Colombian authorities arrested Romanian national Mihai Ionut Paunescu, also known as "Virus," in Bogotá on U.S. charges tied to the Gozi banking trojan. Prosecutors allege Paunescu ran the bulletproof hosting service PowerHost[.]ro and helped protect and scale Gozi infrastructure after joining the operation around the release of Gozi 2.0. U.S. officials said the botnet infected more than one million computers between 2007 and 2013, stole online banking credentials, and enabled the theft of tens of millions of dollars from victims in the United States and Europe; authorities said they would pursue extradition from Colombia after earlier efforts in Romania failed.
The arrest adds to a case that previously saw Gozi creator Nikita Kuzmin sentenced in the United States after admitting to computer intrusion and fraud offenses, while investigators also tied Deniss Calovskis to web injects used against banks. Court filings said Kuzmin marketed Gozi through an early malware-as-a-service scheme known as "76 Service," renting the malware to other criminals. Security researchers have since linked Gozi’s leaked codebase to later malware families, including the advanced RM3 / Gozi-ISFB strain, which targeted more than 130 financial institutions across Oceania and Europe and expanded beyond credential theft into browser interception, hidden VNC, SOCKS proxying, remote shell access, and ransomware-enabling post-compromise activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
16 events from the most recent confirmed update back to the earliest known activity.
A short-lived RM3.at infrastructure appeared around summer 2019 and showed similarities with GoziAT infrastructure. The report cited it as part of RM3's evolving operational footprint.
Fox-IT reported that 2019 was a peak period for RM3 activity, with five operators active at the same time. Researchers also observed at least eight RM3 infrastructures across Europe, Oceania, and worldwide operations.
The actor known as Sagrid was identified as a prolific RM3 distributor, especially in Australia and New Zealand around 2018 and 2019. The campaigns commonly used malspam to spread the malware.
Fox-IT said the RM3 variant of Gozi/ISFB was detected in the wild in 2017 with major modifications from previous variants. Researchers described it as a heavily reworked strain with new modules and communications methods.
On May 2, 2016, Nikita Kuzmin was sentenced in Manhattan federal court to time served of 37 months and ordered to pay $6,934,979 in forfeiture and restitution. The Justice Department said Gozi had infected over one million computers and caused tens of millions of dollars in losses.
Deniss Calovskis was sentenced on January 5, 2016 to time served of 21 months for writing certain web injects used by Gozi to target particular banks. Prosecutors said his code helped tailor the malware to specific financial institutions.
The Fox-IT report states that Gozi ISFB began targeting financial institutions around 2013 to 2015. This marked the expansion of post-leak Gozi-derived malware activity.
Nikita Kuzmin was arrested in California in 2013 in connection with the Gozi case. Prosecutors identified him as the original creator of the banking trojan.
After the Gozi gang was charged in January 2013, the malware's source code leaked online. The leak later enabled multiple banking trojan strains including Gozi ISFB, Neverquest, Rovnix, Vawtrack, and Ursnif.
U.S. authorities officially charged Mihai Ionut Paunescu in January 2013 as one of three suspects accused of creating and operating the Gozi banking trojan. The case also involved Nikita Kuzmin and Deniss Calovskis.
Mihai Ionut Paunescu was arrested in Bucharest, Romania, in December 2012 for allegedly operating a bulletproof hosting service that enabled distribution of Gozi and other malware. He was later described as awaiting extradition to the United States.
Nikita Kuzmin pleaded guilty in May 2011 to computer intrusion and fraud charges pursuant to a cooperation agreement. He was later identified by prosecutors as the creator of the Gozi malware.
U.S. officials said Mihai Ionut Paunescu joined the Gozi operation in 2010 when the Gozi 2.0 variant was first released. Prosecutors alleged he helped protect and scale the malware's infrastructure through his bulletproof hosting service.
Computer network security experts first identified Gozi in approximately 2007 as malware that stole victims' bank account information on a widespread basis. Authorities later said the botnet infected more than one million computers between 2007 and 2013.
Colombian authorities arrested Mihai Ionut Paunescu at El Dorado airport in Bogotá in connection with longstanding U.S. charges tied to Gozi. Colombia's attorney general office announced the arrest on Thursday, and U.S. officials said they would begin new extradition proceedings there.
After the pandemic, RM3 activity shifted away from classic fraud toward bot harvesting and reconnaissance. Researchers observed tasking such as GET_SYSINFO and domain enumeration that they linked to ransomware-style triage.
3 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourceblog.fox-it.com
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.