Cybercrime

Ukrainian Pleads Guilty in US to Key Role in Zeus, IcedID Malware Operations

Ukrainian national Vyacheslav Igorevich Penchukov has pleaded guilty to holding key roles in the Zeus and IcedID malware operations.

Ukrainian national Vyacheslav Igorevich Penchukov has pleaded guilty to holding key roles in the Zeus and IcedID malware operations.

The US Department of Justice announced on Thursday that a Ukrainian national has pleaded guilty to charges related to his role in two major malware operations.

The defendant, Vyacheslav Igorevich Penchukov, aka ‘Tank’, was on the FBI’s Cyber Most Wanted List until 2022, when he was arrested in Switzerland. 

He was extradited to the United States last year and he has now pleaded guilty to RICO and wire fraud charges related to his leadership role in separate cybercrime operations involving the Zeus and IcedID malware.

US authorities have accused Penchukov of helping lead the Zeus operation starting in May 2009. The trojan is said to have infected millions of devices, including thousands of business computers, enabling cybercriminals to obtain personal and banking information that could be used to make unauthorized transfers from victims’ bank accounts.

Law enforcement cracked down on cybercriminals using the Zeus malware in 2010, and Zeus botnets were targeted by Microsoft in 2012, but the malware continued making headlines in the coming years.

Investigators believe Penchukov had a leadership position in the IcedID malware operation between at least November 2018 and February 2021. IcedID enabled cybercriminals to steal banking and personal information, and could also be used to deliver other malware to compromised computers, including ransomware.

Advertisement. Scroll to continue reading.

The Justice Department said the Zeus and IcedID malware operations caused tens of millions of dollars in losses. 

Penchukov’s sentencing is scheduled for May 9. He faces up to 20 years in prison for each count. 

Related: Man Sentenced to Prison for Stealing Millions in Cryptocurrency via SIM Swapping 

Related: JFK Airport Taxi Hackers Sentenced to Prison

Related: DraftKings Hacker Sentenced to 18 Months in Prison

Related Content

Malware & Threats

The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions.

Malware & Threats

The attackers impersonate at least 40 companies and disable 145 security products to deploy infostealer malware.

Malware & Threats

Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts.

Malware & Threats

US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C.

Malware & Threats

Ads led to a ClickFix page designed to trick macOS and Windows users into installing malware.

Malware & Threats

The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.

Cybercrime

The defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash.

Artificial Intelligence

The AI giant is logging customers out of their accounts and removing payment data to prevent unauthorized Claude usage.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version