{
  "id": "case-brovko-botnet",
  "slug": "us-v-brovko-botnet-logs",
  "title": "U.S. v. Aleksandr Brovko (Botnet Parsing & Credential Sales)",
  "summary": "Russian national who developed automated scripts to parse botnet logs, extracting financial information and account credentials from thousands of victim computers and marketing them on cybercrime forums.",
  "case_number": "1:20-cr-00037",
  "court": "U.S. District Court for the Eastern District of Virginia",
  "district": "E.D. Va.",
  "country": "United States",
  "opened_at": "2020-02-12",
  "status": "sentenced",
  "victim_sector": "Consumer Finance, Banking",
  "victim_country": "United States",
  "loss_amount_usd": 100000000,
  "loss_amount_note": "Parsed stolen data contributing to more than $100 million in estimated consumer fraud losses.",
  "first_seen_at": "2007-01-01T00:00:00Z",
  "last_updated_at": "2026-08-18T14:00:00Z",
  "actor_slug": "brovko-network",
  "defendant_slugs": [
    "aleksandr-brovko"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1555",
      "evidence_excerpt": "Defendant wrote Python scripts to parse massive unorganized text files exfiltrated by info-stealer trojans to isolate valid credit card numbers and passwords.",
      "evidence_locator": "Plea Agreement \u00b6 4, Page 5",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Plea Agreement: U.S. v. Brovko",
      "source_url": "https://www.justice.gov/usao-edva/pr/russian-national-sentenced-conspiracy-commit-wire-fraud",
      "technique_name": "Credentials from Password Stores",
      "tactic": "Credential Access"
    }
  ],
  "events": [
    {
      "event_type": "plea",
      "event_date": "2020-02-14",
      "description": "Pleads guilty to conspiracy to commit wire fraud and computer intrusion."
    },
    {
      "event_type": "sentencing",
      "event_date": "2020-10-30",
      "description": "Sentenced to 96 months (8 years) in federal prison."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Consumer Finance, Banking networks. Russian national who developed automated scripts to parse botnet logs, extracting financial information and account credentials from thousands of victim computers and marketing them on cybercrime forums.",
    "blast_radius": "Parsed stolen data contributing to more than $100 million in estimated consumer fraud losses. Impacted Consumer Finance, Banking infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Credential Access",
        "title": "Credential Harvesting & Memory Dumping",
        "description": "Defendant wrote Python scripts to parse massive unorganized text files exfiltrated by info-stealer trojans to isolate valid credit card numbers and passwords.",
        "technical_artifacts": [
          "T1555",
          "Credentials from Password Stores"
        ],
        "mitre_technique_id": "T1555"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}