Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Russian Pleads Guilty to Role in Developing TrickBot Malware

Russian national Vladimir Dunaev pleaded guilty to involvement in the development and use of the TrickBot malware that caused tens of millions of dollars in losses.

A Russian national has admitted to his role in developing and using the notorious TrickBot malware.

Vladimir Dunaev, 40, pleaded guilty to his involvement in the development and deployment of the TrickBot malware, which was used in cyberattacks against organizations worldwide, including hospitals and schools, causing tens of millions of dollars in losses.

Around since 2016, TrickBot was used to steal money and information, and acted as an initial access vector for other malware families, including ransomware such as Ryuk and Conti. The operation was taken down by law enforcement in 2022.

While active, the malware infected millions of computers worldwide, allowing threat actors to harvest sensitive information, including banking credentials, credit card numbers, social security numbers, dates of birth, emails, and passwords.

Dunaev, according to court documents, was part of the Trickbot gang between November 2015 and August 2020. In his role, he built “browser modifications and malicious tools that aided in credential harvesting and data mining from infected computers.”

He also developed tools that enabled the TrickBot operators to access the infected systems remotely, and helped the malware evade detection.

Advertisement. Scroll to continue reading.

Documents presented in court also show that, while Dunaev was actively involved in the scheme, TrickBot was used to deploy ransomware on the networks of 10 victims in the United States, including schools and a real-estate company, which were defrauded of more than $3.4 million.

Arrested in South Korea, Dunaev was extradited to the US in 2021. He is scheduled for sentencing on March 20, 2024.

Dunaev pleaded guilty to two counts of conspiracy to commit computer fraud and identity theft, and wire fraud and bank fraud. He faces up to 35 years in prison.

In February and September 2023, the US announced two rounds of sanctions against members of the TrickBot group, along with charges against numerous individuals involved in the malware’s development.

Related: Russian National Arrested, Charged for Role in LockBit Ransomware Attacks

Related: Russian Admits to Laundering Money for Ryuk Ransomware Gang

Related: US Sanctions Entities Aiding Russia’s Cyber Operations

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Mark Carter has been appointed Chief Information Security Officer at Socure.

Spektrum Labs has named Mark Cravotta Chief Operating Officer.

Philip Martin has joined Uber as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.