A Russian national, Ilya Angelov, was sentenced to two years in prison after admitting that the phishing botnet he managed was used to deliver malware and enable BitPaymer ransomware attacks against 72 U.S. companies. The Mario Kart/TA551 operation ran massive spam campaigns that infected thousands of machines, sold access to ransomware affiliates (including ties to IcedID and TrickBot partners), and led to over $14 million in extortion payments. #BitPaymer #TA551
Keypoints
- Ilya Angelov pleaded guilty and was sentenced to two years for managing a phishing botnet used in BitPaymer ransomware attacks on 72 U.S. companies.
- The gang’s spam campaigns could send up to 700,000 emails per day and infected roughly 3,000 computers per day at the operation’s peak.
- The operation, tracked as Mario Kart and TA551, recruited coders and spammers, customized malware to evade defenses, and sold access to affiliates.
- The FBI tied the group’s activity to more than $14 million in extortion payments, and Angelov’s crew received about $1 million from IcedID for botnet access.
- Another defendant, Aleksey Volkov, was sentenced to nearly seven years for acting as an initial access broker for Yanluowang ransomware attacks.