A Russian man wanted internationally over his alleged role in a major cybercrime operation worked as an adviser to Vladislav Davankov, a deputy speaker of Russia’s State Duma and leader of the New People party, Russian independent media ASTRA reported on Thursday.
Vitaly Kovalev, who used the aliases “Stern” and “Ben,” was also included on the New People party’s federal candidate list for Russia’s 2026 State Duma elections before being removed, according to Novaya Gazeta Europe and The Moscow Times.
JOIN US ON TELEGRAM
Follow our coverage of the war on the @Kyivpost_official.
Davankov himself has previously mentioned Kovalev in his Telegram channel, describing him as an adviser and investor in medical technology.
Wanted over TrickBot
Germany’s Federal Criminal Police Office (BKA), has been seeking Kovalev over allegations that he founded and led the group behind the TrickBot malware.
The BKA says Kovalev, is suspected of founding the TrickBot group and playing a leading role in its operations. The group infiltrated computer systems, stole sensitive data, and in many cases, deployed ransomware to demand cryptocurrency payments.
According to the BKA’s wanted-person notice, the group was active from at least 2016 and at times had more than 100 members. Its victims included hospitals, public institutions, companies, government agencies, and private individuals.
The BKA says the group infected hundreds of thousands of systems in Germany and worldwide, generating hundreds of millions of euros through its criminal activities. German authorities estimate the damage caused in Germany to be at least €6.8 million ($7.8 million).
Other Topics of Interest
Ukraine Repatriates 252 Bodies From Russia
Forensic specialists will examine and identify the remains before they can be returned to families for burial.
The agency says Kovalev is believed to be living in Russia, although his current whereabouts are unknown. He is wanted on suspicion of forming a criminal organization.
Link to Conti
Kovalev’s alleged role extends beyond TrickBot.
The EU in July 2026 sanctioned Kovalev, identifying him as a senior figure in both the TrickBot and Conti malware operations. The EU decision says TrickBot and Conti were originally created and developed by the Wizard Spider cybercrime group.
According to them, Wizard Spider conducted ransomware campaigns against multiple sectors, including essential services such as healthcare and banking, and that its operations caused significant economic damage in Europe.
US authorities have separately linked TrickBot and Conti. The US Justice Department says TrickBot was used as an initial means of infiltrating computer systems before ransomware such as Conti was deployed. Conti was used against more than 900 victims worldwide, according to the department.
Hospitals among the victims
Healthcare organizations were among the targets.
The US Justice Department says Conti ransomware affected more than 900 businesses, nonprofits, governments, and other victims worldwide.
US authorities have also documented attacks against hospitals, local governments, and emergency services. The Justice Department said Conti conspirators encrypted computer systems belonging to a sheriff’s department, police department, and emergency medical services in the US.
From cybercrime to Russian politics
The reported connection between Kovalev and Davankov has drawn attention because of Kovalev’s status as a wanted cybercrime suspect.
According to Davankov’s own Telegram posts, Kovalev worked with him as an adviser. ASTRA reported that the New People party subsequently included Kovalev on its federal State Duma candidate list, although he was later removed.
Kovalev is not currently a candidate, according to Novaya Gazeta Europe, which reported that he was removed from the list when it was formally approved in July.
Click Here For The Original Source.
