U.S. v. Peter Levashov (Kelihos Botnet)
Key Facts
- Legal Status: PLEADED in U.S. District Court for the District of Connecticut.
- Primary Target Sector: E-Commerce, Consumer Services, Telecommunications.
- Documented Financial Loss: $25.0 million.
- 1 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Unauthorized intrusion originating from targeted infiltration directed against E-Commerce, Consumer Services, Telecommunications networks. Russian operator (Severa) of the notorious Kelihos botnet, controlling over 100,000 infected computers worldwide used to harvest credentials, distribute ransomware, and blast billions of spam and stock pump-and-dump emails daily.
Operational & Financial Fallout
Generated tens of millions in fraudulent spam income and illicit botnet lease fees. Impacted E-Commerce, Consumer Services, Telecommunications infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Unauthorized intrusion originating from targeted infiltration directed against E-Commerce, Consumer Services, Telecommunications networks. Russian operator (Severa) of the notorious Kelihos botnet, controlling over 100,000 infected computers worldwide used to harvest credentials, distribute ransomware, and blast billions of spam and stock pump-and-dump emails daily.
Adversary Kill Chain Flow
2 Documented PhasesOperatives secured access to victim infrastructure within the E-Commerce, Consumer Services, Telecommunications sector.
Russian operator (Severa) of the notorious Kelihos botnet, controlling over 100,000 infected computers worldwide used to harvest credentials, distribute ransomware, and blast billions of spam and stock pump-and-dump emails daily.
Generated tens of millions in fraudulent spam income and illicit botnet lease fees. Impacted E-Commerce, Consumer Services, Telecommunications infrastructure and associated victim operations.
Procedural & Incident Timeline
Levashov arrested while vacationing in Barcelona, Spain, by Spanish National Police.
Extradited from Spain to the District of Connecticut.
Pleads guilty to wire fraud, computer fraud, and identity theft charges.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Peter Yuryevich Levashov | Russian Federation | pleaded | Pending | None | Operator of the Kelihos botnet; pleaded guilty in the District of Connecticut. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1584 | Compromise Infrastructure Resource Development | "Levashov leased out compromised zombie computers as an automated bulletproof proxy network to shield criminal infrastructure." | Indictment ¶ 11, Page 5 | reviewed |