Threat Picture
Latest Cybersecurity News

Maksim Yakubets: Inside the U.S. Case Against Evil Corp

U.S. charges link him to Zeus and Dridex. The case follows stolen banking credentials, money mules and an alleged criminal network.
By Charles Joseph · Updated
Share
Share
Copy URL

Maksim Yakubets is the most expensive name on the FBI's cyber most-wanted list. The US State Department has offered up to $5 million for information that leads to his arrest, the largest reward ever put on an accused cybercriminal when it was announced in 2019.

Prosecutors say he spent a decade behind two of the most destructive banking trojans ever written, Zeus and Dridex, and that the crew he led, Evil Corp, pulled more than $100 million out of bank accounts in more than 40 countries.

Yet he's never spent a night in a Western cell. He's been filmed driving a camouflage-wrapped Lamborghini with a number plate that translates as "thief," and the US Treasury says the Russian security service that could arrest him has had him working on its own projects instead.

Maksim Yakubets at a Glance

  • Born May 20, 1987, in Polonne, Ukraine, Yakubets became a Russian citizen and settled in Moscow, where he went by the handle "aqua."
  • From 2009, "aqua" recruited and managed the money mules for the Jabber Zeus crew, whose banking trojan attempted to steal an estimated $220 million from US accounts and got away with about $70 million.
  • In August 2012 a Nebraska grand jury charged "aqua" in a superseding indictment without knowing who he was.
  • By 2014 he was leading Evil Corp, the Moscow group behind the Bugat, Cridex and Dridex malware, which harvested banking logins from roughly 300 banks and financial institutions in over 40 countries.
  • The Treasury says that by 2017 he was also working for Russia's FSB and that by April 2018 he was obtaining a license to handle Russian classified information.
  • On December 5, 2019, the US unsealed charges against him, sanctioned Evil Corp and 17 of its people, and put up the $5 million reward.
  • Evil Corp answered the sanctions with a string of rebranded ransomware, from WastedLocker to Hades, Phoenix Locker and Macaw, and eventually slipped in among LockBit's affiliates.
  • In October 2024, the US, UK and Australia sanctioned his father, his former-FSB father-in-law and his right-hand man, laying out how the family protected the business.
  • He remains at large in Russia.
Sponsored

The Life of Maksim Yakubets

Yakubets's Early Years

Very little about Yakubets's childhood is on the public record. The sanctions listing gives his birthplace as Polonne, a small town in western Ukraine, and his birthday as May 20, 1987, and notes a Russian passport.

By the time he first appears in court papers he's 22 years old, living in Moscow, and already trusted with the part of a cybercrime operation that handles the money.

Aqua and the Jabber Zeus Crew

In 2009 the Zeus trojan was the sharpest tool in online bank fraud. Spam emails planted it on a victim's PC, where it captured usernames, passwords and one-time codes as they were typed into a banking site.

The crew that ran one of its most profitable variants chatted over Jabber, which is why investigators called them the Jabber Zeus crew. Its leader went by "tank," later identified as Ukrainian Vyacheslav Penchukov, and the man who kept the stolen money moving went by "aqua."

That was Yakubets's job. According to the FBI's complaint in Nebraska, he supplied the money mules: Americans recruited through online job sites who were "hired" as US representatives of Russian software companies and told to open accounts, receive payments and wire the funds overseas.

The victims were small and unglamorous, which was the point. A religious congregation in Chicago, an ethanol producer in Plainview, Nebraska, a county court in Kentucky and dozens of small businesses watched their accounts drain into mule accounts a few thousand dollars at a time.

Sponsored

"They Exposed the Entire Deal"

In July 2009, the reporter Brian Krebs wrote up one of those cases: thieves had taken $415,000 from Bullitt County, Kentucky. The crew read it, and the FBI later found their reaction in chat logs seized from a server.

"But they described the entire scheme," aqua wrote to tank on July 12, 2009. "The Bastards." A moment later he was blaming the publicity for the mules, or "drops," that'd been burned.

Those chats became evidence. In August 2012 a superseding indictment in Nebraska charged "aqua" with racketeering conspiracy, bank fraud and identity theft, but the name on the paperwork stayed a John Doe for another seven years.

Tank's luck ran out first. Penchukov was arrested in Switzerland in 2022, pleaded guilty in Nebraska and was sentenced to 18 years in 2024.

