Threat Picture
Latest Cybersecurity News

Evgeniy Bogachev: The Hunt Behind the GameOver Zeus Case

U.S. investigators linked him to a banking botnet built to resist takedowns. Operation Tovar brought an international effort to disrupt it.
By Charles Joseph · Updated
Share
Share
Copy URL

The FBI knows exactly where Evgeniy Bogachev lives. He has a large apartment near the shore in Anapa, a resort town on Russia's Black Sea coast, a collection of cars, a yacht and a lawyer who politely declines to comment.

He also has a $3 million bounty on his head, the largest the United States has ever offered for a cybercriminal. The man the bureau calls Slavik wrote Zeus, the banking trojan that emptied accounts on three continents, and ran GameOver Zeus, the botnet that stole more than $100 million and spread the ransomware that taught the world the word.

Nobody has ever arrested him, and the strangest part of the story is why.

Evgeniy Bogachev at a Glance

  • Born on October 28, 1983, Bogachev was known online as "slavik" and "lucky12345" long before anyone knew his real name.
  • Zeus appeared around 2006 and became the most popular bank-fraud kit in the criminal underground, sold to hundreds of crews who stole from victims' own computers.
  • In 2010 he announced his retirement, then quietly built a private, peer-to-peer version for an inner circle that called itself the Business Club.
  • GameOver Zeus launched in September 2011 and infected up to a million computers, while in 2013 the gang used it to spread CryptoLocker, the ransomware that made bitcoin extortion mainstream.
  • An FBI rookie in Omaha first pulled the thread in 2009, and a 2012 Nebraska indictment named only a handle, "lucky12345."
  • On June 2, 2014, Operation Tovar seized the botnet and unsealed charges against Bogachev by name in Pittsburgh.
  • The State Department put up a $3 million reward in February 2015, and the Treasury sanctioned him in December 2016.
  • He lives openly in Anapa. Russia has no extradition treaty with the US, and investigators believe its intelligence services were quietly using his botnet to spy.
Sponsored

The Life of Evgeniy Bogachev

Bogachev's Black Sea Years

Evgeniy Mikhailovich Bogachev was born on October 28, 1983, and the FBI's file on him is thin on childhood. He's from Anapa, a faded resort on the Black Sea in the Krasnodar region, works "in the information technology field," enjoys boating and, in the one photograph everyone has seen, holds a spotted Bengal cat while wearing matching leopard-print pajamas.

Even his closest criminal associates never met him or knew his name. "He was very, very paranoid," said J. Keith Mularski, the FBI supervisor in Pittsburgh whose investigation eventually led to his indictment. "He didn't trust anybody."

What they knew was his code.

Zeus

Zeus first appeared around 2006 and quickly earned a reputation as a masterpiece: smooth, versatile and brutally effective. It arrived as a fake IRS email or a bogus shipping notice, and once installed it sat inside the browser, logging keystrokes and rewriting bank login pages on the fly to ask for extra details like a Social Security number.

Bitdefender Total Security: One Year of Protection for Five Devices
  • Multi-layer malware and ransomware defense, webcam and microphone monitoring, anti-phishing and a hardened banking browser for Windows, Mac, iOS and Android. The code ships on a card.

The author sold it on underground forums to anyone with money, and thousands of freelance crooks used it to drain accounts and move the cash through "money mules." Security researchers knew him only as Slavik.

In the spring of 2009, a rookie FBI agent in Omaha named James Craig caught two odd cases: a First Data subsidiary lost $450,000 in May, and a client of the First National Bank of Omaha lost $100,000.

The thefts came from the victims' own computers, using their own passwords. Both machines were infected with Zeus. The hunt had begun.

Sponsored

The Fake Retirement

In late 2010, Slavik announced he was retiring. It was a feint. He'd already built a private, customized version and gathered a tight inner circle, a half-dozen core members and around 50 helpers, who called themselves the Business Club.

VICE News: How the Business Club Took $100 Million From US Banks
VICE News on the Russian crews that pulled $100 million out of American banks, and the question of whether hackers who do double duty for the Kremlin get a pass. Over half a million views.

In September 2011 the new version went live. GameOver Zeus ran on a peer-to-peer network with no central servers to seize, which made it nearly impossible to take down. At its peak it controlled between 500,000 and a million infected computers.

The club ran like a company. Fox-IT, which secretly got hold of its chat logs, found members working nine-to-five, Monday to Friday, following the sun from Australian banks in the morning to American ones at the end of the day. Their botnet control panel was labeled "World Bank Center," with a tagline: "We are playing with your banks."

