Article Details
Scrape Timestamp (UTC): 2024-01-26 05:36:35.442
Source: https://thehackernews.com/2024/01/russian-trickbot-mastermind-gets-5-year.html
Original Article Text
Click to Toggle View
Russian TrickBot Mastermind Gets 5-Year Prison Sentence for Cybercrime Spree. 40-year-old Russian national Vladimir Dunaev has been sentenced to five years and four months in prison for his role in creating and distributing the TrickBot malware, the U.S. Department of Justice (DoJ) said. The development comes nearly two months after Dunaev pleaded guilty to committing computer fraud and identity theft and conspiracy to commit wire fraud and bank fraud. "Hospitals, schools, and businesses were among the millions of TrickBot victims who suffered tens of millions of dollars in losses," DoJ said. "While active, Trickbot malware, which acted as an initial intrusion vector into victim computer systems, was used to support various ransomware variants." Originating as a banking trojan in 2016, TrickBot evolved into a Swiss Army knife capable of delivering additional payloads, including ransomware. Following efforts to take down the botnet, it was absorbed into the Conti ransomware operation in 2022. The cybercrime crew's allegiance to Russia during the Russo-Ukrainian war led to a series of leaks dubbed ContiLeaks and TrickLeaks, which precipitated its shutdown in mid-2022, resulting in its fragmentation into numerous other ransomware and data extortion groups. Dunaev is said to have provided specialized services and technical abilities to further the TrickBot scheme between June 2016 and June 2021, using it to deliver ransomware against hospitals, schools, and businesses. Specifically, the defendant developed browser modifications and malicious tools that made it possible to harvest credentials and sensitive data from compromised machines as well as enable remote access. He also created programs to prevent the Trickbot malware from being detected by legitimate security software. Another TrickBot developer, a Latvian national named Alla Witte, was sentenced to two years and eight months in prison in June 2023. News of Dunaev's sentencing comes days after governments from Australia, the U.K., and the U.S. imposed financial sanctions on Alexander Ermakov, a Russian national and an affiliate for the REvil ransomware gang, for orchestrating the 2022 attack against health insurance provider Medibank. Cybersecurity firm Intel 471 said Ermakov went by various online aliases such as blade_runner, GustaveDore, JimJones, aiiis_ermak, GistaveDore, gustavedore, GustaveDore, Gustave7Dore, ProgerCC, SHTAZI, and shtaziIT. As JimJones, he has also been observed attempting to recruit unethical penetration testers who would supply login credentials for vulnerable organizations for follow-on ransomware attacks in exchange for $500 per access and a 5% cut of the ransom proceeds. "These identifiers are linked to a wide range of cybercriminal activity, including network intrusions, malware development, and ransomware attacks," the company said, offering insights into his cybercrime history. "Ermakov had a robust presence on cybercriminal forums and an active role in the cybercrime-as-a-service economy, both as a buyer and provider and also as a ransomware operator and affiliate. It also appears that Ermakov was involved with a software development company that specialized in both legitimate and criminal software development." SaaS Security Masterclass: Insights from 493 Companies Watch this webinar to discover Critical SaaS Security Do's and Don'ts based on a study of 493 companies, offering real-world comparisons and benchmarks.
Daily Brief Summary
Russian cybercriminal Vladimir Dunaev is sentenced to 5 years and four months in prison for his involvement with TrickBot malware.
Dunaev provided technical skills for the TrickBot scheme, which impacted hospitals, schools, and businesses with significant financial losses.
TrickBot evolved from a banking trojan to a multi-purpose tool, ultimately becoming part of the Conti ransomware operation.
The TrickBot network fragmented after leaks exposed its activities, leading to a multitude of other cybercrime efforts.
Dunaev developed tools to harvest sensitive data, enable remote access, and evade detection by security software.
His sentencing follows the recent conviction of another TrickBot developer, Latvian national Alla Witte.
Governments from Australia, the U.K., and the U.S. have sanctioned Alexander Ermakov, affiliated with REvil, signifying ongoing international cybersecurity collaborations and enforcement.