The Evolution of Cybercrime: From Jabber Zeus to Evil Corp and the Reign of “Aqua“
The world of cybercrime is a constantly evolving landscape, and few stories illustrate this better than the rise and fall – and continued operation - of groups like Jabber zeus and its successor, Evil Corp. This article delves into the history of these refined criminal enterprises, the innovative techniques they employed, and the individuals behind them, offering a comprehensive look at a decade of digital theft.
The Jabber zeus Trojan: A Game Changer
Initially, the Jabber Zeus trojan represented a critically important leap in online banking fraud. According to security researcher Brian Baldwin, this malware featured a custom “backconnect” component. This allowed hackers to route bank account takeovers through the victim’s own infected computer, effectively masking their location.
This meant the attackers were connecting to your bank account using your IP address, and even fully mimicking your device. Baldwin described the trojan as “a hot knife through butter,” easily bypassing the security measures considered state-of-the-art at the time.
unmasking the players: Enter maksim Yakubets – “Aqua”
While the Jabber Zeus crew collaborated with the original Zeus author, intercepted communications revealed a troubling dynamic. The group frequently pleaded for assistance, often ignored by the creator. Though, investigations by law enforcement identified the true leader of the jabber Zeus operation as Maksim Yakubets, a 38-year-old Ukrainian national with Russian citizenship.
Yakubets operated under the hacker handle “Aqua.” He frequently interacted with key team members like MrICQ and Tank, coordinating money mule operations and cashouts from within Russia.
[Image of Maksim “Aqua” Yakubets – FBI]
The Birth of Evil Corp and the Dridex Trojan
subsequently, Yakubets/Aqua would emerge as the head of an even more elite cybercrime ring: evil corp. This group, comprised of at least 17 hackers, developed and deployed the Dridex trojan (also known as Bugat).
Dridex proved incredibly effective, enabling Evil Corp to steal over $100 million from hundreds of companies across the United States and Europe. They targeted businesses, not individuals, making their attacks particularly damaging.
How Did They Operate?
Here’s a breakdown of Evil Corp’s key tactics:
* Sophisticated Malware: Dridex was designed to steal banking credentials and other sensitive information.
* Money Mules: The group relied on a network of money mules to launder stolen funds.
* Remote Control: Aqua and other leaders maintained remote control over operations, often from within Russia.
* Targeted Attacks: Evil Corp focused on large organizations, maximizing potential profits.
The Investigation and the $5 Million Bounty
Law enforcement agencies have been actively pursuing Evil Corp and its members for years. In 2019, the U.S. government offered a $5 million bounty for information leading to Yakubets’s arrest.
This bounty announcement included excerpts from intercepted chats, revealing the group’s awareness of media coverage surrounding their victims – including reporting by KrebsOnSecurity. both Baldwin and I contributed to a new six-part podcast by the BBC that explores the history of Evil Corp in detail.
* Episode One: Focuses on the evolution of the Zeus trojan. (https://www.bbc.com/audio/play/w3ct89y8)
* Episode Two: centers on the investigation led by former FBI agent Jim Craig. (https://www.bbc.com/audio/play/w3ct89y9)
[Image of BBC Cyberhack Podcast]
What Does This Mean for You?
The story of Jabber Zeus and Evil Corp serves as a stark reminder of the ever-present threat of cybercrime.You need to understand that these groups are highly organized, technically skilled, and relentlessly pursuing financial gain.
Here are some steps
Related reading