The U.S. Department of Justice disrupted the Kelihos botnet, a network of more than 100,000 compromised Windows computers allegedly controlled by Russian national Peter Yuryevich Levashov (also known as Peter Severa). Authorities said Kelihos had operated since 2010 and was used to send spam, steal passwords and credentials, distribute malware, and support pump-and-dump stock fraud. The FBI linked Levashov to the infrastructure through IP addresses and online account records, while working with CrowdStrike and the Shadowserver Foundation to sinkhole the botnet and cut communications between infected machines and their controllers.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Peter Yuryevich Levashov pleaded guilty in U.S. District Court in Hartford to causing intentional damage to a protected computer, conspiracy, wire fraud, and aggravated identity theft tied to Kelihos.
A grand jury in the District of Connecticut returned an indictment against Peter Levashov over his alleged operation of the Kelihos botnet.
The U.S. Department of Justice announced a global disruption operation against the Kelihos botnet, working with partners to sinkhole the botnet and sever communications with infected machines.
Spanish authorities arrested alleged Kelihos operator Peter Yuryevich Levashov in Barcelona based on a criminal complaint and arrest warrant from the District of Connecticut.
The Kelihos botnet began operating in 2010, infecting Microsoft Windows systems and supporting spam, password theft, fraud schemes, and malware distribution.
Peter Levashov was extradited from Spain to the United States in February following his arrest in the Kelihos botnet case.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
justice.gov
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.