Russian authorities have arrested and charged notorious ransomware collaborator Mikhail Pavlovich Matveev (also known as Wazawaka, Uhodiransomwar, m1x, and Boriselcin) with developing malware and participating in various hacking.
See also: New Elpaco Ransomware variant uses RDP

While the prosecutor's office has not yet provided details on the identity of the individual (described as a "programmer" in court documents), the individual is Matveev, according to an anonymous source at Russian state news agency RIA Novosti.
As first identified by cyber expert Oleg Shakirov, Wazawaka is accused of developing ransomware (described by prosecutors’ notes as “specialized malware” that can encrypt files and data) that he planned to use to encrypt the data of “commercial organizations with a ransom demand for decryption.”
Last year, in May 2023, the US Department of Justice also filed charges against Matveev for his involvement in the Hive and LockBit that targeted victims across the United States.
He is also believed to be “Orange,” the original creator and administrator of the hacking forum Ramp , and the original administrator of the ransomware operation Babuk. The latter disbanded after members could not decide whether to publish data stolen from the Washington, D.C. Metropolitan Police Department.
See also: Starbucks: Suffered ransomware attack via third-party software provider
A Justice Department press release and unsealed indictments in New Jersey and the District of Columbia provide a rough timeline of his activity while working with the three ransomware gangs:

- In June 2020, Wazawaka and his LockBit co-conspirators allegedly deployed the LockBit ransomware on the network of a law enforcement agency in Passaic County, New Jersey.
- In April 2021, the Babuk ransomware defendant and associates allegedly deployed malicious payloads to the systems of the Metropolitan Police Department in Washington, D.C.
- In May 2022, members of the Hive and Matveev allegedly encrypted the systems of a nonprofit behavioral healthcare organization based in Mercer County, New Jersey.
Matveev was also sanctioned by the Treasury Department's Office of Foreign Assets Control (OFAC) for conducting cyberattacks against U.S. entities, including U.S. law enforcement agencies and critical infrastructure organizations.
The US State Department is also offering a reward of up to $10 million for any information that could lead to his arrest or conviction for transnational organized crime.
See also: Zyxel firewall vulnerability exploited in Ransomware attacks
Ransomware gangs represent one of the most dangerous situations we face today. These groups hold their victims’ files and data hostage, demanding a ransom to restore access. Ransomware attacks can have devastating consequences for both individuals and businesses, causing data loss, financial losses, and severe operational disruptions. It is essential to take preventive measures and strengthen the security of our systems and data to effectively address this threat.
Source: bleepingcomputer
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
