{
  "id": "case-levashov-kelihos",
  "slug": "us-v-levashov-kelihos-botnet",
  "title": "U.S. v. Peter Levashov (Kelihos Botnet)",
  "summary": "Russian operator (Severa) of the notorious Kelihos botnet, controlling over 100,000 infected computers worldwide used to harvest credentials, distribute ransomware, and blast billions of spam and stock pump-and-dump emails daily.",
  "case_number": "3:17-cr-00083",
  "court": "U.S. District Court for the District of Connecticut",
  "district": "D. Conn.",
  "country": "United States",
  "opened_at": "2017-04-07",
  "status": "pleaded",
  "victim_sector": "E-Commerce, Consumer Services, Telecommunications",
  "victim_country": "United States, Worldwide",
  "loss_amount_usd": 25000000,
  "loss_amount_note": "Generated tens of millions in fraudulent spam income and illicit botnet lease fees.",
  "first_seen_at": "2010-01-01T00:00:00Z",
  "last_updated_at": "2026-08-15T12:00:00Z",
  "actor_slug": "kelihos-crew",
  "defendant_slugs": [
    "peter-levashov"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1584",
      "evidence_excerpt": "Levashov leased out compromised zombie computers as an automated bulletproof proxy network to shield criminal infrastructure.",
      "evidence_locator": "Indictment \u00b6 11, Page 5",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Levashov",
      "source_url": "https://www.justice.gov/opa/pr/russian-national-pleads-guilty-operating-notorious-kelihos-botnet",
      "technique_name": "Compromise Infrastructure",
      "tactic": "Resource Development"
    }
  ],
  "events": [
    {
      "event_type": "arrest",
      "event_date": "2017-04-07",
      "description": "Levashov arrested while vacationing in Barcelona, Spain, by Spanish National Police."
    },
    {
      "event_type": "extradition",
      "event_date": "2018-02-02",
      "description": "Extradited from Spain to the District of Connecticut."
    },
    {
      "event_type": "plea",
      "event_date": "2018-09-12",
      "description": "Pleads guilty to wire fraud, computer fraud, and identity theft charges."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against E-Commerce, Consumer Services, Telecommunications networks. Russian operator (Severa) of the notorious Kelihos botnet, controlling over 100,000 infected computers worldwide used to harvest credentials, distribute ransomware, and blast billions of spam and stock pump-and-dump emails daily.",
    "blast_radius": "Generated tens of millions in fraudulent spam income and illicit botnet lease fees. Impacted E-Commerce, Consumer Services, Telecommunications infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Infiltration",
        "title": "Perimeter Ingress",
        "description": "Operatives secured access to victim infrastructure within the E-Commerce, Consumer Services, Telecommunications sector.",
        "technical_artifacts": [
          "Network perimeter logs"
        ],
        "mitre_technique_id": "T1190"
      },
      {
        "phase": "Phase 2: Execution",
        "title": "Payload Deployment",
        "description": "Russian operator (Severa) of the notorious Kelihos botnet, controlling over 100,000 infected computers worldwide used to harvest credentials, distribute ransomware, and blast billions of spam and stock pump-and-dump emails daily.",
        "technical_artifacts": [
          "Malicious payload"
        ],
        "mitre_technique_id": "T1486"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}