U.S. and European authorities, working with security companies and researchers, disrupted the GameOver Zeus peer-to-peer botnet and seized infrastructure tied to CryptoLocker in a multinational action known as Operation Tovar. The malware network was estimated to have infected 500,000 to 1 million Windows systems worldwide and was used to steal banking credentials, personal data, and funds through account takeovers, spam campaigns, and DDoS-assisted fraud. U.S. prosecutors said the operation caused more than $100 million in losses, while CryptoLocker had infected more than 234,000 computers and generated over $27 million in ransom payments shortly after its emergence.
The U.S. Justice Department charged Russian national Evgeniy Mikhailovich Bogachev, also known as Slavik and Pollingsoon, as the alleged administrator behind the botnet. Authorities said the takedown created a roughly two-week window for victims and enterprises to clean infected machines before operators could attempt to regain control, and agencies including US-CERT and internet service providers were mobilized to support remediation. Investigators said GameOver Zeus spread largely through phishing emails, malicious spam, and compromised websites exploiting outdated software, prompting officials to urge users to update systems, run security scans, and change passwords.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
On 2015-02-25, U.S. authorities announced a reward of up to $3 million for information leading to the arrest or conviction of Evgeniy Bogachev, the alleged administrator of the GameOver Zeus botnet. The reward marked a significant escalation in efforts to apprehend Bogachev after the 2014 charges and botnet disruption.
In July 2014, researchers from Arbor Networks and Bitdefender observed new GameOver Zeus activity after Operation Tovar, including two new configurations using DGAs that generated 1,000 and 10,000 domains per day. Arbor said infections rose from 127 on July 14 to 429 on July 21 and then jumped to 8,494 on July 25 following a large spam campaign, with many infections concentrated in the United States.
Following the disruption, authorities said victims had an estimated two-week window to remove infections and secure systems before botnet operators might regain control. US-CERT and internet service providers were expected to help notify affected users and support remediation.
The Justice Department unsealed charges against Russian national Evgeniy Mikhailovich Bogachev, also known as "Slavik" and "Pollingsoon," alleging he created and operated GameOver Zeus. He was charged in a 14-count indictment and separate civil action but was not in custody.
On June 2, 2014, U.S.-led international law enforcement and private-sector partners launched Operation Tovar to seize control of the GameOver Zeus botnet and servers used to administer CryptoLocker. The action involved the FBI, DOJ, Europol, the UK National Crime Agency, security companies, and researchers.
U.S. authorities said the GameOver Zeus criminal enterprise enabled cybercriminals to steal more than $100 million from businesses and consumers since 2011. Prosecutors said the botnet infected roughly 500,000 to 1 million computers worldwide.
Authorities said CryptoLocker, distributed through the GameOver Zeus ecosystem, infected more than 234,000 computers and generated over $27 million in ransom payments in its first two months online. By April 2014, about half of known infections were in the United States.
In June 2012, the FBI's Pittsburgh office began investigating GameOver Zeus after encountering a small-business victim. The case then expanded into a long-running effort with private-sector researchers and security firms that ultimately led to Operation Tovar.
According to court documents cited in the references, the GameOver Zeus botnet had been operated since October 2011 by a core group of hackers from Russia and Ukraine. The malware infected hundreds of thousands of Windows systems and was used for banking theft, credential theft, spam, and DDoS-assisted fraud.
The FBI wanted notice says the bureau began investigating GameOver Zeus in September 2011. This predates the later June 2012 Pittsburgh case expansion already reflected in the timeline.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
fbi.gov
Open sourcevice.com
Open sourcekrebsonsecurity.com
Open sourcejustice.gov
Open sourcekrebsonsecurity.com
Open sourcekrebsonsecurity.com
Open sourcefbi.gov
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.