The Russia-linked Evil Corp cybercrime group repeatedly renamed and modified its ransomware after U.S. Treasury sanctions tied to its Dridex operations complicated ransom payments. Researchers and incident reporting linked a progression from BitPaymer/FriedEx and WastedLocker to Hades, Phoenix Locker, PayloadBIN, and Macaw Locker, with analysts citing shared code, tooling, and tradecraft across the families. Security firms said the group also adjusted its operations by leaning on tools such as SocGholish, Cobalt Strike, and the CryptOne packer to blur attribution while continuing enterprise-focused intrusions.
The rebrands were tied to major disruptive attacks on large organizations. Garmin suffered a global outage in a confirmed WastedLocker incident, Forward Air disclosed operational disruption from Hades, and later Olympus and Sinclair Broadcast Group were linked to Macaw Locker, with Sinclair experiencing broadcast interruptions. Reporting said victims were directed to Tor-based negotiation portals and, in some cases, faced demands as high as 450 bitcoin or $40 million, underscoring how Evil Corp preserved its extortion business despite sanctions pressure.

TTPs, infrastructure, and targeting history in one profile.
23 events from the most recent confirmed update back to the earliest known activity.
SentinelLabs assessed with high confidence that WastedLocker, Hades, Phoenix Locker, PayloadBIN, and Macaw Locker all belonged to the same Evil Corp-linked cluster, with BitPaymer likely evolutionarily linked as well.
BleepingComputer reported that code analysis tied the new Macaw Locker ransomware to Evil Corp, identifying it as the latest rebrand in the group's ransomware family and linking it to the Olympus and Sinclair attacks.
SentinelLabs said Macaw Locker appeared in the wild in an attack against Olympus that began on October 10, 2021.
A few days after the Olympus incident, Sinclair Broadcast Group was also attacked by Macaw Locker, causing widespread broadcast disruption.
Fortinet documented a new Dridex variant spread through phishing emails with malicious Excel .xlsb attachments that used VBA and Excel 4.0 macros to install the malware.
Fabian Wosar and Michael Gillespie analyzed PayloadBIN and concluded it was another Evil Corp rebrand rather than a Babuk successor.
A Cypherpunk ransomware variant reported in June 2021 was analyzed by SentinelLabs and linked to the same lineage as PayloadBIN.
At the end of May 2021, the Babuk leak site was redesigned and rebranded as a new group called Payload Bin.
CrowdStrike linked Hades ransomware to Evil Corp, describing it as a 64-bit WastedLocker variant used to evade U.S. sanctions and continue monetizing attacks.
SentinelLabs reported that Phoenix Locker appeared in the wild in March 2021 and assessed it was a rebranded version of Hades.
Forward Air detected an IT security incident on December 15, 2020, took systems offline, notified law enforcement, and began an investigation after ransomware disrupted operations.
Sources told BleepingComputer that the ransomware attack on Forward Air was conducted by a newly emerged operation known as Hades.
SentinelLabs reported that Hades ransomware was first observed in the wild in December 2020.
Garmin experienced a worldwide outage that sources and internal evidence tied to a WastedLocker ransomware attack, disrupting online services, call centers, and aviation-related functions.
CrowdStrike said Evil Corp started deploying WastedLocker in June 2020 to circumvent sanctions-related payment barriers.
SentinelLabs said WastedLocker appeared in the wild in May 2020, marking the start of this ransomware family's observed activity.
Multiple sources state that Evil Corp introduced the WastedLocker ransomware in 2020 as a new project following BitPaymer.
The U.S. Treasury Department sanctioned Evil Corp and related individuals and entities over its Dridex operations, which officials said caused more than $100 million in losses.
ESET assessed that the developers behind the Dridex banking trojan also created FriedEx/BitPaymer, citing extensive code overlap and shared build artifacts.
FriedEx/BitPaymer infections impacted NHS hospitals in Scotland in August 2017.
Michael Gillespie discovered the FriedEx ransomware family, also known as BitPaymer, in early July 2017.
ESET reported that Dridex first appeared in 2014 as a banking trojan and later evolved into a more sophisticated malware platform.
BleepingComputer found a new ransomware sample named PayloadBIN on a Thursday and initially suspected it was connected to Babuk's Payload Bin rebrand.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 31 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
13 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourcesecureworks.com
Open sourcesentinelone.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourcehome.treasury.gov
Open sourcewelivesecurity.com
Open sourcecrowdstrike.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.