4 December 2023

TrickBot developer pleads guilty, faces up to 35 years in prison


TrickBot developer pleads guilty, faces up to 35 years in prison

A Russian national has pleaded guilty to his involvement in developing and deploying the Trickbot malware.

“Vladimir Dunaev, 40, of Amur Blast, provided specialized services and technical abilities in furtherance of the Trickbot scheme,” the US Department of Justice said in a press release.

Disrupted in 2022, Trickbot was a modular banking trojan that over time evolved into a dangerous malware dropper used to deliver additional malware, including ransomware, on infected devices. The Trickbot Group primarily targeted victim computers belonging to businesses, entities, and individuals. Targets included hospitals, schools, public utilities, and governments.

Dunaev developed browser modifications and malicious tools used for credential harvesting and data stealing from infected computers, facilitated and enhanced the remote access used by Trickbot actors, and created a program code that allowed the Trickbot malware to stay undetected by anti-virus software.

During Dunaev’s participation in the scheme, 10 victims were defrauded of more than $3.4 million via ransomware deployed by Trickbot.

In 2021, Dunaev was extradited from the Republic of Korea to the United States.

Dunaev pleaded guilty to conspiracy to commit computer fraud and identity theft and conspiracy to commit wire fraud and bank fraud. He is scheduled to be sentenced on March 20, 2024, and faces a maximum penalty of 35 years in prison if found guilty.

In 2021, the US authorities charged another TrickBot developer, Alla Witte (aka Max) for her role in the TrickBot operation. In June 2023, she was sentenced to two years and eight months in prison.

In September of this year, the US and UK governments named and sanctioned 11 Russians said to be connected to the notorious TrickBot cybercrime crew. Sanctioned individuals include Trickbot actors involved in management and procurement, namely administrators, managers, developers and coders who have materially assisted the TrickBot group in its operations. In total, the joint US and UK operations sanctioned 18 TrickBot members.

Back to the list

Latest Posts

Cyber Security Week in Review: November 1, 2024

Cyber Security Week in Review: November 1, 2024

In brief: Hackers are exploiting critical zero-day flaw in PTZ cameras, the Dstat.cc DDoS service disrupted by law enforcement, and more.
1 November 2024
North Korean hackers caught collaborating with Play ransomware

North Korean hackers caught collaborating with Play ransomware

The theory is that Andariel is either working as an affiliate of Play ransomware or serving as an initial access broker.
31 October 2024
Large-scale phishing campaign targeting Ukraine's taxpayers

Large-scale phishing campaign targeting Ukraine's taxpayers

The attack deploys the Litemanager RMT, which provides unauthorized access to the infected computer.
30 October 2024