{
  "id": "case-bitzlato-hydra",
  "slug": "us-v-legkodymov-bitzlato",
  "title": "U.S. v. Anatoly Legkodymov (Bitzlato Cryptocurrency Laundering)",
  "summary": "Founder of Hong Kong-registered cryptocurrency exchange Bitzlato charged with laundering over $700 million in ransomware and darknet market illicit proceeds, serving as a primary financial conduit for Hydra Market.",
  "case_number": "1:23-cr-00021",
  "court": "U.S. District Court for the Eastern District of New York",
  "district": "E.D.N.Y.",
  "country": "United States",
  "opened_at": "2023-01-17",
  "status": "sentenced",
  "victim_sector": "Cryptocurrency, Financial Services",
  "victim_country": "United States, Russia, France",
  "loss_amount_usd": 700000000,
  "loss_amount_note": "Processed over $4.58 billion in crypto transactions, with at least $700 million directly tied to darknet contraband and ransomware proceeds.",
  "first_seen_at": "2018-05-01T00:00:00Z",
  "last_updated_at": "2026-09-03T16:00:00Z",
  "actor_slug": "bitzlato",
  "defendant_slugs": [
    "anatoly-legkodymov"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1090",
      "evidence_excerpt": "Bitzlato operated with negligible anti-money laundering controls, advertising that users could open accounts with no identity verification via Tor.",
      "evidence_locator": "Plea Agreement \u00b6 6, Page 7",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Plea Agreement: U.S. v. Legkodymov",
      "source_url": "https://www.justice.gov/opa/pr/founder-and-majority-owner-bitzlato-pleads-guilty-unlicensed-money-transmitting",
      "technique_name": "Proxy",
      "tactic": "Command and Control"
    }
  ],
  "events": [
    {
      "event_type": "arrest",
      "event_date": "2023-01-17",
      "description": "Legkodymov arrested in Miami by FBI agents in coordinated international operation."
    },
    {
      "event_type": "plea",
      "event_date": "2023-12-06",
      "description": "Defendant pleads guilty to operating an unlicensed money transmitting business."
    },
    {
      "event_type": "sentencing",
      "event_date": "2024-07-18",
      "description": "Sentenced to time served (18 months) and ordered to forfeit all interest in Bitzlato ($23 million)."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Cryptocurrency, Financial Services networks. Founder of Hong Kong-registered cryptocurrency exchange Bitzlato charged with laundering over $700 million in ransomware and darknet market illicit proceeds, serving as a primary financial conduit for Hydra Market.",
    "blast_radius": "Processed over $4.58 billion in crypto transactions, with at least $700 million directly tied to darknet contraband and ransomware proceeds. Impacted Cryptocurrency, Financial Services infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Infiltration",
        "title": "Perimeter Ingress",
        "description": "Operatives secured access to victim infrastructure within the Cryptocurrency, Financial Services sector.",
        "technical_artifacts": [
          "Network perimeter logs"
        ],
        "mitre_technique_id": "T1190"
      },
      {
        "phase": "Phase 2: Execution",
        "title": "Payload Deployment",
        "description": "Founder of Hong Kong-registered cryptocurrency exchange Bitzlato charged with laundering over $700 million in ransomware and darknet market illicit proceeds, serving as a primary financial conduit for Hydra Market.",
        "technical_artifacts": [
          "Malicious payload"
        ],
        "mitre_technique_id": "T1486"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}