Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

On September 7, 2023, the U.S. Treasury Department’s Office of Foreign Assets Control (OFAC), coordinating with the United Kingdom, designated 11 people Treasury identified as members of the Russia-based Trickbot cybercrime group. The announcement also noted that the U.S. Department of Justice was unsealing nine indictments related to Trickbot malware and Conti ransomware schemes; seven of the designated people were included. Sanctions designations and criminal indictments are separate actions, and the Treasury announcement does not establish the outcome of those cases.

Who did the United States and United Kingdom sanction?

Treasury named these 11 individuals in its September 7, 2023 announcement:

  • Andrey Zhuykov
  • Maksim Galochkin
  • Maksim Rudenskiy
  • Mikhail Tsarev
  • Dmitry Putilin
  • Maksim Khaliullin
  • Sergey Loguntsov
  • Vadym Valiakhmetov
  • Artem Kurov
  • Mikhail Chernov
  • Alexander Mozhaev

Treasury described the group’s roles as including administration and management, testing, software development and coding, procurement, finance, bookkeeping, human resources, and internal utilities. It also listed online aliases for some individuals. These are Treasury’s descriptions in the announcement, not independently established findings in this article.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What did the sanctions do?

OFAC said it designated the individuals under Executive Order 13694, as amended by Executive Order 13757. The stated basis was materially assisting, sponsoring, or providing financial, material, or technological support, goods, or services for covered cyber activity.

Treasury’s release said property and interests in property belonging to the designated individuals must be blocked and reported to OFAC if they are in the United States or in the possession or control of U.S. persons. It also summarized restrictions on dealings by U.S. persons or within the United States, including transactions that pass through the country, involving property or interests in property of blocked or designated persons. The release warned that certain transactions could expose other parties to designation, and that foreign financial institutions knowingly facilitating significant transactions or services could face U.S. correspondent or payable-through account sanctions.

This is a summary of Treasury’s explanation of the 2023 action, not individualized legal advice. The announcement alone does not establish any person’s present-day status on U.S. or U.K. sanctions lists. For a current compliance decision, check the relevant official lists and guidance.

How were the sanctions different from the indictments?

OFAC’s designations were a sanctions action. Separately, the Justice Department was concurrently unsealing nine indictments concerning Trickbot malware and Conti ransomware schemes, seven of which involved people designated that day. An indictment is a criminal charge, not proof of guilt; the Treasury announcement does not report the eventual outcome of those cases.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What is Trickbot, and why did it matter to hospitals?

Treasury said Trickbot was first identified in 2016 and evolved from Dyre, an online banking trojan operated by Moscow-based individuals and used against non-Russian targets beginning in mid-2014. Treasury described Trickbot as a modular malware suite capable of supporting different malicious activity, including ransomware, and said it infected millions of computers worldwide.

Attacks on health-care providers

Treasury reported that Trickbot targeted U.S. hospitals and other health-care providers during the COVID-19 pandemic in 2020. In one cited example, ransomware deployed by the group disrupted computer networks and telephone service at three Minnesota medical facilities, leading to ambulance diversions.

Treasury also said members were associated with Russian intelligence services and that the group’s preparations in 2020 aligned with Russian state objectives. Those state-link statements are Treasury’s characterization in the release.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the 2023 announcement establishes—and what it does not

The announcement documents a U.S. designation action coordinated with the U.K. on September 7, 2023, and identifies the individuals Treasury named, the authority it cited, and its summary of the sanctions’ effects. It also records Treasury’s account of Trickbot’s history and alleged activity. It does not establish the later outcome of the indictments or confirm each named person’s current status on sanctions lists.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Source: U.S. Department of the Treasury, “United States and United Kingdom Sanction Additional Members of the Russia-Based Trickbot Cybercrime Gang,” September 7, 2023.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.