2 Russians charged in multimillion-dollar malware scheme

Image
AP Washington
Last Updated : Dec 06 2019 | 4:40 AM IST

The Justice Department unsealed charges Thursday against the alleged leader and an administrator of a Russian cyber-criminal gang that U.S. officials say developed and distributed malware used to steal at least $100 million from banks and other financial institutions in more than 40 countries over the past decade.

Separately, the Treasury Department said that in collaboration with Britain's National Crime Agency it was freezing all assets of the two Russian men along with 15 other associates and seven Russian-based organizations including Evil Corp., their alleged umbrella group.

Charged in a 10-count indictment filed in federal court in Pittsburgh were Evil Corp.'s alleged leader, Maksim V. Yakubets, 32, of Moscow and Igor Turashev, 38, from Yoshkar-Ola, Russia. The charges include conspiracy, computer hacking, wire fraud, and bank fraud. The two men have not been arrested, their whereabouts are unknown. Russia and the U.S. do not have an extradition treaty.

In a statement, Treasury officials also accused Jakubets of recruiting cybercriminals for Russia's government. According to the statement, he began working for FSB, a successor to the KGB spy agency, in 2017 and was tasked to work on projects including acquiring confidential documents through cyber-enabled means and conducting cyber-enabled operations on its behalf." The Treasury's press office would not elaborate on those projects.

The State Department and the FBI are offering a $5 million reward for information leading to Yakubets' arrest and conviction. Officials say that's the largest reward ever offered for an accused cybercriminal.

Prosecutors say the charges filed Thursday stem from the creation of malware Bugat (also known as Dridex and Kridex) that automates the theft of credentials used to log into banks and other financial institutions.

It was typically delivered through phishing emails that tricked users into entering their personal information at fake online banking websites, investigators said. The online thieves would then make unauthorized withdrawals.

Yakubets, who used the online moniker aqua, and Turashev are accused in the indictment of targeting two banks, a school district and four companies in Pennsylvania - a petroleum business, building supply company, vacuum and thin film deposition technology company and metal manufacturer - as well as a gun manufacturer.

The cybersecurity company FireEye said in an email that in the past year it has seen instances of Dridex infections being used not just for cybertheft but also to distribute ransomware to infected machines.

Today's announcement should make clear to those engaged in cybercrime that we will identify you, we will unmask you, and we will prosecute you, no matter how much effort it requires or how long it takes," said Assistant Attorney General Brian Benczkowski, who heads the Justice Department's criminal division.

Yakubets is also being charged in a separate case in Nebraska with allegedly conspiring to commit bank fraud in connection with other malware, authorities said.

Yakubets and his co-conspirators are alleged to have victimized 21 specific municipalities, banks, companies, and non-profit organizations in California, Illinois, Iowa, Kentucky, Maine, Massachusetts, New Mexico, North Carolina, Ohio, Texas, and Washington.

The case is not the first involving the cyber-racketeering ring. Two co-conspirators of Yakubets, both Ukrainian nationals, were extradited after their 2014 indictment and pleaded guilty to conspiracy charges, investigators said.

Disclaimer: No Business Standard Journalist was involved in creation of this content

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Dec 06 2019 | 4:40 AM IST

Next Story