U.S. v. Aleksandr Brovko (Botnet Parsing & Credential Sales)
Key Facts
- Legal Status: SENTENCED in U.S. District Court for the Eastern District of Virginia.
- Primary Target Sector: Consumer Finance, Banking.
- Documented Financial Loss: $100.0 million.
- 1 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Unauthorized intrusion originating from targeted infiltration directed against Consumer Finance, Banking networks. Russian national who developed automated scripts to parse botnet logs, extracting financial information and account credentials from thousands of victim computers and marketing them on cybercrime forums.
Operational & Financial Fallout
Parsed stolen data contributing to more than $100 million in estimated consumer fraud losses. Impacted Consumer Finance, Banking infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Unauthorized intrusion originating from targeted infiltration directed against Consumer Finance, Banking networks. Russian national who developed automated scripts to parse botnet logs, extracting financial information and account credentials from thousands of victim computers and marketing them on cybercrime forums.
Adversary Kill Chain Flow
1 Documented PhasesDefendant wrote Python scripts to parse massive unorganized text files exfiltrated by info-stealer trojans to isolate valid credit card numbers and passwords.
Parsed stolen data contributing to more than $100 million in estimated consumer fraud losses. Impacted Consumer Finance, Banking infrastructure and associated victim operations.
Procedural & Incident Timeline
Pleads guilty to conspiracy to commit wire fraud and computer intrusion.
Sentenced to 96 months (8 years) in federal prison.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Aleksandr Brovko | Russian Federation | sentenced | 96 mo | None | Botnet log parser sentenced to 8 years in federal prison in E.D. Va. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1555 | Credentials from Password Stores Credential Access | "Defendant wrote Python scripts to parse massive unorganized text files exfiltrated by info-stealer trojans to isolate valid credit card numbers and passwords." | Plea Agreement ¶ 4, Page 5 | reviewed |