A Russian national accused of developing a piece of malware named NLBrute has been extradited to the United States from the Eastern European country of Georgia.
The suspect, Dariy Pankov, aka dpxaker, was extradited from Georgia in October 2022 and he appeared before a US judge this week. It’s unclear for how long he had been in Georgia before being detained, but more than 100,000 Russians reportedly fled to the neighboring country last year, often in an effort to avoid being drafted into Russia’s armed forces as the country wages its war against Ukraine.
Pankov has been charged with computer fraud, conspiracy, and access device fraud, and faces up to 47 years in prison. The man will remain in custody during his trial.
According to the Justice Department, Pankov made at least $350,000 from cybercrime activities between 2016 and 2019. He is believed to have developed and sold NLBrute, a tool that has been widely used by cybercriminals to obtain credentials.
The fact that NLBrute was created by a Russian developer has been known. The tool is designed for brute-forcing RDP credentials and at one point it was used in tandem with a botnet in an effort to distribute the brute-forcing process.
US authorities said Pankov used the malware to obtain login credentials for tens of thousands of computers around the world, and offered to sell 35,000 credentials on a cybercrime forum.
Two law firms in Florida are mentioned as victims in the indictment, but they have not been named.
US authorities said they also plan on forfeiting more than $350,000 that can be traced to the proceeds of Pankov’s crimes.
In addition to the Pankov extradition, the DoJ announced this week that two men from Maryland have been sentenced to a combined 14 years in prison for laundering money as part of a business email compromise (BEC) scheme.
Related: Russian Businessman Guilty in Hacking, Insider Trade Scheme
Related: Russian National Arrested in Canada Over LockBit Ransomware Attacks
Related: Russian Man Extradited to US for Laundering Ryuk Ransomware Money

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
More from Eduard Kovacs
- Thousands Access Fake DDoS-for-Hire Websites Set Up by UK Police
- Intel Boasts Attack Surface Reduction With New 13th Gen Core vPro Platform
- Dole Says Employee Information Compromised in Ransomware Attack
- High-Severity Vulnerabilities Found in WellinTech Industrial Data Historian
- CISA Expands Cybersecurity Committee, Updates Baseline Security Goals
- Exploitation of 55 Zero-Day Vulnerabilities Came to Light in 2022: Mandiant
- Organizations Notified of Remotely Exploitable Vulnerabilities in Aveva HMI, SCADA Products
- Waterfall Security, TXOne Networks Launch New OT Security Appliances
Latest News
- 14 Million Records Stolen in Data Breach at Latitude Financial Services
- Webinar Today: Understanding Hidden Third-Party Identity Access Risks
- Thousands Access Fake DDoS-for-Hire Websites Set Up by UK Police
- iOS Security Update Patches Exploited Vulnerability in Older iPhones
- Microsoft: No-Interaction Outlook Zero Day Exploited Since Last April
- US to Adopt New Restrictions on Using Commercial Spyware
- Hackers Earn Over $1 Million at Pwn2Own Exploit Contest
- GoAnywhere Zero-Day Attack Hits Major Orgs
