Trickbot ransomware hackers hit with US and UK sanctions

Quick Take

  • Law enforcement agencies in the U.S. and UK sanctioned 11 additional members of the Russian crypto ransomware group Trickbot. 
  • Trickbot members used various ransomware strains to extort at least $833 million in cryptocurrency from victims.

Eleven additional members of the Russian ransomware group Trickbot were sanctioned in a joint enforcement effort brought by the U.S. and UK. 

The Trickbot group used ransomware strains called Ryuk, Conti, Diavol, Karakurt and others to extort victims for at least $833 million in cryptocurrency — mainly bitcoin — over their lifetimes, Chainalysis found. Trickbot is the second largest crypto-based cybercrime organization behind the North Korean hacker league Lazarus Group

The 11 Russian nationals sanctioned Thursday join seven Trickbot members hit with sanctions in February of this year, which also marked the first ever joint sanctions between the U.S. and UK. The 18 individuals face travel bans, asset freezes and curtailed access to legitimate financial services, the UK National Crime Agency said.

Trickbot targets

"Attacks by this ransomware group have caused significant damage to our businesses and ruined livelihoods, with victims having to deal with the prolonged impact of financial and data losses," the NCA added. 

Trickbot members targeted hospitals, schools, local authorities and businesses in the UK and government entities, businesses health care providers during the COVID-19 pandemic in the U.S.

© 2023 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.