US Offers $10 Million Reward For Russian Hacker

The United States has charged a Russian national with carrying out ransomware attacks against critical infrastructure.

The US Department of Justice (DoJ) announced on Tuesday that Mikhail Pavlovich Matveev (aka Wazawaka, aka m1x, aka Boriselcin, aka Uhodiransomwar) had alleged attacked law enforcement agencies in Washington DC, and New Jersey, as well as other victims worldwide.

The two unsealed indictments charge Matveev with using three different ransomware variants to attack numerous victims throughout the United States, and in a sign of how much the US wants to catch him, the US Department of State has announced an award of up to $10 million for information that leads to his arrest and/or conviction.

Ransomware allegations

So why does the US want Matveev so badly?

Well according to the DoJ from at least as early as 2020, Matveev allegedly participated in conspiracies to deploy three ransomware variants.

These variants are known as LockBit, Babuk, and Hive, and Matveev transmitted ransom demands in connection with each. The perpetrators behind each of these variants, including Matveev, have allegedly used these types of ransomware to attack thousands of victims in the United States and around the world.

These victims include law enforcement and other government agencies, hospitals, and schools.

The US said that total ransom demands allegedly made by the members of these three global ransomware campaigns to their victims amount to as much as $400 million, while total victim ransom payments amount to as much as $200 million.

“From his home base in Russia, Matveev allegedly used multiple ransomware variants to attack critical infrastructure around the world, including hospitals, government agencies, and victims in other sectors,” said Assistant Attorney General Kenneth A. Polite, Jr. of the Justice Department’s Criminal Division.

“These international crimes demand a co-ordinated response,” said Polite Jr. “We will not relent in imposing consequences on the most egregious actors in the cybercrime ecosystem.”

Among the attacks that Matveev allegedly carried out was an attack alongside his LockBit co-conspirators against a law enforcement agency in Passaic County, New Jersey.

On 26 April 2021, Matveev and his Babuk coconspirators allegedly deployed Babuk against the Metropolitan Police Department in Washington, DC.

Matveev is charged with conspiring to transmit ransom demands, conspiring to damage protected computers, and intentionally damaging protected computers.

If convicted, he faces over 20 years in prison.

Don’t give a ****

CNN quoted Azim Khodjibaev, senior threat analyst at Cisco Talos, who has tracked Matveev for years, saying that Matveev lives in the Russian enclave of Kaliningrad and regularly visits the Russian city of St. Petersburg.

Asked for comment by CNN on Twitter, Matveev replied with a video with a Russian man repeating the phrase, “I don’t give a f*** at all.”

With no extradition agreement between the US and Russia, and relations between Moscow and the rest of the world at an all time low due to Russia’s illegal invasion of Ukraine, there is little change that Matveev will end up in a US courtroom.

However, the temptation of a $10m reward for information leading to his arrest or conviction, may persuade some of his acquaintances to assist US authorities.

Tom Jowitt

Tom Jowitt is a leading British tech freelancer and long standing contributor to Silicon UK. He is also a bit of a Lord of the Rings nut...

Recent Posts

Intel To Invest More Than $28 Billion In Ohio Chip Factories – Report

Troubled chip giant Intel will invest more than $28 billion to construct two new chip…

2 days ago

Apple Returns To Top 5 Smartphone Ranks In China, Amid Tim Cook Visit

In Q3 Apple rejoins ranks of top five smartphone makers in China, as government welcomes…

2 days ago

Apple Cuts Orders iPhone 16, Says Analyst

Industry supply chain analyst says Apple cut orders for the iPhone 16 for Q4 2024…

2 days ago

LinkedIn Fined €310m By Irish Data Protection Commission

Heavy fine for LinkedIn, after Irish data protection watchdog cites GDPR violations with people's personal…

3 days ago

CMA Begins Probe Into Alphabet Partnership With Anthropic

UK competition regulator begins phase one investigation into Alphabet's partnership with AI startup Anthropic

3 days ago