Vyacheslav Igorevich Penchukov, a Ukrainian national known as "Tank" and "Father," pleaded guilty in the United States to RICO conspiracy and wire fraud conspiracy for his role in long-running cybercrime schemes tied to the Zeus and IcedID malware operations. U.S. authorities said Penchukov helped lead groups that infected thousands of computers, stole tens of millions of dollars from businesses, and used banking trojans, phishing, man-in-the-browser tactics, and money mule networks to drain victim accounts. Prosecutors also said the malware activity enabled follow-on intrusions, including ransomware deployment, and reporting has linked Penchukov to the Maze and Egregor ecosystems.
Penchukov was arrested in Switzerland in 2022 after years of allegedly evading law enforcement in Ukraine, then extradited to the United States in 2023. His case connects to a broader international campaign against the Zeus cybercrime infrastructure, including earlier U.S.-led action against the Gameover Zeus botnet and CryptoLocker ransomware, as well as prosecutions of bulletproof hosting operators that supported malware families such as Zeus, SpyEye, and Citadel. The guilty plea marks a significant step in a multinational effort to dismantle the criminal services, hosting networks, and operators behind major banking malware and ransomware activity.

See the reporting duties and controls this puts on the clock.
12 events from the most recent confirmed update back to the earliest known activity.
Penchukov pleaded guilty in the United States to one RICO conspiracy count tied to his leadership role in the Zeus operation and one wire fraud conspiracy count tied to the IcedID malware group. The Justice Department said he helped lead two prolific malware groups that infected thousands of computers and caused tens of millions of dollars in losses.
Penchukov was extradited from Switzerland to the United States in 2023 to face charges tied to the Zeus and IcedID malware operations.
The Swiss Federal Office of Justice approved Penchukov's extradition to the United States after he declined simplified extradition proceedings.
Swiss authorities arrested a Ukrainian national wanted on U.S. cybercrime charges in Geneva, later identified as Vyacheslav Penchukov. U.S. authorities accused him of extortion, bank fraud, and identity theft.
Chief Judge Denise Page Hood sentenced Pavel Stassi on June 28, 2021, to 24 months in prison and Aleksandr Skorodumov on October 20, 2021, to 48 months for their roles in a bulletproof hosting scheme used by cybercriminals.
Aleksandr Grichishkin, Andrei Skvortsov, Aleksandr Skorodumov, and Pavel Stassi pleaded guilty in the Eastern District of Michigan to a RICO conspiracy tied to bulletproof hosting services used by cybercriminals. The hosted infrastructure supported malware including Zeus, SpyEye, Citadel, and the Blackhole Exploit Kit.
Penchukov's period on the FBI Cyber Most Wanted List ended in February 2021, according to later reporting.
Ukrainian police arrested suspects during a joint international operation targeting the Egregor ransomware gang in January 2021; later reporting said Penchukov was among the suspects arrested. Trend Micro separately reported that French and Ukrainian authorities apprehended three alleged Egregor members in Ukraine during the crackdown.
Penchukov was on the FBI Cyber Most Wanted List beginning in November 2018, reflecting his wanted status in connection with cybercrime allegations.
The U.S. Department of Justice announced a multinational operation to disrupt the Gameover Zeus botnet and a related action to seize infrastructure used by CryptoLocker ransomware. Authorities also unsealed charges against alleged administrator Evgeniy Bogachev in Pittsburgh and Omaha.
A 2014 U.S. Department of Justice indictment identified Vyacheslav "Tank" Penchukov as a top figure in the JabberZeus crew.
U.S. authorities first charged Vyacheslav Penchukov in 2012 for his involvement in the Zeus malware operation, according to later Justice Department reporting.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
7 references tracked. Mallory keeps watching after this page renders.
justice.gov
Open sourcebleepingcomputer.com
Open sourcekrebsonsecurity.com
Open sourcejustice.gov
Open sourcejustice.gov
Open sourcetrendmicro.com
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.