
The Justice Department (DoJ) stated that a Russian man received a two-year prison sentence for running a botnet used to launch ransomware attacks against businesses in the U.S.
Ilya Angelov, age 40, from Tolyatti, Russia, was also penalized with a $100,000 fine. Angelov, known online as “milan” and “okart,” is believed to have been a co-leader of the Russian cybercrime group TA551 (also known as ATK236, G0127, Gold Cabin, Hive0106, Mario Kart, Monster Libra, and Shathak) from 2017 to 2021.
“Angelov’s group created their network of infected computers (a ‘botnet’) by spreading malware attached to junk emails,” the DoJ explained. “Angelov and his partner profited from this botnet by selling access to the individual infected machines (‘bots’).”
The sentencing document indicates that the criminal group developed specific programs to send out spam and refine malware to evade detection measures. Angelov and his associate managed staff and oversaw the diverse activities. The major malicious tool was a backdoor allowing malicious software to be installed on victims’ computers.
The main goal of these intrusions was to sell access to other criminal groups, who subsequently exploited it for ransomware schemes. TA551 granted the BitPaymer ransomware gang access to its botnet between August 2018 and December 2019, leading to the infection of 72 U.S. businesses. These attacks resulted in over $14.17 million in ransom payments.
The masterminds behind the IcedID malware also paid Angelov’s group more than $1 million around late 2019 / early 2020 to gain access to the botnet and to help spread ransomware; however, the full extent of damages caused is so far unknown. Itâs believed that this alliance developed after the takedown of the BitPaymer gang. Documentation revealed by the U.S. Federal Bureau of Investigation (FBI), showed the partnership went on to around August 2021.
In November 2021, Cybereason reported that the developers behind the TrickBot trojan had allied with TA551 to deliver Conti Ransomware. In that same month, French Computer Emergency Response Team (CERT-FR) also revealed that the Lockean ransomware gang was making use of TA551’s distribution services since the law enforcement dismantlement of the Emotet botnet occurred at the beginning of 2021.
“Foreign cybercriminals such as this defendant target citizens and corporations in America,” stated U.S. Attorney Jerome F. Gorgon Jr. “Their skills keep getting more evolved, but their intentions are the same – to steal from and hurt us.”
This announcement follows a related statement made just the day prior by the DoJ revealing that another Russian national, 26-year-old Aleksei Olegovich Volkov (aka “chubaka.kor” and “nets”), received nearly 7 years in prison after pleading guilty to working as an initial access broker (IAB) for Yanluowang ransomware operations that targeted eight American organizations between July 2021 and November 2022.
#(ta551). #botnet #for #gets #hacker #news #ransomware #russian #scheme #years — News
© Bulletproof Servers. All rights reserved.