The U.S. Department of Justice unsealed indictments against Russian national Mikhail Pavlovich Matveev, also known as "Wazawaka" and "Boriselcin," alleging he participated in multiple ransomware conspiracies tied to the Babuk, Hive, and LockBit operations. Prosecutors said Matveev was involved in attacks affecting a Passaic County, New Jersey law enforcement agency, a Mercer County, New Jersey behavioral healthcare nonprofit, and the Metropolitan Police Department in Washington, D.C., and that he was associated with cybercrime forum personas used in ransomware activity and data-leak extortion.
U.S. authorities also moved to increase pressure beyond the criminal charges. The Treasury Department sanctioned Matveev, while the State Department announced a reward of up to $10 million for information leading to his capture or conviction, underscoring Washington's effort to disrupt prominent ransomware operators accused of helping deploy malware, steal data, and publish victim information when extortion demands were not met.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
Prosecutors allege that Matveev conspired with the Hive ransomware group to attack a nonprofit behavioral healthcare organization headquartered in Mercer County, New Jersey. This alleged intrusion is another incident cited in the indictments.
After the January 2022 reporting, a man resembling Matveev in social media photos posted selfie videos on Twitter attacking security journalists and researchers. The same account also posted exploit code for a widely used VPN appliance.
KrebsOnSecurity reported that clues from pseudonyms and contact details linked the ransomware actor Wazawaka to Mikhail Matveev of Abaza, Russia. The article says this identification was published in January 2022.
Prosecutors allege that Matveev and the Babuk gang deployed ransomware against the Metropolitan Police Department in Washington, D.C. The incident is one of the attacks named in the U.S. case against him.
In a January 2021 discussion on a Russian cybercrime forum, Matveev's alleged persona Wazawaka said he had no plans to leave Russia. The statement was cited as relevant to the likelihood of his capture while in Russia.
According to U.S. prosecutors, Mikhail Matveev and LockBit co-conspirators deployed LockBit ransomware against a law enforcement agency in Passaic County, New Jersey. The alleged attack is one of the incidents cited in the later indictments.
The article states that Babuk surfaced on New Year's Eve 2020. This provides context for Matveev's alleged later association with the Babuk affiliate program.
The U.S. Department of the Treasury added Matveev to its sanctions list, barring U.S. persons from financial transactions with him. The U.S. State Department also offered up to $10 million for information leading to his capture or prosecution.
The U.S. Department of Justice unsealed two indictments against Russian national Mikhail Pavlovich Matveev, also known as Wazawaka and Boriselcin, over alleged roles in Babuk, Hive, and LockBit ransomware conspiracies. The indictments were returned in New Jersey and the District of Columbia.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.