Evil Corp debuts WastedLocker ransomware & new TTPs, researchers say

Evil Corp debuts WastedLocker ransomware & new TTPs, researchers say

Researchers have discovered a new ransomware, WastedLocker, that they are attributing with “high confidence” to the Evil Corp cybercriminal gang, two members of which the U.S. Justice Department charged last December with federal hacking and bank fraud crimes.


Evil Corp is historically associated with the banking credentials-stealing Zeus trojan and Bugat (aka Dridex) malware, as well as Locky and more recently BitPaymer ransomware. However, since mid-March there has been a marked decrease in BitPaymer attack activity, according to NCC Group and its Fox-IT InTELL division in a company blog post on Tuesday. It’s likely that during this quiet period, the adversaries were busy developing the new WastedLocker ransomware program, which first debuted in May 2020.


Additionally, the cybercriminals have apparently changed up some of its TTPs in 2020. “We believe those changes were ultimately caused by the unsealing of [DOJ] indictments against [alleged Evil Corp members] Igor Olegovich Turashev and Maksim Viktorovich Yakubets, and the financial sanctions against Evil Corp in December 2019,” the NCC Group blog post states. “These legal events set in motion a chain of events to discon ..

Support the originator by clicking the read the rest link below.