Egor Igorevich Kriuchkov
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Egor Igorevich Kriuchkov, also known as Egor Kriuchkov, is a Russian national who became known to authorities in July 2020 for an extortion plot targeting a major American automotive manufacturer. On approximately July 15 2020, he approached an employee at Tesla’s Nevada Gigafactory with an offer to deploy malicious software inside the company’s network. The recruit was promised a payment of one million dollars after successfully installing the malware and assisting in its development. Kriuchkov intended to use any data obtained through the malware as leverage to demand a ransom from Tesla while threatening to leak the information publicly. The scheme also incorporated a distributed denial‑of‑service attack designed to create a distraction during the malware implantation phase.
The targeting was confined to the technology and automotive sector, specifically the Tesla facility located in Nevada, United States. His strategic objective was financial extortion, supplemented by a disruptive component meant to conceal the intrusion. The operation relied on social engineering of an insider as the primary initial access method, with the malware to be delivered either via a USB drive or a malicious email. No specific malware family is named in the reporting, but the plan included the development of custom software tailored for execution on Tesla’s systems. The planned DDoS service would serve as a tool to divert defensive attention, indicating a tooling style that combines insider recruitment with basic network‑level disruption capabilities.
Publicly available sources do not associate Kriuchkov with any state‑sponsored program or larger criminal consortium; he is described solely as an individual actor. The Tesla extortion attempt is the only notable campaign that has been publicly reported for this individual. He was arrested in Los Angeles on August 22 2020 while attempting to flee the United States after arranging an airline ticket. Following his arrest, Kriuchkov was charged with conspiracy to damage a protected computer and faced a potential sentence of up to five years in prison. Law‑enforcement intervention prevented the malware from being deployed, and the case highlighted the risk of insider‑threat recruitment for financial extortion.
Incidents
Attributed incidents are available to members.
1 incident