U.S. and European authorities dismantled the GozNym cybercrime network, unsealing charges against 10 alleged members and coordinating arrests, extraditions, and prosecutions across the United States, Georgia, Ukraine, Moldova, Germany, and Bulgaria with support from Europol and Eurojust. Officials said the group operated as a cybercrime-as-a-service enterprise, combining malware development, phishing spam, crypting, bulletproof hosting, account takeover, and cash-out roles to target primarily U.S. businesses and financial institutions, while some suspects remained fugitives.
Investigators said GozNym infected more than 41,000 computers and was used in roughly $100 million in attempted fraud against victims in the United States and elsewhere. The malware was distributed through the Avalanche criminal infrastructure, a fast-flux botnet platform previously used by more than 20 malware families before its takedown, and Shadowserver said its sinkholing and victim-remediation reporting had helped protect about 2 million victim IP addresses daily in the years following that operation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Authorities in the United States, Georgia, Ukraine, Moldova, Germany, Bulgaria, Europol, and Eurojust coordinated arrests, prosecutions, and evidence sharing to dismantle the GozNym cybercriminal network. Five suspects were arrested while five Russian nationals remained fugitives at the time of the announcement.
U.S. prosecutors unsealed an indictment charging 10 members of the GozNym network, while European and U.S. partners announced coordinated action against the group. Authorities said the malware infected more than 41,000 computers and was used in about $100 million in attempted fraud.
Krasimir Nikolov pleaded guilty in federal court in Pittsburgh to charges related to the GozNym conspiracy.
While extradition proceedings were still underway, Farkhad Manokhin absconded from Sri Lanka and fled back to Russia.
Farkhad Rauf Ogly Manokhin, an alleged GozNym cash-out operator, was arrested in Sri Lanka at the request of the United States.
Bulgarian authorities arrested alleged GozNym conspirator Krasimir Nikolov and extradited him to the United States in connection with the cybercrime case.
Authorities took down the Avalanche criminal malware delivery platform, which had provided fast-flux command-and-control services for more than 20 malware strains including GozNym.
3 references tracked. Mallory keeps watching after this page renders.
justice.gov
Open sourceshadowserver.org
Open sourceeuropol.europa.eu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.