{
  "id": "case-bogachev-gameover",
  "slug": "us-v-bogachev-gameover-zeus",
  "title": "U.S. v. Evgeniy Mikhailovich Bogachev (GameOver Zeus & CryptoLocker)",
  "summary": "Federal indictment of Russian syndicate leader Evgeniy Bogachev for operating GameOver Zeus, a peer-to-peer banking trojan, and CryptoLocker, the first mass-market cryptoviral ransomware, stealing over $100 million with an unprecedented $3 million FBI Rewards for Justice bounty.",
  "case_number": "2:14-cr-00127-MRH",
  "court": "U.S. District Court for the Western District of Pennsylvania",
  "district": "W.D. Pa.",
  "country": "Russia",
  "opened_at": "2014-05-30",
  "status": "fugitive",
  "victim_sector": "Financial Services & Banking",
  "victim_country": "United States",
  "loss_amount_usd": 100000000,
  "loss_amount_note": "Estimated wire fraud losses across regional banks, municipalities, and businesses.",
  "first_seen_at": "2011-09-01T00:00:00Z",
  "last_updated_at": "2026-10-06T10:00:00Z",
  "actor_slug": "evil-corp",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1486",
      "evidence_excerpt": "CryptoLocker utilized asymmetric public-key cryptography (RSA-2048) to encrypt victim files, displaying a 72-hour countdown payment timer demanding Bitcoin or MoneyPak vouchers.",
      "evidence_locator": "DOJ Criminal Indictment \u00b6 32, Page 14",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Indictment: U.S. v. Bogachev",
      "source_url": "https://www.justice.gov/opa/pr/us-leads-multi-national-action-against-gameover-zeus-botnet-and-cryptolocker-ransomware",
      "technique_name": "Data Encrypted for Impact",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1090",
      "evidence_excerpt": "GameOver Zeus replaced traditional centralized command servers with a decentralized peer-to-peer protocol resilient to single-point DNS sinkholing.",
      "evidence_locator": "FBI Technical Analysis Affidavit \u00b6 21",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "FBI Technical Affidavit",
      "source_url": "https://www.justice.gov",
      "technique_name": "Proxy",
      "tactic": "Command and Control"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2013-09-05",
      "description": "CryptoLocker first appears in the wild propagating via GameOver Zeus botnet nodes."
    },
    {
      "event_type": "indictment",
      "event_date": "2014-05-30",
      "description": "Federal grand jury indicts Bogachev on conspiracy, computer fraud, wire fraud, and money laundering."
    },
    {
      "event_type": "takedown",
      "event_date": "2014-06-02",
      "description": "FBI and multinational law enforcement execute Operation Tovar, seizing botnet peer nodes."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Mass spearphishing email campaigns delivering GameOver Zeus banking malware to enterprise and municipal networks.",
    "blast_radius": "Over $100 million in direct wire fraud stolen from financial institutions and regional municipalities, while CryptoLocker infected hundreds of thousands of computers, resulting in an unprecedented $3 million FBI bounty.",
    "kill_chain": [
      {
        "phase": "Initial Access",
        "title": "Malicious Attachment Ingress",
        "description": "Victims received spearphishing emails carrying malicious attachments that installed GameOver Zeus banking trojan droppers.",
        "technical_artifacts": [
          "GameOver Zeus dropper",
          "Weaponized email lures"
        ],
        "mitre_technique_id": "T1566.001"
      },
      {
        "phase": "C2 Overlay",
        "title": "Peer-to-Peer Botnet Command Overlay",
        "description": "GameOver Zeus utilized a decentralized peer-to-peer communication topology that prevented law enforcement from terminating command infrastructure with simple DNS sinkholes.",
        "technical_artifacts": [
          "P2P communication protocol",
          "Cryptographic node verification"
        ],
        "mitre_technique_id": "T1090"
      },
      {
        "phase": "Credential Theft",
        "title": "Web Injection & Financial API Hooking",
        "description": "The malware intercepted online banking sessions, injecting fraudulent wire transfer instructions and harvesting two-factor authentication tokens in real time.",
        "technical_artifacts": [
          "Man-in-the-browser hooks",
          "Web injection scripts"
        ],
        "mitre_technique_id": "T1185"
      },
      {
        "phase": "Payload Distribution",
        "title": "CryptoLocker Secondary Detonation",
        "description": "Syndicate operators pushed the CryptoLocker ransomware binary across botnet nodes, initiating rapid asymmetric encryption of victim hard drives.",
        "technical_artifacts": [
          "CryptoLocker binary",
          "RSA-2048 public key"
        ],
        "mitre_technique_id": "T1486"
      },
      {
        "phase": "Extortion Impact",
        "title": "Countdown Extortion Demand",
        "description": "CryptoLocker displayed a 72-hour countdown timer demanding payment via Bitcoin or prepaid MoneyPak vouchers before destroying decryption keys.",
        "technical_artifacts": [
          "Countdown payment screen",
          "Bitcoin wallet address"
        ],
        "mitre_technique_id": "T1486"
      }
    ],
    "defensive_takeaways": [
      "Enforce strict dual-custody authorization for all outbound corporate wire transfers and ACH payments.",
      "Block inbound executable attachments and macros at email perimeter filtering gateways.",
      "Maintain immutable, air-gapped system backups protected from asymmetric ransomware encryption.",
      "Deploy endpoint behavioral analysis to detect automated encryption attempts and shadow copy deletion."
    ]
  }
}