Natto Thoughts

Natto Thoughts

Wazawaka & Co., Part 2: Patriotic Hacker

The patriotic rhetoric, targeting and timing of attacks, and occasionally unprofitable operations of Mikhail Matveev's Babuk ransomware group align with Russian state strategic interests

Natto Team's avatar
Natto Team
Feb 22, 2024
∙ Paid

In a previous posting, we discussed a report by cybersecurity company Prodaft that explores the place of Mikhail Matveev, a.k.a. Wazawaka, in the stormy Russian-speaking cybercrime ecosystem. As summarized in the Prodaft report, at various times Matveev operated and managed the Babuk and Monti ransomware operations, collaborated with actors from the RagnarLocker group, and worked as an affiliate of the Lockbit, Conti, Hive, NoEscape and Trigona groups.

Politics was not the focus of Prodaft’s analysis, but their report acknowledged that Wazawaka associated with “government-affiliated individuals” such as Conti actors, Yevgeniy Bogachev, and possibly the EvilCorp group. In addition, the material they presented gave glimpses into the political side of Matveev, such as rumors that he could be a police stooge. As the Natto Team commented there, the fact that Matveev continues to flaunt his exploits publicly, apparently confident that nobody will turn him in and claim the $10 million price…

User's avatar

Continue reading this post for free, courtesy of Natto Team.

Or purchase a paid subscription.
© 2026 Natto Thoughts · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture