Actor

Evil Corp (cybercriminal group)

Evil Corp (cybercriminal group) is the name used by several governments for a Russia-based cybercrime network associated with Dridex malware and related activity. Its secure statecraft relevance is as the target of coordinated sanctions, criminal charges and law-enforcement action. United States, United Kingdom and Australian authorities have also assessed links between named members and Russian state bodies. Those links remain attributed official assessments unless established in an adjudicated record. Profit-driven crime, state tolerance, state assistance and state direction are separate categories.

United States actions

On 5 December 2019, the United States Treasury designated seventeen individuals and seven entities associated with Evil Corp. Treasury attributed more than USD 100 million in theft across dozens of countries to the group and stated that its leader, Maksim Yakubets, had provided assistance to the Russian Federal Security Service (United States Treasury, 5 December 2019). The amount and state linkage are Treasury assessments, not adjudicated loss or a judicial finding.

The Department of Justice announced charges against Yakubets and Igor Turashev on the same date (United States Department of Justice, 5 December 2019). The indictment contains allegations, and each defendant is presumed innocent unless and until proved guilty (United States District Court, Criminal No. 19-303). Malware use, an alias or a wallet connection does not by itself establish operator identity.

Coordinated 2024 actions

On 1 October 2024, the United States announced additional sanctions against seven individuals and two entities in coordination with the United Kingdom and Australia (United States Treasury, 1 October 2024). The United Kingdom announced its designations and published a National Crime Agency assessment of the group's structure and alleged state relationships (United Kingdom government, 1 October 2024; National Crime Agency, 1 October 2024). Australia listed three persons on 2 October 2024 (Australian Department of Foreign Affairs and Trade). These actions have different legal bases and effects.

The United Kingdom financial-sanctions notice records identities, aliases, list references, dates and statements of reasons (Office of Financial Sanctions Implementation, 1 October 2024). The live United Kingdom Sanctions List continued to record the relevant Evil Corp designations when checked on 29 July 2026 and should be checked again immediately before publication. A listing creates jurisdiction-specific prohibitions subject to the relevant authority, licences, ownership rules and knowledge standards. It does not make every victim payment worldwide unlawful.

Assessment

Research on state-cybercrime relationships supports a typology rather than a presumption of state control (Lavorgna, 2023). Each person, entity, malware family and alleged successor brand requires identity-controlled evidence. Designations, indictments, intelligence assessments and convictions must remain separate legal categories.

See also

Ransomware and extortion as state-tolerated finance · Office of Foreign Assets Control (United States) · Specially Designated Nationals and Blocked Persons List · Lazarus Group · Economic statecraft

Sources

Recommended citation

Cite this entry

Tennant, James J., ed. 'Evil Corp (cybercriminal group).' The Encyclopedia of Economic Statecraft, version 2.0.0-alpha, last reviewed 29 July 2026. https://jamesjtennant.com/entries/evil-corp/.

Suggest an edit