PR →
Lazarus Group (Reconnaissance General Bureau) DPRK3 2019-09-13 North Korean state-sponsored hacking organization responsible for WannaCry, Sony Pictures hack, and crypto heists. Treasury PR →