Malware

Russian developer of Trickbot malware pleads guilty

0

A Russian national pleaded guilty to charges related to his involvement in developing and deploying the Trickbot malware, which was used to attack hospitals, companies, and individuals in the United States and worldwide.

The 40-year-old individual, also known as FFX, oversaw the development of TrickBot’s browser injection component as a malware developer.

Dunaev’s association with the TrickBot malware syndicate started in June 2016 after being hired as a developer following a recruitment test requiring him to create an app simulating a SOCKS server and to alter the Firefox browser.

In September 2021, he was arrested in South Korea while attempting to depart and remained there for over a year. The extradition process was finalized on October 20, 2021.

Dunaev and his codefendants hid behind their keyboards, first to create Trickbot, then using it to infect millions of computers worldwide — including those used by hospitals, schools, and businesses — invading privacy and causing untold disruption and financial damage.

The TrickBot malware was used to gather personal and sensitive information (including credentials, credit cards, emails, passwords, dates of birth, SSNs, and addresses) and steal funds from their victims’ banking accounts.

Dunaev entered a guilty plea for charges related to conspiracy to commit computer fraud and identity theft, alongside conspiracy charges for wire and bank fraud. His sentencing is set for March 20, 2024, and he is facing a maximum sentence of 35 years in prison for both offenses.

The initial indictment charged Dunaev and eight codefendants for their alleged involvement in developing, deploying, administering, and profiting from the Trickbot operation.

Dunaev is the second TrickBot gang malware developer arrested by the U.S. Department of Justice. In February 2021, Latvian national Alla Witte (aka Max) was apprehended and charged with helping write the code used to control and deploy ransomware on victims’ networks.

The TrickBot malware which surfaced in 2015, initially focused on stealing banking credentials. It was then evolved into a modular tool leveraged by cybercrime organizations such as Ryuk and Conti ransomware for initial access into compromised corporate networks.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

FjordPhantom Android malware targets Banking apps

Previous article

AeroBlade hackers target US aerospace sector

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *