Law enforcement agencies disrupt Gameover Zeus botnet

Two U.S. courts unseal charges releated to the giant botnet and the Cryptolocker ransomware

The U.S. Department of Justice, working with law enforcement agencies in other countries, revealed Monday a multinational effort to disrupt Gameover Zeus, a 2-year-old botnet employing an estimated 500,000 to 1 million compromised computers.

Two U.S. courts, meanwhile, have unsealed criminal charges against the alleged administrator of the giant Gameover Zeus botnet. The FBI estimates that Gameover Zeus, which targets banking credentials and other personal information, is responsible for more than US$100 million in losses.

In a separate but related action, U.S. and foreign law enforcement officials worked together to seize computer servers central to the malware known as Cryptolocker, a form of ransomware that encrypts files on victims' computers until they pay a ransom, the DOJ said.

"This operation disrupted a global botnet that had stolen millions from businesses and consumers as well as a complex ransomware scheme that secretly encrypted hard drives and then demanded payments for giving users access to their own files and data," Deputy Attorney General James Cole said in a statement.

In the Gameover Zeus case, a grand jury in Pittsburgh has unsealed a 14-count indictment against Evgeniy Mikhailovich Bogachev, 30, of Anapa, Russia, the DOJ announced Monday. The grand jury charged him with conspiracy, computer hacking, wire fraud, bank fraud and money laundering in connection with his alleged role as an administrator of Gameover Zeus.

Bogachev was also charged by criminal complaint in Omaha, Nebraska, with conspiracy to commit bank fraud related to his alleged involvement in the operation of a prior variant of Zeus malware known as Jabber Zeus.

"Gameover Zeus is the most sophisticated botnet the FBI and our allies have ever attempted to disrupt," FBI Executive Assistant Director Robert Anderson Jr. said in a statement. "The efforts announced today are a direct result of the effective relationships we have with our partners in the private sector, international law enforcement, and within the U.S. government."

In a separate civil injunction application filed in Pittsburgh, Bogachev is identified as the alleged leader of a tightly knit gang of cybercriminals based in Russia and Ukraine responsible for the development and operation of both the Gameover Zeus and Cryptolocker schemes.

A law enforcement investigation identified the Gameover Zeus network as a common distribution mechanism for Cryptolocker, the DOJ said.

Unsolicited emails containing an infected file purporting to be a voicemail or shipping confirmation are also widely used to distribute Cryptolocker. When opened, those attachments infect victims' computers. Bogachev is alleged in the civil filing to be an administrator of both Gameover Zeus and Cryptolocker.

Law enforcement agencies from several countries also participated in efforts to disrupt Gameover Zeus and Cryptolocker.

The U.S. Department of Homeland Security's Computer Emergency Readiness Team (US-CERT) has published a website to help victims of Gameover Zeus remove the malware.

In addition to the criminal charges announced Monday, U.S. law enforcement agencies have obtained civil and criminal court orders in Pittsburgh authorizing them to redirect the automated requests by victim computers away from the criminal operators to substitute servers established by investigators.

The order authorizes the FBI to obtain the Internet Protocol addresses of the victim computers reaching out to the substitute servers and to share that information with US-CERT, other countries' computer security agencies and private companies in an effort to assist victims of Gameover Zeus, the DOJ said. The FBI and other law enforcement agencies have not accessed the content of victims' computers or their electronic communications, the DOJ said.

Participating in the disruption operation were law enforcement agencies from Australia, the Netherlands, Germany, France, Italy, Japan, Canada, the Ukraine, the U.K. and other countries, the DOJ said.

In addition to the disruption operation against Gameover Zeus, the DOJ led a separate multi-national action to disrupt Cryptolocker, which began appearing about September 2013. The malware forces victims to pay as much as $700 to receive the keys necessary to unlock their files, the DOJ said.

By April, Cryptolocker had infected more than 234,000 computers, with approximately half of those in the U.S., the DOJ said. Victims made more than $27 million in ransom payments in the first two months after Cryptolocker emerged, according to one estimate.

Anyone claiming an interest in any of the property seized or actions enjoined pursuant to the court orders should visit the DOJ's Gameover Zeus website for notice of the full contents of the orders.

Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service. Follow Grant on Twitter at GrantGross. Grant's email address is grant_gross@idg.com.

Join the Good Gear Guide newsletter!

Error: Please check your email address.

Tags U.S. Department of JusticesecurityU.S. Department of Homeland SecurityEvgeniy Mikhailovich BogachevlegalJames ColeIdentity fraud / theftfbicybercrimeRobert Anderson Jr.

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Grant Gross

IDG News Service
Show Comments

Essentials

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?