In December 2019, the US charged the mastermind behind the infamous Dridex malware, a Russian national named Maksim Victorovich Yakubets. He is the FBI's most wanted cybercriminal, with US authorities willing to pay up to $5 million for any information that may lead to his arrest.
Igor Turashev, one of the Dridex botnet administrators, was also charged, but for a minor role in the scheme.
Evgeniy Mikhaylovich Bogachev, known as "Slavik" is a malware author who created and operated the GameOver Zeus banking trojan and adjacent botnet.
After he was charged in 2014 for the theft of over $100 million from GameOver Zeus victims, Bogachev is believed to have become a close collaborator of Russian intelligence agencies. The FBI is willing to pay up to $3 million for any information that may lead to his arrest.
The US said the hackers were responsible for developing and launching the NotPetya ransomware outbreak, the OlympicDestroyer destructive malware against the PyeongChang 2018 Winter Olympics hosts, the Macron Leaks attacks against the French government election in 2017, and the BlackEnergy and KillDisk attacks against Ukraine's power grid in 2015 and 2016.
On July 13, 2018, US authorities finally charged a group of Russian hackers for the infamous DNC hacks of 2015 and 2016, an incident during which two Russian cyber-espionage units breached and stole data from the servers of the Democratic National Committee. This information was later released online as part of a political influence campaign to support Donald Trump's candidacy for the US Presidency.
Twelve Russian military officers were charged. They are believed to be part of either the APT28 (Fancy Bear) or APT29 (Cozy Bear) cyber-espionage groups.
Back in March 2017, the US Department of Justice charged four hackers with breaching Yahoo in 2014 and stealing data on 500 million users.
One, named Karim Baratov, was arrested in Canada, and extradited to the US, where he eventually received a sentence of five years in prison.
The other three, including two officers of FSB intelligence officers, are still at large, believed to reside in Russia. Their names are Alexsey Belan, Dmitriy Aleksandrovich Dokuchayev, and Igor Suchin.
In February 2019, the US charged four Iranian nationals for conspiring with a former US Air Force intelligence agent who defected to Iran in 2013. The group used intelligence provided by the US Air Force agent to launch phishing attacks over email and social media.
One of the four hackers, Behzad Mesri, had been previously charged in November 2017 with hacking HBO and leaking unreleased episodes and scripts for HBO TV series, including from HBO's primetime show Game of Thrones.
Believed to be a member of a Chinese cyber-espionage unit, Wang is still at large in China. He was formally charged earlier this month.
In September 2020, the US Department of Justice charged five hackers believed to be part of APT41, one of China's most active state-sponsored hacking crew.
According to charges, US officials said the group breached more than 100 companies across the world, along with two government networks. Their attacks focused on intelligence gathering, but the group also engaged in financially-motivated attacks during their personal time, attacking video game companies and stealing in-game currency, ransomware attacks, and running crypto-mining botnets.
In September 2018, US authorities charged Park Jin Hyok, a 34-year-old North Korean, with a litany of charges based on his membership in the Lazarus Group, a North Korean government-backed hacking unit.
He stands accused of participating in the WannaCry ransomware outbreak, the 2016 Bangladesh Central Bank cyber-heist, attempts at hacking US defense contractor Lockheed Martin in 2016, the 2014 Sony Pictures hack, breaches at US movie theatre chains AMC Theatres and Mammoth Screen in 2014, and a long string of attacks and successful hacks against cryptocurrency exchanges.
Since their indictment, the source code of the Zeus trojan was leaked online, and has become the inspiration and codebase for tens of other banking trojan strains.
The group was also known as Cobalt Dickens or Silent Librarian in the reports of various cybersecurity firms, and continued its hacking activities despite US charges.
Another group of hackers on the payroll of a foreign government is the duo of Zhu Hua and Zhang Shilong. Believed to be part of a Chinese cyber-espionage group known as APT10, they were charged in December 2018 with hacking more than 45 US companies, US government agencies, and several managed service providers. Victims include IBM, HPE, and Visma.
Another team of Iranian hackers is the one formed by 34-year old Faramarz Shahi Savandi and 27-year old Mohammad Mehdi Shah Mansouri -- collectively known as the operators of the SamSam ransomware.
Charged in November 2018, they are responsible for one of the most prolific ransomware strains around, which they used for attacks targeted at one organization at a time, a tactic they pioneered back in 2015, and which is now the most prevalent and successful type of ransomware attack today, also known as "big game hunting."
In October 2018, US authorities charged seven Russian nationals believed to be members of the GRU military intelligence agency. US officials said the group engaged in a retaliatory action against several sports organizations after Russian athletes were banned from the Rio 2016 Summer Olympics on allegations of doping.
The seven, acting under the fake personas of Anonymous and the Fancy Bears hacking groups, breached the World Anti-Doping Agency (WADA), the United States Anti-Doping Agency (USADA), and other victim entities during the 2016 Summer Olympics and Paralympics and afterwards, stealing and then dumping sensitive records online as part of efforts to discredit the world's most famous athletes and anti-doping organizations.
In early 2016, the US charged seven Iranian hackers for launching a series of coordinated DDoS attacks against US companies in the banking and financial sector. One of these attacks also hit a New York dam, putting US authorities on alert.
The DDoS attacks were retaliation from Iranian authorities after the Stuxnet attacks orchestrated by the US and Israel against Iran's nuclear program.
According to the indictment, the two hacked ArrowTech in 2016, from which they stole a software application named Projectile Rocket Ordnance Design and Analysis System (PRODAS), used in the design of bullets, missiles, and other military projectiles.