The Trickbot group, operating since at least 2016, evolved into a massive "Cybercrime-as-a-Service" (CaaS) operation consisting of more than 100 structured members. While the public often focuses on the ransomware strains that freeze data (like Ryuk and Conti), Kovalskii worked in the highly technical engine room of the organization.
Law enforcement agencies state that Kovalskii is suspected of membership in a foreign criminal organization. Authorities believe he resides within the Russian Federation, shielding him from direct extradition to Western nations. The Alleged Role: Inside the "Trickbot" Ecosystem aleksei valerevich kovalskii updated
The update to his OpenSanctions Profile and the active dissemination of his Interpol Red Notice ensure that any cross-border movement, flight path, or financial footprint registered outside domestic safe havens will trigger immediate arrest and subsequent extradition procedures. Law enforcement continues to update his profile dynamically as ongoing forensic evaluation of seized Trickbot servers yields new indicators of compromise (IoCs), crypto-wallets, and chat logs tied to "neo". Share public link The Trickbot group, operating since at least 2016,