Full Report
Mikhail Matveev, aka WazaWaka, had worked with several ransomware groups, including Babuk, Conti, Darkside, Hive and LockBit
Analysis Summary
# Threat Actor: Mikhail Pavolvich Matveev (WazaWaka)
## Attribution & Identity
**Identified Actor:** Mikhail Pavolvich Matveev.
**Attribution:** Arrested in Kaliningrad, Russia, on charges related to malware creation.
**Known Aliases:** WazaWaka, Uhodiransomwar, m1x, Boriselcin.
**Associated Groups:** Linked as an affiliate to major ransomware gangs including Babuk, Conti, Darkside, Hive, and LockBit.
## Activity Summary
The actor was arrested in November 2024 following charges related to creating novel ransomware developed in January 2024. Matveev was previously identified by security journalist Brian Krebs in January 2022. In May 2023, the US Justice Department charged him with a series of ransomware attacks. The US State Department offered a $10 million reward for information leading to his arrest/conviction.
## Tactics, Techniques & Procedures
- Development of novel ransomware strain (active as of January 2024).
- Conspiring to transmit ransom demands.
- Conspiring to damage protected computers.
- Intentionally damaging protected computers.
- **Affiliation/Collaboration:** Functioned as an affiliate for established ransomware operations (Babuk, Conti, Darkside, Hive, LockBit).
- *(No specific TTPs or MITRE ATT&CK IDs were detailed beyond the criminal charges related to ransomware operation itself.)*
## Targeting
**Sectors:**
- Law enforcement agencies.
- Non-profit behavioral healthcare organizations.
- General government/public sector (Metropolitan Police Department).
**Geography:**
- Attacks mentioned were across the US, including New Jersey and Washington DC.
**Victims:**
- A law enforcement agency in New Jersey.
- A non-profit behavioral healthcare organization in New Jersey.
- Washington DC Metropolitan Police Department.
## Tools & Infrastructure
- **Malware families used:** Novel, custom-developed ransomware (developed in January 2024).
- **Infrastructure (C2, domains, IPs):** Not explicitly detailed in the provided text.
## Implications
The arrest of a prolific actor associated with multiple high-profile ransomware operations (Conti, Hive, LockBit) signifies a significant disruption to the affiliate ecosystem. His development of a "novel" ransomware strain indicates ongoing capability development within the broader threat landscape, even if his operation has now been halted by Russian authorities. The involvement of the US DOJ and a high-value reward highlights the strategic priority placed on apprehending such figures.
## Mitigations
- Enhance threat intelligence gathering on ransomware affiliates known to work with major groups like LockBit and Hive.
- Review and harden security posture for public sector entities and healthcare organizations, given their documented targeting history.
- Implement robust forensic and defensive measures against emerging ransomware strains, particularly those developed internally by threat actors.