In June 2014, the FBI and Department of Justice announced "Operation Tovar" - a coordinated multinational law enforcement action that had successfully dismantled the GameOver Zeus botnet and the Cryptolocker ransomware operation it distributed. Both were operated by the same criminal infrastructure under the control of a Russian national named Evgeniy Mikhailovich Bogachev. The takedown involved law enforcement from the US, UK, Canada, Australia, and a dozen European countries, working with private sector partners including Microsoft, Symantec, CrowdStrike, Dell SecureWorks, Trend Micro, and Shadowserver.
At the time of the takedown, GameOver Zeus was estimated to have infected between 500,000 and 1,000,000 computers worldwide. It had stolen approximately $100 million from businesses and consumers since 2011. The ransomware it distributed, CryptoLocker, had extorted approximately $27 million from victims before it was disrupted. These numbers made Bogachev the most prolific financial cybercriminal the FBI had ever charged. The $3 million reward the US government offered for information leading to his arrest - the largest cybercrime bounty in history at the time - has never been collected. As of this writing, Bogachev remains at large in Russia, where he is believed to reside openly.
What Made GameOver Zeus Different
Zeus was a banking trojan first documented in 2007. The original Zeus code was used to steal banking credentials, intercept browser sessions with financial institutions, and initiate fraudulent transfers. Bogachev's team didn't create Zeus - they licensed or obtained the source code (which leaked publicly in 2011) and built something substantially more sophisticated: a peer-to-peer variant that removed the centralized command-and-control bottleneck.
Standard botnets communicate with a central C2 server. If law enforcement seizes or blocks that server, the botnet goes dark. GameOver Zeus used a P2P overlay network - infected machines communicated directly with each other to relay commands, with no single point of failure. Modules were distributed across the peer network. To take down GameOver Zeus, you couldn't just seize one server. You had to perform a "sinkholing" operation - redirect enough of the P2P traffic to servers under your control that the botnet lost cohesion. This required coordination across hundreds of ISPs and registrars worldwide to seize or redirect the domain names used in the botnet's bootstrap process.
GameOver Zeus also used a domain generation algorithm (DGA) as a fallback - if P2P communication failed, infected machines would calculate a list of pseudo-random domain names and attempt to connect to them. By knowing the DGA algorithm (reverse-engineered from the malware), researchers could pre-register domains the malware would try to contact, creating another sinkhole layer. The combination of P2P and DGA made GameOver Zeus resilient against single-point takedowns, requiring the multi-year multinational effort that eventually succeeded.
The Intelligence Dimension
The GameOver Zeus investigation revealed something that significantly complicated its law enforcement handling: Bogachev appeared to be using his botnet access for Russian intelligence collection, not just financial crime. GameOver Zeus gave Bogachev persistent access to hundreds of thousands of machines worldwide. FBI analysis found that the botnet had been used to search compromised machines in countries including Turkey, Georgia, and Ukraine for documents related to foreign intelligence topics - specifically, in the period before Russia's 2014 annexation of Crimea, the botnet was being used to search infected machines in Eastern Ukraine and Georgia for documents related to military operations and government activities.
This dual use - financial crime as a business, intelligence collection as a side operation with plausible value to Russian state interests - created a diplomatic and law enforcement problem. A purely criminal actor can be pressured for extradition. An actor with apparent utility to Russian intelligence is a different calculation for the Russian government. The FBI's willingness to keep Bogachev's reward active at $3 million (later increased to $3 million by other agencies) reflected the continuing belief that he remains accessible in Russia and that Russia has chosen not to act on extradition requests.
Bogachev was charged by the DOJ with conspiracy, wire fraud, bank fraud, money laundering, and computer fraud. His online handle was "lucky12345" and "Slavik." He had previously operated the Zeus trojan infrastructure, the Jabber Zeus crew, and other banking malware operations going back to at least 2009. By the time of the GameOver Zeus takedown, he had been active in financial cybercrime for five years. After the 2014 disruption, there was no successor botnet attributed to Bogachev himself - the assumption is that his operational value had shifted, or he moved resources.
The Sinkholing Operation
Operation Tovar's technical execution took over a year of preparation. The multinational team needed to simultaneously seize or redirect the domain names used in GameOver Zeus's DGA fallback, coordinate with hundreds of ISPs to block or redirect P2P traffic, and ensure that the sinkhole infrastructure could handle the expected volume of traffic from hundreds of thousands of redirected bots without itself being overwhelmed.
The FBI gave affected users approximately two weeks of disruption window - the period during which the sinkhole redirected infected machines, allowing security researchers to notify victims and offering removal tools. Because the botnet P2P structure allowed the operators to rebuild it if they regained control of enough nodes, the window was inherently temporary. After the sinkhole operation concluded, Bogachev's infrastructure attempted to rebuild. Security researchers tracked the reconstruction effort; within months a smaller version of the botnet had re-formed, though never to the scale of the original.
CryptoLocker was more thoroughly disrupted. The takedown included seizing the command infrastructure used to store the RSA private keys. After the seizure, Bitdefender, FireEye, and Fox-IT were able to extract keys from the seized infrastructure and create a free decryption tool at decryptcryptolocker.com. Victims who had not paid and still had their encrypted files could recover them. The tool was used by hundreds of thousands of victims.