Dr. Evil? No. Evil Corp.? Yes. Treasury Takes Action

WASHINGTON–The U.S. Treasury’s Department’s Office of Foreign Assets Control (OFAC) has taken action against Evil Corp, a Russia-based cybercriminal organization it alleges is responsible for malware it has used to infect computers and harvest login credentials from hundreds of banks and financial institutions in over 40 countries, causing more than $100 million in theft.  

Treasury Dridex

According to Treasury,  Evil Corp. has used the Dridex malware to execute its alleged crimes. 

Concurrent with OFAC’s action, the Department of Justice said it has charged two of Evil Corp’s members with criminal violations, and the Department of State announced a reward for information up to $5 million leading to the capture or conviction of Evil Corp’s leader.  Treasury said it also worked with the United Kingdom’s National Crime Agency (NCA), as well as with FinCEN, and its own Office of Cybersecurity and Critical Infrastructure Protection (OCCIP), which released previously unreported indicators of compromise associated with the Dridex malware and its use against the financial services sector.   

Multi-Year Effort

“Treasury is sanctioning Evil Corp as part of a sweeping action against one of the world’s most prolific cybercriminal organizations.  This coordinated action is intended to disrupt the massive phishing campaigns orchestrated by this Russian-based hacker group,” said Treasury Secretary Steven T. Mnuchin in a statement. “OFAC’s action is part of a multiyear effort with key NATO allies, including the United Kingdom.  Our goal is to shut down Evil Corp, deter the distribution of Dridex, target the “money mule” network used to transfer stolen funds, and ultimately to protect our citizens from the group’s criminal activities.”

According to the Treasury Dept., the action clarifies that, in addition to his involvement in financially motivated cybercrime, the group’s leader, Maksim Yakubets, also provides direct assistance to the Russian government’s malicious cyber efforts, “highlighting the Russian government’s enlistment of cybercriminals for its own malicious purposes.”

Not First Action Against Evil Corp.

This is not the first action against Evil Corp.  In October 2015, the Department of Justice indicted Andrey Ghinkul for spreading the Dridex malware. 

“At that same time, the Federal Bureau of Investigation and the NCA disrupted the global infrastructure utilized at the time by Evil Corp.,” Treasury said. “Over the past several years, the NCA and the United Kingdom’s Metropolitan Police Service have arrested multiple individuals who enabled the activities of Evil Corp, including laundering stolen proceeds acquired through the Dridex malware.”

In all, the most recent action targets 17 individuals and seven entities to include Evil Corp, its core cyber operators, multiple businesses associated with a group member, and financial facilitators utilized by the group.  

Treasury said the Dridex malware is a multifunctional malware package that is designed to automate the theft of confidential information, to include online banking credentials from infected computers. 

How Malware Worked

“Dridex is traditionally spread through massive phishing email campaigns that seek to entice victims to click on malicious links or attachments embedded within the emails,” Treasury said. “Once a system is infected, Evil Corp uses compromised credentials to fraudulently transfer funds from victims’ bank accounts to those of accounts controlled by the group.  As of 2016, Evil Corp had harvested banking credentials from customers at approximately 300 banks and financial institutions in over 40 countries, making the group one of the main financial threats faced by businesses.  In particular, Evil Corp heavily targets financial services sector organizations located in the United States and the United Kingdom.”
Treasury said through its use of the Dridex malware, Evil Corp has illicitly earned at least $100 million, though it is likely that the total of their illicit proceeds is significantly higher.  

Section: Standard
Word Count: 728
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto.flux5.ccplatform.net/Fresh-Today/Dr.-Evil-No.-Evil-Corp.-Yes.-Treasury-Takes-Action