Botnet Ransomware Manager Sentenced to 2 Years.
Mar 25, 2026 // 11:57 - Lina Schonbein


A Russian man was sentenced to two years in jail after confessing to running a phishing network that was used in BitPaymer ransomware attacks on 72 American businesses.

According to legal documents, Ilya Angelov, 40, (known online as “milan” and “okart”) decided to travel to the U.S. to admit guilt and face charges after Russia invaded Ukraine in February 2022, and after Vyacheslav Igorevich Penchukov, an associate and member of the IcedID cybercrime group, was apprehended in Switzerland.

Angelov was one of the two ringleaders of a Russian cybercriminal group known as Mario Kart by the FBI, and as TA551, Shathak, GOLD CABIN, Monster Libra, ATK236, and G0127 by various cybersecurity firms.

Angelov and his co-leader employed members and managed the group’s illegal activities. The gang members held various roles, including software developers who created malware, programs for distributing spam emails, and customized malware to avoid security software.

“Through a massive spam campaign of up to 700,000 emails per day, the group spread malware worldwide,” prosecutors stated. “When an unsuspecting recipient clicked on an email attachment, malware would infect their computer, adding it to the Mario Kart botnet. At its peak, approximately 3,000 computers were infected daily.”

The cybercrime gang employed a large botnet to spread malware through widespread phishing campaigns between 2017 and 2021. They then sold access to these infected devices to other cybercriminals, notably those participating in Ransomware-as-a-Service (RaaS) schemes.

“This access was sold to other criminal organizations, who typically conducted ransomware attacks, which involved locking victims out of their computer networks and seeking payments, typically in cryptocurrency, to restore access,” the Justice Department announced on Tuesday.

“The FBI has identified over 70 U.S. companies that were infected with ransomware by an organization linked to Angelov’s group, resulting in more than $14 million in ransom payments.”

While these attacks occurred between August 2018 and December 2019 and were all linked to the BitPaymer ransomware operation, the IcedID cybercrime group also paid Angelov and his accomplices an additional million dollars between late 2019 and August 2021 for access to their bots, but the resulting damage is currently unknown.

TA551 has previously been linked to different malware distributors and some ransomware affiliates. TA551 operators also worked with the TrickBot group (Wizard Spider) in phishing campaigns that deployed Conti ransomware on compromised systems.

France’s Computer Emergency Response Team (CERT) also reported TA551 as an accomplice in the Lockean ransomware operation, responsible for delivering ProLock, Egregor, and DoppelPaymer ransomware to devices infected with the Qbot/QakBot banking trojan.

This week, Aleksey Olegovich Volkov, a 26-year-old Russian national, was sentenced to almost 7 years in prison after admitting to being an initial access broker (IAB) for Yanluowang ransomware attacks.

#botnet  #manager.  #news  #ransomware  #sentenced  #years   —   News