Cybercrime

Ukrainian Pleads Guilty in US to Key Role in Zeus, IcedID Malware Operations

Ukrainian national Vyacheslav Igorevich Penchukov has pleaded guilty to holding key roles in the Zeus and IcedID malware operations.

Ukrainian national Vyacheslav Igorevich Penchukov has pleaded guilty to holding key roles in the Zeus and IcedID malware operations.

The US Department of Justice announced on Thursday that a Ukrainian national has pleaded guilty to charges related to his role in two major malware operations.

The defendant, Vyacheslav Igorevich Penchukov, aka ‘Tank’, was on the FBI’s Cyber Most Wanted List until 2022, when he was arrested in Switzerland. 

He was extradited to the United States last year and he has now pleaded guilty to RICO and wire fraud charges related to his leadership role in separate cybercrime operations involving the Zeus and IcedID malware.

US authorities have accused Penchukov of helping lead the Zeus operation starting in May 2009. The trojan is said to have infected millions of devices, including thousands of business computers, enabling cybercriminals to obtain personal and banking information that could be used to make unauthorized transfers from victims’ bank accounts.

Law enforcement cracked down on cybercriminals using the Zeus malware in 2010, and Zeus botnets were targeted by Microsoft in 2012, but the malware continued making headlines in the coming years.

Investigators believe Penchukov had a leadership position in the IcedID malware operation between at least November 2018 and February 2021. IcedID enabled cybercriminals to steal banking and personal information, and could also be used to deliver other malware to compromised computers, including ransomware.

The Justice Department said the Zeus and IcedID malware operations caused tens of millions of dollars in losses. 

Penchukov’s sentencing is scheduled for May 9. He faces up to 20 years in prison for each count. 

Advertisement. Scroll to continue reading.

Related: Man Sentenced to Prison for Stealing Millions in Cryptocurrency via SIM Swapping 

Related: JFK Airport Taxi Hackers Sentenced to Prison

Related: DraftKings Hacker Sentenced to 18 Months in Prison

Related Content

Malware & Threats

Threat actors are using DNS tunneling to track victims’ interaction with spam and to scan network infrastructures.

Malware & Threats

A new Android trojan named Brokewell can steal user’s sensitive information and allows attackers to take over devices.

Malware & Threats

A North Korea-linked threat actor hijacked the update mechanism of eScan antivirus to deploy backdoors and cryptocurrency miners.

Malware & Threats

A threat actor tracked as CoralRaider has been using multiple infostealers to harvest credentials from users worldwide.

Malware & Threats

Russia-linked APT28 deploys the GooseEgg post-exploitation tool against numerous US and European organizations.

Malware & Threats

Checkmarx warns of a new attack relying on GitHub search manipulation to deliver malicious code.

Malware & Threats

Human Security identifies 28 VPN applications for Android and an SDK that turn devices into proxies.

Malware & Threats

A suspicious NuGet package likely targets developers working with technology from Chinese firm Bozhon.

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version