Meduza Vitaly Kovalev Linked to Trickbot Malware and Political Candidacy
Article Content
- •Vitaly Kovalev is wanted by Interpol for his role in the Trickbot hacking group.
- •Trickbot was responsible for significant ransomware attacks, including on U.S. hospitals.
- •Kovalev was briefly a candidate for Russia's State Duma elections before being removed.
Vitaly Kovalev, a 38-year-old wanted by Interpol for organizing a criminal enterprise, was placed on the New People party's candidate list for Russia's State Duma elections. He is suspected of founding the Trickbot hacking group, which has been linked to significant cyberattacks, including a ransomware attack on U.S. hospitals during the COVID-19 pandemic. Kovalev faces charges in the U.S. for conspiracy to commit bank fraud and unauthorized access to bank accounts, with nearly $1 million illegally transferred from American financial institutions. Germany's Federal Criminal Police Office claims he contributed substantially to global cyberattacks. Kovalev was removed from the candidate list before certification in July 2026. He has been an adviser to a State Duma deputy speaker since at least 2025. The Trickbot malware, which emerged in 2016, has been used to infiltrate systems and steal data, affecting various sectors.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Conti and Dyre in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…