Ukrainian national Yuriy Igorevich Rybtsov, known online as 'MrICQ', was extradited from Italy to the United States to face cybercrime charges related to his alleged role as a developer and operator within the Jabber Zeus cybercrime group. Rybtsov, who was arrested in Italy and lost his final appeal against extradition in April 2025, arrived in Nebraska under an FBI warrant and is now awaiting trial. Investigators allege that Rybtsov helped operate the Jabber Zeus group by handling real-time alerts of newly compromised victims and laundering stolen funds through electronic exchanges, with connections to other prominent group members including Vyacheslav "Tank" Penchukov, Maksim "Aqua" Yakubets, and Evgeniy Bogachev.
The Jabber Zeus group used a modified version of the Zeus banking trojan, featuring a real-time Jabber alert system called Leprechaun, to steal online banking credentials from small and mid-sized businesses. The group captured sensitive data such as account numbers and one-time passwords, enabling them to make fraudulent transfers to U.S. bank accounts controlled by money mules. Authorities report that the group laundered millions of dollars through networks in the UK, U.S., and Ukraine, and that Rybtsov played a key role in both technical operations and financial laundering activities.

See the reporting duties and controls this puts on the clock.
1 event from the most recent confirmed update back to the earliest known activity.
U.S. authorities gained custody of a suspect identified as a developer for the Jabber Zeus cybercrime gang after he was extradited from Italy. Multiple reports on November 3, 2025 described the individual, also referred to as 'MrICQ,' as a suspected coder tied to the group.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.