Individual threat actor

Vitaly Kovalev

Vitaly Kovalev is publicly identified in sanctions material as a senior figure associated with TrickBot and Conti, with aliases including Bentley, Bergen, Alex Konor, Benny, Ben and Stern. His profile is a persona-level bridge between sanctions, TrickBot/Wizard Spider ecosystem attribution and ransomware-enabled cybercrime.

This profile should be interpreted as a structured intelligence artifact for 3C-INT/CRIPRO. It separates actor-controlled claims, official designations, vendor/public reporting and analytical inference. For persona profiles, the highest-confidence information concerns identity labels, public role, sanctions/designation context and associations; technical capability should be inherited from the associated group or malware ecosystem only when explicitly supported.

INFERENCE (confidence: medium): The defensive value of this profile is strongest when used to enrich relationship graphs, sanctions/persona pivots, campaign correlation, and detection priorities rather than as a standalone proof of operational control by any single individual.

Created by iQBlack CTI Team
Contributors 1
Last updated 2026-08-19

ATT&CK

MITRE ATT&CK

T1003OS Credential Dumping
T1021Remote Services
T1041Exfiltration Over C2 Channel
T1059Command and Scripting Interpreter
T1071.001Web Protocols
T1105Ingress Tool Transfer
T1486Data Encrypted for Impact
T1489Service Stop
T1490Inhibit System Recovery
T1566Phishing

Research

Selected OSINT