U.S. authorities charged Latvian national Alla Witte, also known as "Max", for allegedly serving as a malware developer for the Trickbot cybercrime group, accusing her of writing source code used to control the malware, deploy ransomware, track authorized users, manage victim payments, and store stolen credentials. Prosecutors said Trickbot began operating by late 2015, infected millions of computers worldwide, stole banking and personal information, and was used against businesses, hospitals, schools, utilities, and government entities. Witte was arrested in Miami and arraigned in federal court in Ohio on 19 counts from a broader 47-count indictment tied to the gang.
The case formed part of a wider campaign against the Russia-linked operation and its support network. The United States and United Kingdom later imposed joint sanctions on seven alleged Trickbot members, describing the malware as a banking trojan that evolved into a modular platform for financial theft and ransomware, including attacks on healthcare providers. U.S. officials also linked Trickbot to money-laundering services provided by QQAAZZ, a criminal organization accused of washing tens of millions of dollars for actors tied to Trickbot, Dridex, and GozNym, underscoring how law enforcement pursued both the malware developers and the financial infrastructure behind the group.

See the reporting duties and controls this puts on the clock.
14 events from the most recent confirmed update back to the earliest known activity.
Treasury disclosed that a U.S. indictment unsealed in the District of New Jersey charged alleged senior Trickbot figure Vitaly Kovalev with conspiracy to commit bank fraud and eight counts of bank fraud. The charges related to intrusions into U.S.-based bank accounts in 2009 and 2010.
The United States and the United Kingdom jointly imposed sanctions on seven individuals associated with the Russia-based Trickbot gang. Treasury said the action aimed to disrupt Russian cybercrime and ransomware activity and described it as the U.K.'s first sanctions of this kind related to cyber activity.
The U.S. Department of Justice announced the federal arraignment of Alla Witte in Cleveland, Ohio, on 19 counts from a 47-count indictment tied to the Trickbot operation. The indictment alleged she wrote code for ransomware deployment, payment functions, user tracking, and storage of stolen credentials.
U.S. authorities arrested alleged Trickbot developer Alla Witte in Miami, Florida. Prosecutors said she used the alias "Max" and was later identified as the first Trickbot member arrested.
The Justice Department announced an international operation targeting QQAAZZ and unsealed an indictment charging 14 additional members, bringing the total charged defendants to 20. The action included more than 40 house searches across several European countries and parallel prosecutions in the United States, Portugal, Spain, and the United Kingdom.
In October 2020, a coalition of technology companies attempted to take down the Trickbot botnet. The operation disrupted Trickbot for a few weeks before the botnet recovered.
Russian national Maksim Boiko was arrested by criminal complaint in late March 2020 while visiting the United States. He was identified as an additional conspirator tied to QQAAZZ.
During 2020, Trickbot targeted hospitals and healthcare centers, including three Minnesota medical facilities. The ransomware attack disrupted networks and telephones and caused ambulances to be diverted.
A related U.S. indictment unsealed in October 2019 charged five QQAAZZ members. The defendants in that earlier case were identified as being from Latvia.
Around 2017, Trickbot shifted from a banking trojan into a loader or dropper used to install other malware. It then supported a broader crimeware-as-a-service operation and ransomware delivery.
Treasury said security researchers first identified Trickbot in 2016. The malware later evolved into a modular suite used for financial theft and ransomware activity.
According to the indictment, QQAAZZ laundered or attempted to launder tens of millions of dollars in stolen funds beginning in 2016. The group allegedly serviced cybercriminals tied to malware families including Trickbot.
U.S. authorities said Trickbot began no later than November 2015 after remnants of the Dyre malware gang assembled to distribute a revamped version of the Dyre trojan. Prosecutors alleged Alla Witte had worked with the group from its formation.
The Dyre banking trojan, operated by individuals based in Moscow, began targeting non-Russian businesses and entities in mid-2014. Treasury later described Trickbot as having evolved from Dyre.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
home.treasury.gov
Open sourcejustice.gov
Open sourcetherecord.media
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.