{"id":57262,"date":"2024-10-01T14:08:10","date_gmt":"2024-10-01T14:08:10","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\/"},"modified":"2024-10-01T14:08:10","modified_gmt":"2024-10-01T14:08:10","slug":"nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\/","title":{"rendered":"NCA unmasks man it suspects is both &#8216;Evil Corp kingpin&#8217; and LockBit affiliate"},"content":{"rendered":"<p>The latest installment of the National Crime Agency&#8217;s (NCA) series of ransomware revelations from February&#8217;s LockBit Leak Week emerges today as the agency identifies a man it not only believes is a member of the long-running Evil Corp crime group but also a LockBit affiliate.<\/p>\n<p>The NCA claimed Aleksandr Ryzhenkov is a high-ranking Evil Corp member \u2013 and also alleged he is the LockBit affiliate who has been known as &#8220;Beverley&#8221; since at least 2022. The revelation is the first-of-its-kind about a known crossover between the two Russian gangs.<\/p>\n<p>The unmasking of Ryzhenkov follows the unveiling of the 194 total affiliates \u2013 the cronies that actually carry out ransomware attacks using the brand&#8217;s name \u2013 registered with LockBit at the time of the disruption in February.<\/p>\n<div class=\"promo_article\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2024\/05\/07\/handout_dmitry_yuryevich_khoroshev.jpg?x=174&amp;amp;y=115&amp;amp;crop=1\" width=\"174\" height=\"115\" alt=\"Handout of Dmitry Yuryevich Khoroshev from NCA\"><\/p>\n<h2 title=\"Dmitry Yuryevich Khoroshev's $10M question is answered at last\">Cops finally unmask &#8216;LockBit kingpin&#8217; after two-month tease<\/h2>\n<p><a href=\"https:\/\/www.theregister.com\/2024\/05\/07\/alleged_lockbit_kingpin_charged_sanctioned\/\"><span>READ MORE<\/span><\/a><\/div>\n<p>The disruption came to be known around these parts as LockBit Leak Week, since insights about the group were drip-fed to the public over the course of a week, using the ransomware gang&#8217;s own website to do it. The same website was revived to reveal this week&#8217;s fresh batch of intel.<\/p>\n<p>The 194 affiliates were only registered using the moniker assigned to them by LockBit. Cops who revealed that list believe the affiliate who went by &#8220;Beverley&#8221; to be Ryzhenkov.<\/p>\n<div class=\"CaptionedImage Border Center\" readability=\"10.197916666667\"><a href=\"https:\/\/regmedia.co.uk\/2024\/10\/01\/dmitriy_smirnov_and_aleksandr_ryzhenkov.jpg\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2024\/10\/01\/dmitriy_smirnov_and_aleksandr_ryzhenkov.jpg\" alt=\"Image of a young Dmitry Smirnov (left) and Aleksandr Ryzhenkov (right), two core Evil Corp members. Picture provided by the NCA\" title=\"Image of a young Dmitry Smirnov (left) and Aleksandr Ryzhenkov (right), two core Evil Corp members. Picture provided by the NCA\" height=\"512\" width=\"453\"><\/a><\/p>\n<p class=\"text_center\">From left, a young <a target=\"_blank\" href=\"https:\/\/home.treasury.gov\/news\/press-releases\/sm845\" rel=\"noopener\">Dmitry Smirnov<\/a> and Aleksandr Ryzhenkov, whom the NCA alleges are both core Evil Corp members, cuddle up with a baby cheetah. Picture provided by the NCA \u2013 click to enlarge<\/p>\n<\/div>\n<p>The law enforcement group also said it believes Ryzhenkov is one of Evil Corp leader Maksim Yakubets&#8217; closest professional allies and personal friends. The pair are known to frequently socialize together with their wives; they attended each other&#8217;s weddings and have vacationed together in the past too.<\/p>\n<p>They&#8217;ve also \u2013&nbsp;at least according to the crime agency \u2013 worked together as leading organized cybercriminals since at least 2011.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"condor\" data-xsm=\",fluid,mpu,\" data-sm=\",fluid,mpu,\" data-md=\",fluid,mpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/cybercrime&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2ZvwDWAP5xD-eCXvpC3TxuQAAAIE&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/cybercrime&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2ZvwDWAP5xD-eCXvpC3TxuQAAAIE&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>Ryzhenkov is said to have been active as a LockBit affiliate for around two years, and in that time he built 60 attacks using LockBit&#8217;s tools, the NCA claimed, which altogether led to attempted extortion demands totaling $100 million in Bitcoin.