CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Sentencing of TA551 Botnet Operator for Ransomware Access Facilitation

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A Russian national, Ilya Angelov, was sentenced to two years imprisonment and fined $100,000 for co-managing the TA551 botnet used to facilitate ransomware attacks against U.S. enterprises. Between 2017 and 2021, Angelov and associates operated the botnet via spam email malware distribution, monetizing access by selling compromised systems to criminal groups including BitPaymer, IcedID operators, TrickBot affiliates, and Lockean ransomware gangs. The group’s activities directly enabled ransomware extortion campaigns impacting 72 U.S. corporations with over $14.17 million in proceeds.

Timeline

  1. 25.03.2026 13:52 1 articles · 2h ago

    TA551 Botnet Operator Sentenced for Facilitating Ransomware Attacks via Access Brokering

    U.S. federal sentencing documents reveal Ilya Angelov’s management of the TA551 botnet from 2017 to 2021, which distributed malware via spam emails and sold access to ransomware groups. Proceeds from the botnet’s activities exceeded $14.17 million, with documented links to BitPaymer, IcedID, TrickBot/Conti, and Lockean ransomware campaigns. The development underscores the persistent use of botnet-for-hire models to enable large-scale ransomware extortion.

    Show sources

Information Snippets