Regulation

German Police Name Russian Cybercriminal Behind Trickbot Empire

Law enforcement in Germany has publicly identified the leader of the Trickbot ransomware cartel, ending years of mystery surrounding the figure known as "Stern." The suspect, identified as Vitaly Nikolaevich Kovalev, allegedly orchestrated one of the world's most damaging cybercriminal operations.

6 min read
Ransomware kingpin “Stern” apparently IDed by German law enforcement

Over the course of approximately six years, a Russian cybercriminal organization centered around the Trickbot malware conducted systematic attacks against thousands of targets worldwide. The group's victims included educational institutions, healthcare facilities, and commercial enterprises. In 2020, one member documented plans to assault American medical centers, referencing a specific roster of 428 hospitals. The operation, comprising roughly 100 individuals, was led by someone operating under the pseudonym "Stern," and the organization accumulated hundreds of millions of dollars through criminal activity.

The identity of Stern remained concealed despite significant setbacks to the organization, including law enforcement actions and the disclosure of over 60,000 private communications between Trickbot and Conti, a closely aligned criminal group. However, Germany's federal criminal police authority, the Bundeskriminalamt (BKA), along with local judicial authorities, recently made a public assertion regarding Stern's actual identity. According to their announcement, Stern is Vitaly Nikolaevich Kovalev, a 36-year-old Russian national standing 5 feet 11 inches tall, whom authorities believe remains in Russia and therefore beyond extradition reach.

An Interpol red notice issued in connection with the case designates Kovalev as a fugitive sought by Germany on charges of leading a "criminal organisation."

Stern's naming is a significant event that bridges gaps in our understanding of Trickbot—one of the most notorious transnational cybercriminal groups to ever exist. As Trickbot's 'big boss' and one of the most noteworthy figures in the Russian cybercriminal underground, Stern remained an elusive character, and his real name was taboo for years.

Alexander Leslie, threat intelligence analyst at Recorded Future

Stern's name had conspicuously been absent from multiple rounds of sanctions and criminal charges issued by Western governments against alleged members of Trickbot and Conti in recent years. Analysts and researchers had previously theorized to WIRED that law enforcement agencies might have deliberately withheld details about Stern's identity to support ongoing investigative work. The BKA characterized Kovalev as the "founder" of Trickbot and stated he employed the Stern moniker.

It has long been assumed, based on numerous indications, that 'Stern' is in fact Kovalev. The investigating authorities involved in Operation Endgame were only able to identify the actor Stern as Kovalev during their investigation this year.

BKA spokesperson

The BKA indicated that investigative work conducted in 2023 targeting the Qakbot malware, combined with examination of the previously leaked communications from Trickbot and Conti dating to 2022, proved instrumental in establishing the connection. The agency also noted that "the assessment is also shared by international partners."

The German law enforcement announcement represents the first instance of any government agency formally naming a person in connection with the Stern persona. Operation Endgame, the multinational law enforcement initiative under which BKA made its attribution, involved coordination across multiple countries. However, unlike prior attributions related to Trickbot and Conti members, other nations have not yet publicly endorsed the BKA's identification of Kovalev as Stern. Europol, the United States Department of Justice, the United States Treasury, and the United Kingdom's Foreign, Commonwealth & Development Office did not provide immediate responses to inquiries from WIRED.

Multiple cybersecurity researchers with extensive experience tracking Trickbot stated they had not been aware of the BKA's announcement. An unidentified account on the social platform X recently asserted that Kovalev used the Stern handle and shared purported information about him. WIRED attempted to contact multiple accounts believed to belong to Kovalev based on information from the X account and records from District 4 Labs' database of compromised and released information, but received no replies.

Kovalev's identity and appearance may already be recognizable to those monitoring recent developments in the Trickbot investigation. In early 2023, the United States and United Kingdom jointly imposed sanctions on Kovalev for his role as a senior operative within Trickbot. During the same period, the United States brought charges against him related to hacking activities connected to bank fraud dating to 2010, and he was placed on the nation's most-wanted list. In these earlier actions, authorities connected Kovalev to the online identifiers "ben" and "Bentley." The 2023 sanctions documentation made no reference to any association with the Stern handle. Notably, Kovalev's 2023 indictment drew attention primarily because his use of "Bentley" was established as "historic" and separate from that of another prominent Trickbot operative who also employed the "Bentley" identifier.

The Trickbot ransomware operation emerged circa 2016, following a transition by its members from the Dyre malware platform, which had been shut down by Russian law enforcement authorities. Throughout its operational period, Trickbot employed its signature malware alongside other ransomware tools including Ryuk, IcedID, and Diavol. The group's activities increasingly converged with those of Conti, including shared personnel and coordinated operations. In early 2022, Conti released a statement endorsing Russia's military action in Ukraine. Subsequently, a cybersecurity researcher who had gained access to the organizations' internal systems released more than 60,000 messages from both groups, exposing extensive details about their operational procedures and organizational structure.

According to analysis of the disclosed communications by WIRED and security researchers, Stern conducted himself in the manner of a "CEO," administering both Trickbot and Conti according to corporate business principles.

Trickbot set the mold for the modern 'as-a-service' cybercriminal business model that was adopted by countless groups that followed. While there were certainly organized groups that preceded Trickbot, Stern oversaw a period of Russian cybercrime that was characterized by a high level of professionalization. This trend continues today, is reproduced worldwide, and is visible in most active groups on the dark web.

Alexander Leslie, Recorded Future

Stern's prominence within the Russian cybercriminal ecosystem has been extensively noted in security research. Chainalysis, a firm specializing in cryptocurrency tracking, does not publicly identify cybercriminal actors and declined to comment on the BKA's attribution, though it underscored that the Stern persona ranks among the most financially successful ransomware operators in its records.

The investigation revealed that Stern generated significant revenues from illegal activities, in particular in connection with ransomware.

BKA spokesperson

Stern surrounds himself with very technical people, many of which he claims to have sometimes decades of experience, and he's willing to delegate substantial tasks to these experienced people whom he trusts. I think he's always probably lived in that organizational role.

Keith Jarvis, senior security researcher at Sophos' Counter Threat Unit

Accumulating evidence has suggested that Stern maintains at least informal ties to Russia's state security establishment, particularly the Federal Security Service (FSB). In July 2020, the Stern account referenced establishing a division dedicated to "government topics." Other Trickbot members have been observed suggesting that Stern likely serves as the "link between us and the ranks/head of department type at FSB."

Stern's sustained operational presence significantly enhanced the effectiveness of both Trickbot and Conti, as did the organizations' capacity to maintain rigorous operational security protocols and evade detection.

I have no thoughts on the attribution, as I've never heard a compelling story about Stern's identity from anyone prior to this announcement.

Keith Jarvis, Sophos

Source: Ars Technica · Reporting supplemented by The Silicon Ledger staff.