Spam Nation: Brian Krebs Inside the Cybercrime Economy
  • Krebs's own account of the pharmacy-spam empires, the McColo takedown and the Russian forums he infiltrated to report it. The reporter's story in his own words.

Stolen wires were laundered through phony trading companies in Chinese border towns. Victims ranged from a pest control company in North Carolina to a police department in Massachusetts and a Native American tribe in Washington.

CryptoLocker

In 2013 the Business Club found a way to make money from the infected computers that weren't worth robbing. GameOver Zeus began delivering CryptoLocker, ransomware that encrypted a victim's files and demanded payment in bitcoin or prepaid vouchers for the key.

It hit more than 120,000 US victims. Estimates of the take ranged from $3 million to $27 million, but the model was the real damage. CryptoLocker proved that locking up ordinary people's photos and spreadsheets paid, and the ransomware industry that followed has never looked back.

Operation Tovar

On August 22, 2012, a federal grand jury in Nebraska indicted the man behind Zeus under the only name they had, "lucky12345." Linking the handle to a human took two more years and an unusual coalition of the FBI, foreign police agencies and private security firms, CrowdStrike and Fox-IT among them.

The Operation Tovar Team Explains the GameOver Zeus Takedown
FBI agent Elliott Peterson, Fox-IT's Michael Sandee and CrowdStrike's Tillmann Werner, three of the people behind Operation Tovar, lay out the Business Club, CryptoLocker and the legal maneuvers that pried the botnet away from Bogachev. Black Hat USA 2015.

Over the weekend of May 30 to June 2, 2014, Operation Tovar hijacked the peer-to-peer network and redirected the infected machines to servers under government control, while CryptoLocker's command servers were seized. On June 2 the Justice Department unsealed an indictment from Pittsburgh charging Bogachev with conspiracy, computer fraud, wire fraud, bank fraud and money laundering. Losses were put at more than $100 million.

"GameOver Zeus is the most sophisticated botnet the FBI and our allies have ever attempted to disrupt," said the bureau's Robert Anderson. Bogachev went straight onto the FBI's Cyber's Most Wanted list.

Sponsored

The $3 Million Man

On February 24, 2015, the State Department offered up to $3 million for information leading to his arrest, the biggest reward ever posted for a cybercriminal. Nothing happened. Russia doesn't extradite its citizens, and Russian officials said that as long as he committed no crime on Russian soil there were no grounds to arrest him.

Then, on December 29, 2016, Bogachev turned up on an unexpected list. The Obama administration, retaliating for Russian interference in the presidential election, sanctioned the GRU, the FSB, four senior intelligence officers and two cybercriminals. One was Bogachev.

60 Minutes: How the U.S. Realized Bogachev Was Also a Spy Asset
A two-minute 60 Minutes segment from 2019 on the moment American investigators understood that the thief behind GameOver Zeus was also feeding Russian intelligence, which explains the sanctions list he landed on.

Officials said publicly that it was his crimes that put him there. But the New York Times reported in 2017 that Russian intelligence had been looking over his shoulder, searching GameOver Zeus's infected computers for intelligence on the fighting in eastern Ukraine and the war in Syria and, in the United States, for anything marked "top secret." A line in his file with the Ukrainian Interior Ministry described him as working under the supervision of a special unit of the FSB.

Sale
Sandworm: Andy Greenberg on the Kremlin's Hackers
  • Greenberg's account of the GRU unit behind NotPetya and the Ukrainian grid attacks. The GRU itself was sanctioned on the same December 2016 list as Bogachev.

Untouchable in Anapa

Bogachev, now 42, has never gone into hiding. According to FBI officials he lives openly in Anapa, with a possible second apartment in Moscow, luxury cars he mostly leaves in favor of a Jeep Grand Cherokee, and a boat he takes along the Black Sea coast. A former associate told the Times he once mentioned a wife and two children and complained of being exhausted.

His lawyer in Anapa put it this way: "The fact that he is wanted by the F.B.I. prevents me morally from saying anything."

Evgeniy Bogachev: The Thief the Kremlin Kept

Bogachev's story explains the modern cybercrime economy better than any other: malware sold as a product, crews run like companies, ransomware born from the leftovers of bank fraud, and a state that found a criminal's botnet more useful than a criminal's arrest.

Today he's still listed on the FBI's most wanted page, still the subject of a $3 million reward, and still, by every account, enjoying the Black Sea.

The reward is real. So, apparently, is the protection.

QUOTE:

"Amateurs hack systems, professionals hack people."