Russian hackers are raking in ransomware rewards

Ransomware
Image credit: Shutterstock (Image credit: Shutterstock)

Most of the money made from ransomware operations ends up in the hands of Russian-speaking threat actors, a report from market analysts Chainalysis claims.

Speaking to the BBC, Chainalysis says 74% of all money stolen through ransom demands in 2021 went to threat actors linked to Russia, in one way or another - equivalent to more than $400 million worth of cryptocurrencies.

What’s more, Chainalysis claims that “a huge amount of cryptocurrency-based money laundering” is being conducted by Russian cryptocurrency companies, as well.

Refraining from attacking Russian-speaking businesses

Most cryptocurrencies are easy to track. Their respective blockchains (the technology underpinning the tokens, or coins) are usually transparent, meaning that specific coins can easily be tracked through time. Also, specific cryptocurrency wallets can be monitored freely. 

But it’s not just wallets and money that the researchers are tracking. The BBC also reported that the malware usually used in ransomware attacks displays unique characteristics like being prevented, at code-level, from damaging files and companies on endpoints located in Russia, or other Russian-speaking countries. 

The gangs that distribute the ransomware usually hang out on Russian-speaking forums, and they are often linked to Evil Corp, a threat actor group wanted by the US which, Chainalysis claims, takes almost 10% of all ransomware revenue.

The problem with this line of thinking, BBC also adds, is that many of the ransomware threat actors work on a RaaS principle, offering Ransomware as a service to whoever is willing to pay. 

Russia, on the other hand, has denied the accusations of facilitating cyber-criminals. To that end, it reminded of the dismantling of the REvil ransomware operators, which it did at the request of the States.

Still, one of Evil Corp’s alleged leaders, Igor Turashev, is running multiple businesses from Moscow City’s Federation Tower, one of the country’s “most prestigious” addresses, the BBC added. 

"In any given quarter, the illicit and risky addresses account for between 29% and 48% of all funds received by Moscow City crypto-currency businesses", Chainalysis concluded.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Less than half of ransomware incidents end in payment - but you should still be on your guard
A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag
China government-linked hackers caught running a seriously dangerous ransomware scam
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
More reports claim 2024 was the worst year for ransomware attacks yet
Flags of Iran, China, Russia and North Korea on a wall. China North Korea Iran Russia alliance
Cybercrime is helping fund rogue nations across the world - and it's only going to get worse, Google warns
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Bad news - businesses who pay ransomware attackers aren’t very likely to get their data back
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Latest in Security
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Meta warns of worrying security flaw hitting open source type software
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Biometrics add another layer of security to passwordless authentication
Data leak
Hacked Tata Technologies data leaked by ransomware gang
Latest in News
Google Gemini Flash 2.0 Images
I tried Gemini's new AI image generation tool - here are 5 ways to get the best art from Google's Flash 2.0
An image of the Samsung Galaxy S25 Ultra from a hands-on event
Samsung Galaxy S26 Ultra could resurrect an intriguing camera feature
Eurocom Raptor X18
At $15,000, this massive 256GB RAM laptop makes Apple's MacBook Pro look affordable, tiny and very, very slow
Cristin Milioti in Black Mirror season 7
Netflix launches trailer for Black Mirror season 7, giving us a look at its first-ever sequel episode and an unexpected returning character
A graphic of the PC Gaming Show
Get ready for a bounty of PC games on June 8, as the PC Gaming show is back
A close up of The Daily podcast from Pocket Casts' web page
‘Podcasting shouldn’t be locked behind walled gardens’: Pocket Casts slams Spotify and makes its web player free to all