{"id":215,"date":"2024-11-27T10:05:25","date_gmt":"2024-11-27T10:05:25","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2024\/11\/27\/authorities-unmasked-lockbit-affiliate-evil-corp-key-member\/"},"modified":"2024-11-27T10:05:25","modified_gmt":"2024-11-27T10:05:25","slug":"authorities-unmasked-lockbit-affiliate-evil-corp-key-member","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2024\/11\/27\/authorities-unmasked-lockbit-affiliate-evil-corp-key-member\/","title":{"rendered":"Authorities Unmasked LockBit Affiliate Evil Corp Key Member"},"content":{"rendered":"<p>    Authorities Unmasked LockBit Affiliate Evil Corp Key Member<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Law enforcement agencies have identified Russian national Aleksandr Viktorovich Ryzhenkov as a key member of the notorious Evil Corp cybercrime group and a LockBit ransomware affiliate.<\/p>\n<p>Ryzhenkov, also known by his alias \u201cBeverley,\u201d has been linked to over 60 <a href=\"https:\/\/cybersecuritynews.com\/identity-lockbit-ransomware\/\" target=\"_blank\" rel=\"noreferrer noopener\">LockBit ransomware<\/a> builds and is believed to have sought to extort at least $100 million from victims in ransom demands.<\/p>\n<p>According to Authorities, Ryzhenkov was unmasked through data obtained during Operation Cronos, a joint investigation with international partners.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 84%,rgb(169,184,195) 100%)\">Analyse Any Suspicious Links Using ANY.RUN\u2019s New Safe Browsing Tool:<strong>\u00a0<a href=\"https:\/\/app.any.run\/?utm_source=li_csn&amp;utm_medium=linkedin&amp;utm_campaign=safebrowsing&amp;utm_content=service&amp;utm_term=300924\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try for Free<\/a><\/strong><\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiRzmslS_a6uw8ET6zL5nxH3a3dBWWCAE7Evrk0ApnNYTRLWst84AuCa91mqoiS91JMaTuFNB2FrLwWWAEwB4cHXqSRk7YCTYDZPDWZliEXePXj4r7T-KF74zifoAqnQI3oO2yH2dAl_KsR53_4wnjlHPRhxnLM4mLSu_qyQ6rD8op_ugsNyty2Ws5jHzeg\/s16000\/Wanted%2520by%2520FBI%2520%281%29.webp?ssl=1\" alt=\"\"><\/figure>\n<\/div>\n<p><a href=\"https:\/\/www.justice.gov\/opa\/pr\/russian-national-indicted-series-ransomware-attacks\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Authorities revealed<\/a> that Ryzhenkov used the affiliate name \u201cBeverley\u201d and was associated with the alias \u201cmx1r\u201d and the threat group UNC2165, an evolution of Evil Corp-affiliated actors.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi73VftNN-_PGLumM7f0bRXfFYaRfFkcTLdFwiZQ5tMF5T3V49HcHt0PEwQt5lmegRvO2j23cr5ZF4cpRvhLTxFF9HMEteKZLyx9LaQKgwM1A8fdl5cLdsgspjzG4W3PNKuZ8KAUf_08dTrK21UpjoU4W3v8tz94fVewYFRq51-Ws3RZvV4F_cxuFhtpmWl\/s16000\/Evil%2520Group%2520members%2520%26%2520Affiliates.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Evil Corp &amp; Affiliates (Source : U.S. Department of the Treasury)<\/figcaption><\/figure>\n<\/div>\n<p>The United Kingdom\u2019s Foreign, Commonwealth, and Development Office (FCDO), the United States Office of Foreign Assets Control (OFAC), and the Australian Department of Foreign Affairs and Trade (DFAT) have also sanctioned Ryzhenkov for his involvement in Evil Corp.<\/p>\n<p>In a separate development, the United States Department of Justice unsealed a 2023 indictment charging Ryzhenkov with using the BitPaymer ransomware variant to attack numerous victims in Texas and throughout the United States.<\/p>\n<p>The indictment alleges that Ryzhenkov and his conspirators gained unauthorized access to victims\u2019 computer networks, deployed the BitPaymer ransomware, and demanded millions of dollars in ransom.<\/p>\n<p>\u201cThe Justice Department is using all the tools at its disposal to attack the ransomware threat from every angle,\u201d said Deputy Attorney General Lisa Monaco. <\/p>\n<p>\u201cToday\u2019s charges against Ryzhenkov detail how he and his conspirators stole the sensitive data of innocent Americans and then demanded ransom. With law enforcement partners here and around the world, we will continue to put victims first and show these criminals that, in the end, they will be the ones paying for their crimes.\u201d<\/p>\n<p>Victims of ransomware attacks are encouraged to contact their local FBI field office. For additional information on ransomware, please visit <a href=\"https:\/\/cybersecuritynews.com\/cisa-fbi-releases-ttps-iocs-used-by-phobos-ransomware-group\/\" target=\"_blank\" rel=\"noreferrer noopener\">StopRansomware.gov<\/a>.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\">Free Webinar on How to Protect Small Businesses Against Advanced Cyberthreats\u00a0-&gt; <a href=\"https:\/\/my.demio.com\/ref\/eUcOj8lOn9xpgJb3?utm_source=cyber_security_news&amp;utm_medium=social&amp;utm_campaign=Q4-sponsored-webinars&amp;utm_content=ECMSIwebinar\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Free Webinar<\/strong><\/a><\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/cybersecuritynews.com\/authorities-unmasked-lockbit-affiliate\/\">Authorities Unmasked LockBit Affiliate Evil Corp Key Member<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/authorities-unmasked-lockbit-affiliate\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Authorities Unmasked LockBit Affiliate Evil Corp Key Member Law enforcement agencies have identified Russian national Aleksandr Viktorovich Ryzhenkov as a key member of the notorious Evil Corp cybercrime group and a LockBit ransomware affiliate. Ryzhenkov, also known by his alias \u201cBeverley,\u201d has been linked to over 60 LockBit ransomware builds and is believed to have [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-215","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/215"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=215"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/215\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=215"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=215"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=215"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}