logo

Behind the Scenes of Matveev's Ransomware Empire: Tactics and Team

ID: 071a59ed-5c2f-5cb5-8626-13418f804474

STIX ID: report--071a59ed-5c2f-5cb5-8626-13418f804474

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2023-12-19

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

PRODAFT attributes a widespread Russian ransomware operation to Mikhail "Wazawaka" Matveev and a six-person team, linking them to development and deployment of LockBit, Babuk, Hive and related operations since 2020; the analysis details their use of OSINT and scanning services, initial access brokers, brute-force and privilege escalation techniques, frequent abuse of MeshCentral RMM, and associations with known cybercriminals including Evil Corp and Evgeniy Bogachev.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.