Russian authorities arrested a malware in late September, causing a surprise as Russia is a country that is usually lenient with hackers. According to the Russian Interior Ministry, the accused is a 20-year-old Russian hacker from the North Ossetia-Alania region.

According to Russian authorities, the Russian hacker created several malware during the period from November 2017 to March 2018. He used this malware to infect at least 2,100 computers across Russia.
However, according to the indictment, the malware was not used by him alone. The defendant collaborated with six other people to distribute the malware. The entire group earned more than 4.3 million Russian rubles (~$55,000) thanks to this malware.
Russian authorities have not publicly named the arrested person. However, Benoit Ancel, a malware analyst at CSIS Security Group, said the suspect is a Russian hacker who is being monitored by other security researchers. His alias is “1ms0rry.”
In April 2018, Ancel and other security worked together to identify 1ms0rry's online businesses and malware.
Based on report , Ancel linked 1ms0rry to the following malware:
1ms0rry-Miner: a trojan that starts cryptocurrency mining immediately after installation on a device.
N0f1l3: an info-stealer trojan that steals data (browser passwords, cryptocurrency wallet configuration files, Filezilla FTP credentials, and specific files from the desktop) from infected computers.
LoaderBot: a trojan that first infects a device and then deploys other malicious programs.

According to the French researcher, Russian hacker 1ms0rry sold his malware on Russian-language hacking forums. In addition, some of them were eventually used to create even more powerful malware, such as Bumblebee (based on 1ms0rry-Miner), FelixHTTP (based on N0f1l3), EnlightenedHTTP and the very popular Evrial (which shared code with 1ms0rry's malware).
The 2018 report by the researcher and his collaborators also revealed some clues about 1ms0rry's true identity. The report stated that he was a talented young programmer from the city of Vladikavkaz, who had also received praise from local authorities for his involvement in cybersecurity .
However, the young programmer made a big mistake. His malware was used to attack Russian users.
Until now, Russian authorities have been lenient with Russian hackers and have turned a blind eye to various criminal activities. However, this was the case as long as Russian citizens and local businesses were not targeted.
In recent years, many Russian hacking groups have gone unpunished for operations conducted outside Russia's borders. Russian authorities have refused to extradite Russian hackers despite repeated accusations from US.
According to ZDNet, all major Russian-language hacking forums and the dark web make it very clear in their rules that members are prohibited from attacking users in the former Soviet space. Everyone knows that if they don't attack Russian citizens, they will be able to continue their activities without being bothered by the authorities.
Therefore, much of the malware is designed to avoid infecting Russian users.
However, it appears that 1ms0rry was either unaware of this rule or chose to deliberately ignore it for additional profits. In any case, the decision to target Russian users did not work out well for him.
