The U.S. Department of Justice announced that a Russian national has been sentenced to two years in prison for operating a botnet that was used to carry out ransomware attacks against U.S. companies. Ilya Angelov , 40, of Tolyatti, Russia, was also fined $100,000.

Angelov, known online by the aliases 'milan' and 'okart', allegedly co-led a Russian cybercrime group known as TA551 (also known as ATK236, G0127, Gold Cabin, Hive0106, Mario Kart, Monster Libra and Shathak) between 2017 and 2021.
See also: Intellexa Tal Dilian: Shots against the Greek government
“Angelov’s group created a network of compromised computers (a ‘botnet’) by distributing malicious files attached to spam emails,” the Justice Department said. “Angelov and his co-administrator then exploited this botnet by selling access to individual compromised computers (‘bots’).”
According to the indictment, the threat group developed programs to distribute spam emails and improved malware to bypass security tools. Angelov and his co-administrator recruited members and oversaw the various activities. Their main tool was a backdoor, through which malware could be loaded onto victims' computers.
Use of botnet for ransomware attacks
The main goal of the attacks was to resell the access to other criminal groups, who used it for ransomware. Between August 2018 and December 2019, TA551 provided the BitPaymer ransomware with access to its botnet. This access allowed the gang to infect 72 US companies. This resulted in more than $14.17 million in ransom payments.
See also: Cyberattack on the Dutch Ministry of Finance

The operators of the IcedID malware also paid Angelov's group over a million dollars to gain access to the botnet and distribute ransomware, although the extent of the damage is not yet known.
Later, in November 2021, Cybereason revealed that operators of the TrickBot trojan were working with TA551 to distribute the Conti Ransomware. In the same month, the French Computer Emergency Response Team (CERT-FR) also revealed that the Lockean ransomware was using the distribution services offered by TA551 after the Emotet botnet collapsed.
“Foreign cybercriminals, like this defendant, target American citizens and companies,” said U.S. Attorney Jerome F. Gorgon Jr.“Their methods are becoming more sophisticated. But their motive remains the same – to deceive us and harm us.”
See also: Mazda: Data breach affects employees and partners

It is worth noting that another Russian national, 26-year-old Aleksei Olegovich Volkov (also known as “chubaka.kor” and “nets”), was recently sentenced to almost 7 years in prison after pleading guilty to acting as an initial access broker (IAB) for ransomware attacks.
Source: thehackernews.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
