CASE DOSSIER fugitive

U.S. v. Evgeniy Mikhailovich Bogachev (GameOver Zeus & CryptoLocker)

Docket: 2:14-cr-00127-MRH Court: U.S. District Court for the Western District of Pennsylvania Opened: 2014-05-30 Sector: Financial Services & Banking

Key Facts

Status
FUGITIVE
Legal disposition
Loss Amount
$100.0 million
Estimated wire fraud losses across regional banks, municipalities, and businesses.
Techniques
2
Verified mappings
Defendants
0
Named in charges
  • Legal Status: FUGITIVE in U.S. District Court for the Western District of Pennsylvania.
  • Primary Target Sector: Financial Services & Banking.
  • Documented Financial Loss: $100.0 million.
  • 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Federal indictment of Russian syndicate leader Evgeniy Bogachev for operating GameOver Zeus, a peer-to-peer banking trojan, and CryptoLocker, the first mass-market cryptoviral ransomware, stealing over $100 million with an unprecedented $3 million FBI Rewards for Justice bounty.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Mass spearphishing email campaigns delivering GameOver Zeus banking malware to enterprise and municipal networks.

Operational & Financial Fallout

Over $100 million in direct wire fraud stolen from financial institutions and regional municipalities, while CryptoLocker infected hundreds of thousands of computers, resulting in an unprecedented $3 million FBI bounty.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: FUGITIVE
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Mass spearphishing email campaigns delivering GameOver Zeus banking malware to enterprise and municipal networks.

Adversary Kill Chain Flow

5 Documented Phases
1
Initial Access Malicious Attachment Ingress
MITRE ATT&CK T1566.001 →

Victims received spearphishing emails carrying malicious attachments that installed GameOver Zeus banking trojan droppers.

Artifacts & Tooling: GameOver Zeus dropper Weaponized email lures
2
C2 Overlay Peer-to-Peer Botnet Command Overlay
MITRE ATT&CK T1090 →

GameOver Zeus utilized a decentralized peer-to-peer communication topology that prevented law enforcement from terminating command infrastructure with simple DNS sinkholes.

Artifacts & Tooling: P2P communication protocol Cryptographic node verification
3
Credential Theft Web Injection & Financial API Hooking
MITRE ATT&CK T1185 →

The malware intercepted online banking sessions, injecting fraudulent wire transfer instructions and harvesting two-factor authentication tokens in real time.

Artifacts & Tooling: Man-in-the-browser hooks Web injection scripts
4
Payload Distribution CryptoLocker Secondary Detonation
MITRE ATT&CK T1486 →

Syndicate operators pushed the CryptoLocker ransomware binary across botnet nodes, initiating rapid asymmetric encryption of victim hard drives.

Artifacts & Tooling: CryptoLocker binary RSA-2048 public key
5
Extortion Impact Countdown Extortion Demand
MITRE ATT&CK T1486 →

CryptoLocker displayed a 72-hour countdown timer demanding payment via Bitcoin or prepaid MoneyPak vouchers before destroying decryption keys.

Artifacts & Tooling: Countdown payment screen Bitcoin wallet address
Real-World Blast Radius & Operational Fallout

Over $100 million in direct wire fraud stolen from financial institutions and regional municipalities, while CryptoLocker infected hundreds of thousands of computers, resulting in an unprecedented $3 million FBI bounty.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce strict dual-custody authorization for all outbound corporate wire transfers and ACH payments.
✓ Block inbound executable attachments and macros at email perimeter filtering gateways.
✓ Maintain immutable, air-gapped system backups protected from asymmetric ransomware encryption.
✓ Deploy endpoint behavioral analysis to detect automated encryption attempts and shadow copy deletion.

Procedural & Incident Timeline

2013-09-05 incident

CryptoLocker first appears in the wild propagating via GameOver Zeus botnet nodes.

2014-05-30 indictment

Federal grand jury indicts Bogachev on conspiracy, computer fraud, wire fraud, and money laundering.

2014-06-02 takedown

FBI and multinational law enforcement execute Operation Tovar, seizing botnet peer nodes.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1486 Data Encrypted for Impact
Impact
"CryptoLocker utilized asymmetric public-key cryptography (RSA-2048) to encrypt victim files, displaying a 72-hour countdown payment timer demanding Bitcoin or MoneyPak vouchers." DOJ Criminal Indictment ¶ 32, Page 14 reviewed
T1090 Proxy
Command and Control
"GameOver Zeus replaced traditional centralized command servers with a decentralized peer-to-peer protocol resilient to single-point DNS sinkholing." FBI Technical Analysis Affidavit ¶ 21 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Evgeniy Mikhailovich Bogachev (GameOver Zeus & CryptoLocker), No. 2:14-cr-00127-MRH (U.S. District Court for the Western District of Pennsylvania 2014), https://cybercaselibrary.com/cases/us-v-bogachev-gameover-zeus/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-bogachev-gameover-zeus" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>