CSIDB logo
Threat actor

Evaldas Rimasauskas

Attribution profile

Type
Criminal
Location
Lithuania
Known incidents
2 incidents
First seen
2013-01-01
Last seen
2013-01-01
Updated
2026-07-31 19:35
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Evaldas Rimasauskas is the primary alias used for the Lithuanian individual who has been publicly identified in connection with a large‑scale fraud scheme targeting major United States technology firms. He is described as a Lithuanian national, with his place of residence or activity noted as Lithuania in open‑source reporting. The actor came to public attention after law‑enforcement charges were filed in the United States District Court for the Southern District of New York. Public sources refer to him solely by this name, without additional aliases or nicknames. His identity is tied to the criminal complaint that alleges he posed as an Asian‑based manufacturer to deceive corporate employees.

The scheme primarily targeted the technology sector, specifically two large US‑based internet companies that operate social media and search platforms, as indicated by the victim identification in the Department of Justice announcement. The strategic objective was financial gain, as the actor attempted to divert more than one hundred million dollars through fraudulent invoices and payment requests. No public source attributes espionage, disruption, or ideological motives to the activity. The initial access vector consisted of spear‑phishing emails that impersonated employees of the purported Asian supplier, using spoofed email addresses to appear legitimate. Following initial contact, the actor employed forged invoices, contracts and letters that falsely bore the signatures of company executives, a technique often described as CEO fraud or business‑email compromise. No malware families or custom tooling are mentioned in the available sources; the operation relied on social engineering and document forgery rather than technical exploits.

Attribution to any state sponsor or criminal consortium has not been established in the publicly available material; the actor is presented as an individual acting alone or with unspecified accomplices. The most significant publicly reported operation is the multi‑year fraud against Facebook and Google that unfolded from at least 2013 until 2015, resulting in the alleged loss of over one hundred million dollars. Both companies reported that they detected the fraud, notified authorities, and recovered the majority of the transferred funds, which contributed to the subsequent arrest and prosecution of the individual. The case is frequently cited as an illustration of how business‑email compromise schemes can exploit internal verification processes during periods of corporate change. This profile summarizes the facts that are directly supported by the provided sources.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB