Russian national Mikhail Pavlovich Matveev, also known as Wazawaka and Boriselcin, remains on the FBI’s cyber most-wanted list over allegations that he acted as a prolific ransomware affiliate linked to Hive, LockBit, and Babuk. U.S. authorities have accused Matveev and his accomplices of participating in global ransomware operations that generated roughly $200 million in demands, and have tied him to high-profile incidents including the ransomware attack on the Metropolitan Police Department in Washington, D.C. The United States has also sanctioned him for his alleged role in those campaigns.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
Earlier in 2023, the U.S. government accused Matveev of participating in a global ransomware campaign targeting corporations and critical infrastructure, including hospitals and government agencies. Prosecutors described him as a prolific affiliate tied to Hive, LockBit, and Babuk, and alleged involvement in the ransomware attack on Washington, D.C.'s Metropolitan Police Department.
Matveev said he lost a finger in 2017 while installing a 35 kg server cabinet and later underwent surgery. The detail was noted as part of the publication's identity verification against the FBI wanted page.
In the interview, Mikhail Matveev said his last trip outside Russia was to Thailand in 2014. He cited no later foreign travel before saying he eventually stopped traveling abroad.
In the TechCrunch interview, Matveev denied being formally affiliated with ransomware gangs and said he only rented ransomware software while operating independently. He also disputed the FBI's attribution of $200 million in ransomware proceeds and said he was no longer interested in ransomware, though he admitted he missed hacking.
After his indictment and sanctions, Matveev remained active on X and publicly mocked the U.S. actions against him by printing a T-shirt featuring his FBI most wanted poster. The act was described as part of his public response to the case.
Matveev said he no longer travels outside Russia and burned his passport to avoid being caught abroad. He said this followed the U.S. indictment and sanctions against him.
The United States placed Matveev on a sanctions list in connection with the alleged ransomware activity. In the interview, Matveev said the sanctions had not materially harmed him and claimed they improved his security because Russia would not deport him.
The FBI placed Mikhail Pavlovich Matveev on its wanted list and offered up to $10 million for information leading to his arrest and/or conviction. The TechCrunch report states he is wanted by the FBI in connection with the U.S. allegations.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.