U.S. v. Evgeniy Mikhailovich Bogachev (GameOver Zeus & CryptoLocker)
Key Facts
- Legal Status: FUGITIVE in U.S. District Court for the Western District of Pennsylvania.
- Primary Target Sector: Financial Services & Banking.
- Documented Financial Loss: $100.0 million.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Mass spearphishing email campaigns delivering GameOver Zeus banking malware to enterprise and municipal networks.
Operational & Financial Fallout
Over $100 million in direct wire fraud stolen from financial institutions and regional municipalities, while CryptoLocker infected hundreds of thousands of computers, resulting in an unprecedented $3 million FBI bounty.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Mass spearphishing email campaigns delivering GameOver Zeus banking malware to enterprise and municipal networks.
Adversary Kill Chain Flow
5 Documented PhasesVictims received spearphishing emails carrying malicious attachments that installed GameOver Zeus banking trojan droppers.
GameOver Zeus utilized a decentralized peer-to-peer communication topology that prevented law enforcement from terminating command infrastructure with simple DNS sinkholes.
The malware intercepted online banking sessions, injecting fraudulent wire transfer instructions and harvesting two-factor authentication tokens in real time.
Syndicate operators pushed the CryptoLocker ransomware binary across botnet nodes, initiating rapid asymmetric encryption of victim hard drives.
CryptoLocker displayed a 72-hour countdown timer demanding payment via Bitcoin or prepaid MoneyPak vouchers before destroying decryption keys.
Over $100 million in direct wire fraud stolen from financial institutions and regional municipalities, while CryptoLocker infected hundreds of thousands of computers, resulting in an unprecedented $3 million FBI bounty.
Procedural & Incident Timeline
CryptoLocker first appears in the wild propagating via GameOver Zeus botnet nodes.
Federal grand jury indicts Bogachev on conspiracy, computer fraud, wire fraud, and money laundering.
FBI and multinational law enforcement execute Operation Tovar, seizing botnet peer nodes.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1486 | Data Encrypted for Impact Impact | "CryptoLocker utilized asymmetric public-key cryptography (RSA-2048) to encrypt victim files, displaying a 72-hour countdown payment timer demanding Bitcoin or MoneyPak vouchers." | DOJ Criminal Indictment ¶ 32, Page 14 | reviewed |
| T1090 | Proxy Command and Control | "GameOver Zeus replaced traditional centralized command servers with a decentralized peer-to-peer protocol resilient to single-point DNS sinkholing." | FBI Technical Analysis Affidavit ¶ 21 | reviewed |