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"falcon\" data-xmd=\",fluid,mpu,leaderboard,\" data-lg=\",fluid,mpu,leaderboard,\" data-xlg=\",fluid,billboard,superleaderboard,mpu,leaderboard,\" data-xxlg=\",fluid,billboard,superleaderboard,brandwidth,brandimpact,leaderboard,mpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/cybercrime&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44ZvwDWAP5xD-eCXvpC3TxuQAAAIE&amp;t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/cybercrime&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44ZvwDWAP5xD-eCXvpC3TxuQAAAIE&amp;t=ct%3Dns%26unitnum%3D426raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<div class=\"adun_eagle_desktop_story_wrapper\">\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"mid\" data-raptor=\"eagle\" data-xxlg=\",mpu,dmpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/cybercrime&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33ZvwDWAP5xD-eCXvpC3TxuQAAAIE&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/cybercrime&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33ZvwDWAP5xD-eCXvpC3TxuQAAAIE&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<\/p><\/div>\n<p>While the evidence leading to Ryzhenkov&#8217;s identification is unknown, it&#8217;s understood that the authorities believe they have ample financial and technical proof to link him to Evil Corp.<\/p>\n<p>The NCA claimed that, together, Ryzhenkov and Yakubets form two key parts of one of the most successful groups of its kind, which has raked in hundreds of millions of dollars since first spinning up ten years ago, although the group&#8217;s lineage dates back to 2009.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"falcon\" data-xsm=\",fluid,mpu,\" data-sm=\",fluid,mpu,\" data-md=\",fluid,mpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/cybercrime&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44ZvwDWAP5xD-eCXvpC3TxuQAAAIE&amp;t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/cybercrime&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44ZvwDWAP5xD-eCXvpC3TxuQAAAIE&amp;t=ct%3Dns%26unitnum%3D426raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>Yakubets was believed to be involved with the Jabber Zeus crew, distributing the eponymous bank-draining malware until it was disrupted in 2010, with some alleged crew members arrested.<\/p>\n<p>The following year, Yakubets is said to have formed <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2015\/08\/06\/100m_business_gang_foxit_report\/\" rel=\"noopener\">The Business Club<\/a> with Ryzhenkov and Igor Turashev, who you may know from being <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2019\/12\/05\/evil_corp_russian_bounty_doj\/\" rel=\"noopener\">rapped in 2019<\/a> for his alleged role as a sysadmin in Yakubets&#8217; various criminal endeavors, including the creation and distribution of the <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2015\/10\/14\/dridex_botnet_takedown\/\" rel=\"noopener\">Dridex<\/a> and <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2014\/06\/03\/gameover_cryptolocker_takedown\/\" rel=\"noopener\">Gameover Zeus malware<\/a> strains.<\/p>\n<p>According to police, the trio went on to form Evil Corp in 2014. In addition to being known as the force behind the Dridex malware, they began experimenting with ransomware in 2017, namely with the <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2017\/08\/30\/lanarkshire_nhs_infection_named_as_bitpaymer_variant\/\" rel=\"noopener\">BitPaymer<\/a> variant, before going on to use various others in the following years. One of those we now know is LockBit.<\/p>\n<p>During its rise to infamy, Evil Corp worked its way up into a highly privileged position in the Russian government. The relationship between the criminal gang and the Russian security services is thought to be extraordinarily close, which was also revealed in a far greater extent today courtesy of the NCA.<\/p>\n<p>That&#8217;s a whole other story, though, which will appear on <em>The Register<\/em> later today.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" id=\"story_eagle_xsm_sm_md_xmd_lg_xlg\" data-pos=\"mid\" data-raptor=\"eagle\" data-xsm=\",mpu,dmpu,\" data-sm=\",mpu,dmpu,\" data-md=\",mpu,dmpu,\" data-xmd=\",mpu,dmpu,\" data-lg=\",mpu,dmpu,\" data-xlg=\",mpu,dmpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/cybercrime&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33ZvwDWAP5xD-eCXvpC3TxuQAAAIE&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/cybercrime&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33ZvwDWAP5xD-eCXvpC3TxuQAAAIE&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>It&#8217;s understood that the NCA&#8217;s work on Evil Corp hasn&#8217;t stopped since the disruption and sanctions storm in 2019, which were believed to have significantly hampered its activity since.<\/p>\n<p>The disruption led to reputational damage akin to what <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2024\/07\/31\/five_months_after_lockbit\/\" rel=\"noopener\">February&#8217;s action against LockBit had<\/a>, and its infrastructure needed to be rebuilt. The operation was never the same, and some of its members went on to pursue other lines of work, usually all related to malware.