Russian national Vladimir Dunaev pleaded guilty in U.S. federal court for helping develop and deploy TrickBot, a malware platform used to steal credentials, harvest data, evade security tools, and enable ransomware attacks against hospitals, schools, businesses, and other victims. Prosecutors said TrickBot infected millions of computers, caused tens of millions of dollars in losses in the United States, and stole more than $180 million worldwide. Dunaev was arrested in South Korea on a U.S. extradition request, transferred to the United States in 2021, and now faces up to 35 years in prison; his plea follows earlier action against alleged TrickBot developer Alla Witte and sanctions targeting other members the U.S. linked to Russian intelligence services.
The guilty plea comes amid a broader U.S. crackdown on the TrickBot-Conti ecosystem, with federal indictments accusing multiple Russian nationals of developing, operating, and profiting from malware and ransomware campaigns tied to Conti, Ryuk, Anchor, BazaLoader, and related tooling. Court filings and security research describe TrickBot as both an initial-access and post-compromise framework: spam campaigns delivered obfuscated loaders, operators used browser manipulation and antivirus-evasion techniques, and intrusions progressed through credential dumping, domain enumeration, lateral movement, and Cobalt Strike activity before ransomware deployment. One indictment specifically tied alleged member Maksim Galochkin to the 2021 Conti attack on Scripps Health, while separate research has examined internal TrickBot roles and disputed attribution of the handle bentley among senior operators.

See the reporting duties and controls this puts on the clock.
17 events from the most recent confirmed update back to the earliest known activity.
In September, the United States and the United Kingdom imposed financial sanctions on 18 alleged TrickBot members, freezing assets and imposing travel bans while citing ties between the group and Russian intelligence services.
Alla Witte, a TrickBot developer previously indicted by U.S. authorities, pleaded guilty and was sentenced to 32 months in prison in June 2023.
In February 2023, the U.S. Treasury Department and U.S. Secret Service identified Vitaly Kovalev as the ransomware actor using the handle “bentley,” based on activity from 2009 and 2010.
A Twitter account named @trickleaks released alleged TrickBot chat logs and actor dossiers, including a dossier on the actor using the handle “bentley.”
The Justice Department said Trickbot was taken down in 2022 after years of infecting millions of computers and facilitating theft and ransomware deployment.
A later Southern District of California indictment alleges that Maksim Galochkin was involved in the May 1, 2021 Conti ransomware attack on Scripps Health, which impaired medical examination, diagnosis, treatment, and care.
Vladimir Dunaev was extradited from South Korea to the United States in 2021 to face charges related to his alleged role in developing and deploying Trickbot.
In October 2020, U.S. Cyber Command, Microsoft, and numerous security companies attempted to disrupt TrickBot infrastructure, but the interruption was limited and the gang rebuilt its systems.
SentinelLabs observed TrickBot-linked Cobalt Strike server activity across roughly three sessions from 2019-10-07 to 2019-10-09, showing operators enumerating networks, dumping credentials, pivoting laterally, and preparing Ryuk deployment.
A BleepingComputer report says the arrested Russian suspect allegedly worked as a web browser developer for the TrickBot operation while living in Russia in 2016.
According to a Northern District of Ohio indictment later unsealed by the U.S. Department of Justice, defendants allegedly began conspiring in November 2015 to use Trickbot to steal money and personal and confidential information from victims in the United States and worldwide.
Vladimir Dunaev pleaded guilty in U.S. federal court in Cleveland to charges tied to developing and deploying Trickbot, including creating browser modifications and tools for credential theft, data mining, remote access, and security evasion.
The U.S. Department of Justice unsealed three federal indictments charging multiple Russian nationals for alleged roles in the Trickbot malware operation and Conti ransomware conspiracies across Ohio, Tennessee, and California.
Nisos published research arguing that the TrickBot-associated handle “bentley” was likely used by Maksim Sergeevich Galochkin, while leaving open the possibility that both Galochkin and Vitaly Kovalev used the alias at different times.
A Russian man alleged to be a TrickBot developer was arrested in South Korea after attempting to leave the country while subject to a U.S. extradition request.
Researchers identified two TrickBot samples embedding text from Trump impeachment news articles in an apparent attempt to evade static or machine-learning-based antivirus detection.
Trend Micro reported a Trickbot campaign delivered through spam emails with malicious Word documents that hid obfuscated JavaScript, established persistence, and downloaded a Trickbot variant that stole credentials and browser data.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See what this changes for your reporting obligations and which controls it puts on the clock.
7 references tracked. Mallory keeps watching after this page renders.
labs.sentinelone.com
Open sourcetherecord.media
Open sourcejustice.gov
Open sourcenisos.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourceblog.trendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.