Building Evil Corp

Zeus was the apprenticeship. The business was Bugat, a trojan that later shipped under the names Cridex and Dridex.

Dridex arrived by phishing email, stole banking credentials, and increasingly installed ransomware on the networks it reached. Britain's National Cyber Security Centre said it'd been hitting UK victims since at least 2014, the year the NCA says Evil Corp formally took shape as a crime group.

According to the Treasury, Yakubets ran Evil Corp and kept personal control of the Dridex malware, while Igor Turashev, known online as "Enki," administered it. The NCA said the group employed dozens of people and ran its operations out of the basements of Moscow cafés.

The take was enormous. The Treasury put the losses from Dridex at more than $100 million, with credentials harvested from about 300 banks and financial institutions in over 40 countries.

Lamborghinis and a £250,000 Wedding

When British investigators finally went public, they brought photographs. Yakubets's cars included a custom-painted Audi R8 and a matching camouflage Lamborghini Huracán, and the NCA said his 2017 wedding cost more than a quarter of a million pounds.

The Lamborghini's personalized plate, the NCA noted, translates as "thief."

The wedding mattered for another reason. The bride's father, Eduard Benderskiy, was a former officer in the FSB's Vympel special forces unit, and the US and UK governments later described him as the bridge between the gang and the Russian state.

The Treasury said that by 2017 Yakubets was working for the FSB himself, tasked with "acquiring confidential documents through cyber-enabled means," and that by April 2018 he was getting a license to work with classified information.

Sponsored

The $5 Million Man

On December 5, 2019, Washington and London moved together. A Pittsburgh indictment returned on November 13 charged Yakubets and Turashev over Dridex, and a Nebraska complaint filed the next day finally tied "aqua" to his real name.

The same morning the Treasury designated Evil Corp, 17 individuals and seven companies, and the State Department announced its $5 million reward. The NCA, which had led the investigation since 2014, called Evil Corp the world's most harmful cyber crime group.

"The significance of this group of cyber criminals is hard to overstate," said the NCA's director general, Lynne Owens.

None of it produced an arrest. Russia doesn't extradite its citizens, and Yakubets stayed in Moscow.

Sanctions, Rebrands and a Garmin Outage

The sanctions were designed to bite anyway. Any US person who paid a ransom to Evil Corp risked breaking the law, so the group needed a new name.

It called its next ransomware WastedLocker. In July 2020, Garmin told regulators that an attack had encrypted some of its systems on July 23, knocking out services from fitness syncing to aviation flight planning for days. Security researchers tied the malware to Evil Corp, and the attackers were widely reported to have demanded $10 million.

More rebrands followed: Hades, Phoenix Locker, Macaw, and a spell impersonating a rival gang called PayloadBIN. By 2022 Mandiant was reporting that a cluster it linked to Evil Corp had simply started renting LockBit, blending in with the affiliates of the most prolific ransomware franchise on earth.

The Family Business

On October 1, 2024, the US, UK and Australia went after the people around him. The Treasury sanctioned seven more individuals, the UK 16, and the NCA finally said out loud what it'd learned about the family.

Viktor Yakubets, his father, had procured equipment for the group. Benderskiy, the father-in-law, had used his influence after 2019 to protect senior members from Russian authorities. And Aleksandr Ryzhenkov, Yakubets's second-in-command since 2013, was unmasked as a LockBit affiliate and indicted in the US over BitPaymer attacks.

The NCA added that before 2019 Russian intelligence had tasked Evil Corp with attacks and espionage against NATO allies, and estimated the group had extorted at least $300 million from victims worldwide.

Sponsored

Where Yakubets Is Now

He's still wanted and still free. The FBI lists him as a Russian citizen, and the reward remains on offer.

The old cases keep moving without him. In October 2025 Yuriy Rybtsov, the alleged Jabber Zeus coder known as "MrICQ," was extradited from Italy to Nebraska to face the 2012 charges that first named "aqua."

As long as Yakubets stays inside Russia, that's as close as the FBI is likely to get.

Maksim Yakubets: The Thief Who Never Had to Hide

Most of the great hackers in these pages were caught, flipped or quietly retired. Yakubets did none of those things, because he never had to.

His story is really a story about Russia, where a man wanted for stealing from nuns and county courts can marry into the security services and keep his Lamborghini.

The plate says "thief." He doesn't seem to see a reason to hide it.

QUOTE:

"Amateurs hack systems, professionals hack people."