<\/p>\n<p>At the time, law enforcement investigators vowed never to give up until the key members were brought to justice, and that ambition persists five years later. \u00ae<\/p>\n<p> READ MORE <a href=\"https:\/\/go.theregister.com\/feed\/www.theregister.com\/2024\/10\/01\/nca_names_alleged_evil_corp_kingpin\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Aleksandr Ryzhenkov alleged to have extorted around $100M from victims, built 60 LockBit attacks The latest installment of the National Crime Agency&#8217;s (NCA) series of ransomware revelations from February&#8217;s LockBit Leak Week emerges today as the agency identifies a man it not only believes is a member of the long-running Evil Corp crime group but also a LockBit affiliate.\u2026 READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":57263,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-57262","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>NCA unmasks man it suspects is both &#039;Evil Corp kingpin&#039; and LockBit affiliate 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NCA unmasks man it suspects is both &#039;Evil Corp kingpin&#039; and LockBit affiliate 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2024-10-01T14:08:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/regmedia.co.uk\/2024\/05\/07\/handout_dmitry_yuryevich_khoroshev.jpg?x=174&amp;amp;y=115&amp;amp;crop=1\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"NCA unmasks man it suspects is both &#8216;Evil Corp kingpin&#8217; and LockBit affiliate\",\"datePublished\":\"2024-10-01T14:08:10+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\\\/\"},\"wordCount\":748,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/10\\\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate.jpg\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\\\/\",\"name\":\"NCA unmasks man it suspects is both 'Evil Corp kingpin' and LockBit affiliate 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/10\\\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate.jpg\",\"datePublished\":\"2024-10-01T14:08:10+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/10\\\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/10\\\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate.jpg\",\"width\":174,\"height\":115},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"NCA unmasks man it suspects is both &#8216;Evil Corp kingpin&#8217; and LockBit affiliate\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"NCA unmasks man it suspects is both 'Evil Corp kingpin' and LockBit affiliate 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\/","og_locale":"en_US","og_type":"article","og_title":"NCA unmasks man it suspects is both 'Evil Corp kingpin' and LockBit affiliate 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2024-10-01T14:08:10+00:00","og_image":[{"url":"https:\/\/regmedia.co.uk\/2024\/05\/07\/handout_dmitry_yuryevich_khoroshev.jpg?x=174&amp;amp;y=115&amp;amp;crop=1","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"NCA unmasks man it suspects is both &#8216;Evil Corp kingpin&#8217; and LockBit affiliate","datePublished":"2024-10-01T14:08:10+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\/"},"wordCount":748,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/10\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate.jpg","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\/","url":"https:\/\/www.threatshub.org\/blog\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\/","name":"NCA unmasks man it suspects is both 'Evil Corp kingpin' and LockBit affiliate 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/10\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate.jpg","datePublished":"2024-10-01T14:08:10+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/10\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/10\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate.jpg","width":174,"height":115},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/nca-unmasks-man-it-suspects-is-both-evil-corp-kingpin-and-lockbit-affiliate\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"NCA unmasks man it suspects is both &#8216;Evil Corp kingpin&#8217; and LockBit affiliate"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/57262","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=57262"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/57262\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/57263"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=57262"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=57262"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=57262"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}