The EU sanctions, "Most active software extortion operator in history," Stern, involved over $300 million in ransom inflows
On 15 July, the United States, the European Union and the United Kingdom jointly announced the imposition of sanctions against a group of State-level hacker organizations, cybercrime gangs and their infrastructure providers, targeted for the cumulative loss of billions of dollars in global business, critical infrastructure and government institutions. Of particular concern is the EU sanctions against Russian cybercriminals, Vitally Nikolayevich Kovalev (alias “Stern”). The EU concludes that Stern is one of the infamous core managers of the Trickbot Group extortion software group, which includes a number of high-risk extortion software variations, including Conti ransomware and Ryuk. The chain analysis shows that Stern-related wallet addresses have accumulated more than $300 million in ransom payments, making them the “most widely blackmailed software operator” identified so far. According to the analysis, $300 million represents only the proceeds received by Stern individuals, and the Trickbot group as a whole may be much larger in illicit revenues. The flow of money along the chain shows that Stern had a trade-off with a number of extortion software ecology, including Ryuk, Conti, Diavol, Karakurt, Royal and Quantum. According to the survey, Stern plays a similar role within the Trickbot organization as the CEO, which is responsible for budget management, staff recruitment, infrastructure procurement and planning of attacks。
