US, European officials bring charges in global malware case

The attacks infected tens of thousands of computers and sought to steal $100 million from victims.

  • By ERIC TUCKER Associated Press
  • Thursday, May 16, 2019 3:31pm
  • Business

By Eric Tucker / Associated Press

WASHINGTON — Ten people, including five Russian fugitives, have been charged in connection with malicious software attacks that infected tens of thousands of computers worldwide and sought to steal $100 million from victims, U.S. and European authorities announced Thursday.

The malware enabled criminals from Eastern Europe to take remote control of infected computers and siphon funds from victims’ bank accounts, and targeted companies and institutions across all sectors of American life. Victims included a Washington law firm, a church in Texas, a furniture business in California, a casino in Mississippi and a Pennsylvania asphalt and paving business.

Several defendants are awaiting prosecution in Europe, and five are Russians who remain fugitives in that country. An 11th participant in the conspiracy was extradited to the United States from Bulgaria in 2016 and pleaded guilty last month in a related case in federal court in Pittsburgh, where Thursday’s indictment was brought.

Though the Justice Department has pursued multiple malware prosecutions in recent years against foreign hackers, this case stands out as a novel model of international collaboration , said Scott Brady, the U.S. attorney in Pittsburgh.

Instead of seeking the immediate extradition of all 10 defendants — an often cumbersome process that can take years of negotiations, even in countries that have treaties with the U.S. — American authorities shared evidence with their European counterparts to allow officials in Ukraine, Moldova and Georgia to initiate prosecutions in the nations where the defendants reside.

“It represents a paradigm change in how we prosecute cybercrime,” Brady said in an interview with The Associated Press before a news conference in The Hague with a coalition of a half-dozen countries.

Cybercrime networks “are increasingly targetable” when investigators work together, Robert Jones, the FBI special agent in charge of the Pittsburgh office, said at the news conference. “International cooperation is no longer a nicety, it’s a requirement,” he said.

Other law enforcement officials also said the strategy represents the new face of combating high-tech crime.

Cybercrime has no borders, and criminals have taken advantage of the legal complexities of trying to fight it, said Steven Wilson, head of the European CyberCrime Centre at Europol. “Only through international cooperation can we hope to tackle it,” he said, adding the charges “provide for a safer internet for all of us.”

The charges in the indictment include conspiracy to commit computer fraud, conspiracy to commit wire and bank fraud and conspiracy to commit money laundering.

The investigation was an outgrowth of the Justice Department’s dismantling in 2016 of a network of computer servers, known as Avalanche, which hosted more than 20 different types of malware. GozNym, the malware cited in Thursday’s case, was among the ones hosted on the network and was designed to automate the theft of sensitive personal and financial information.

Law enforcement officials say it was formed by the defendants as they advertised their technical skills in underground, Russian-language online criminal forums. The defendants had different roles within the conspiracy: including developing the malware, encrypting it so it could avoid detection by anti-virus software, mass distributing the spam emails and sneaking in to the victims’ bank accounts.

The leader of the network, authorities say, was from Tbilisi, Georgia, and leased access to the malware from a developer, who in turn worked with coders to create GozNym.

“For the past three years, we have been unpeeling an onion as it were that is very challenging to investigate and identify,” Brady said.

GozNym controlled more than 41,000 computers, officials said. The malware relied on spam emails, disguised as legitimate messages, that once opened enabled the malware to be downloaded onto the machines. From there, the hackers were able to record keystrokes from the victims’ computers, steal banking log-in credentials and then launder the stolen money into foreign bank accounts they controlled.

Brady said prosecutors always look to recover stolen funds, but that is especially challenging in international cybercrime cases.

“Proceeds were converted to bitcoin and without the private key, it is really hard to identify and access, let alone seize, those accounts,” Brady told the AP.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Business

FILE — Jet fuselages at Boeing’s fabrication site in Everett, Wash., Sept. 28, 2022. Some recently manufactured Boeing and Airbus jets have components made from titanium that was sold using fake documentation verifying the material’s authenticity, according to a supplier for the plane makers. (Jovelle Tamayo/The New York Times)
Boeing adding new space in Everett despite worker reduction

Boeing is expanding the amount of space it occupies in… Continue reading

Paul Roberts makes a speech after winning the Chair’s Legacy Award on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
Paul Roberts: An advocate for environmental causes

Roberts is the winner of the newly established Chair’s Legacy Award from Economic Alliance Snohomish County.

Laaysa Chintamani speaks after winning on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
Laasya Chintamani: ‘I always loved science and wanted to help people’

Chintamani is the recipient of the Washington STEM Rising Star Award.

Dave Somers makes a speech after winning the Henry M. Jackson Award on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
County Executive Dave Somers: ‘It’s working together’

Somers is the recipient of the Henry M. Jackson Award from Economic Alliance Snohomish County.

Mel Sheldon makes a speech after winning the Elson S. Floyd Award on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
Mel Sheldon: Coming up big for the Tulalip Tribes

Mel Sheldon is the winner of the Elson S. Floyd Award from Economic Alliance Snohomish County

Craig Skotdal makes a speech after winning on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
Craig Skotdal: Helping to breathe life into downtown Everett

Skotdal is the recipient of the John M. Fluke Sr. award from Economic Alliance Snohomish County

The Coastal Community Bank branch in Woodinville. (Contributed photo)
Top banks serving Snohomish County with excellence

A closer look at three financial institutions known for trust, service, and stability.

Image from Erickson Furniture website
From couch to coffee table — Local favorites await

Style your space with the county’s top picks for furniture and flair.

2025 Emerging Leader winner Samantha Love becomes emotional after receiving her award on Tuesday, April 8, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Samantha Love named 2025 Emerging Leader for Snohomish County

It was the 10th year that The Herald Business Journal highlights the best and brightest of Snohomish County.

2025 Emerging Leader Tracy Nguyen (Olivia Vanni / The Herald)
Tracy Nguyen: Giving back in her professional and personal life

The marketing director for Mountain Pacific Bank is the chair for “Girls on the Run.”

2025 Emerging Leader Kellie Lewis (Olivia Vanni / The Herald)
Kellie Lewis: Bringing community helpers together

Edmonds Food Bank’s marketing and communications director fosters connections to help others.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.