onlinesyscfg.research
utc
syscfg://research
home/research/operation-tovar-gameover-zeus-cryptolocker-fbi
PublishedThreat History

Operation Tovar: How the FBI Killed CryptoLocker, Freed 500,000 Victims, and Still Couldn't Catch the Guy

2026-08-09-16 min read
#operation-tovar#gameover-zeus#cryptolocker#bogachev#botnet#p2p#dga#fbi#sinkhole#bitcoin#ransomware#decryptor

In June 2014, the US Department of Justice and FBI, working with law enforcement partners across Europe and private sector security firms, executed Operation Tovar - a simultaneous multi-country disruption of the Gameover Zeus botnet and the CryptoLocker ransomware infrastructure. In two weeks, they had redirected Gameover Zeus traffic by hijacking its domain generation algorithm, obtained encryption keys from the CryptoLocker command and control servers that had been seized, and made those keys freely available to victims. It was the most effective botnet disruption to that point in history.

The operation also indicted Evgeniy Bogachev, the Russian national identified as the creator and operator of Gameover Zeus. Bogachev - whose online handle was "lucky12345" and "slavik" - was already the subject of a criminal complaint. He remains one of the FBI's most wanted cybercriminals, with a $3 million reward for information leading to his arrest or conviction. He has never been charged in a Russian court and lives openly in Russia, where he reportedly knows he cannot be extradited. US intelligence has separately suggested that Bogachev was not merely a criminal but was also performing intelligence work for Russian state services - using Gameover Zeus to search compromised computers in Ukraine, Georgia, and Turkey for sensitive government documents around the time of geopolitical tensions.

What Gameover Zeus Was

Gameover Zeus (GOZ) was a successor to the original Zeus banking trojan - the same credential-stealing code that had compromised millions of banking session credentials, but architecturally redesigned. Where original Zeus used a centralized command-and-control server infrastructure (takedown one server, lose control of that portion of the botnet), Gameover Zeus used a peer-to-peer architecture. Each infected machine participated in the botnet's command network, relaying traffic and instructions. There was no single server to take down. To disrupt it, you had to either infect the machines with a counter-payload (legally and practically difficult) or overwhelm the P2P routing by controlling enough peer nodes to redirect the botnet's traffic.

Gameover Zeus also included a domain generation algorithm (DGA) as a fallback mechanism. If the P2P network was disrupted, the botnet would begin querying algorithmically generated domain names until it found one that resolved to an attacker-controlled server. This provided a second communication channel even if the P2P network failed.

The botnet was used primarily for banking credential theft - stealing login credentials for business bank accounts through browser hooking and web injection, then silently initiating fraudulent wire transfers. Business accounts were preferred because the transfer limits were much higher than consumer accounts. GOZ-related losses to US businesses alone were estimated at over $100 million.

[TECHNICAL NOTE]
Gameover Zeus's P2P architecture represented a significant advance in botnet resilience engineering. Traditional centralized C2 botnets are vulnerable to sinkholing - registering or seizing the C2 domain and redirecting bot traffic to a controlled server. The P2P design made this impossible: there was no domain to sinkhole, no server to seize, no central point of failure. The Operation Tovar disruption worked differently: by registering the algorithmically predictable DGA domains before the botnet operators could, law enforcement could direct the fallback traffic (which activated when the P2P network was disrupted) to their own sinkhole servers. Simultaneously, by coordinating with ISPs and hosting providers in the countries where the P2P relay nodes were concentrated, they could disrupt the P2P routing. The two-week disruption window was not a permanent takedown - it was a window designed to give users time to clean their machines before the botnet operators could reconstitute the P2P network and reclaim DGA domains. CrowdStrike and other private sector partners provided the technical infrastructure for the sinkhole operation. The GOZ operation became a template for public-private partnership in botnet disruption, specifically the model of coordinating sinkhole operations with ISP notification and simultaneous victim-side cleanup tools.

CryptoLocker and the Key Recovery

CryptoLocker was a ransomware that used Gameover Zeus for distribution - infected machines in the GOZ botnet could receive CryptoLocker as a secondary payload. CryptoLocker's technical implementation was novel for 2013: it used genuine asymmetric cryptography (RSA-2048) with the private key stored on the attacker's C2 server. Previous ransomware had used symmetric encryption or fake encryption; CryptoLocker's encryption was real and the files were genuinely unrecoverable without the key. It demanded payment in Bitcoin or prepaid cards within 72-96 hours before deleting the private key.

The Operation Tovar seizure of CryptoLocker's C2 infrastructure gave law enforcement access to the database of private keys. The FBI and its partners worked with Fox-IT and FireEye to build a free service - DecryptCryptoLocker.com - through which victims could upload an encrypted file and receive the decryption key. This was an unprecedented step: rather than holding seized criminal evidence, law enforcement used it directly to remediate victims. Approximately 500,000 CryptoLocker victims had their files encrypted; the key recovery service provided relief to those who still had their encrypted files.

[WARNING]
Operation Tovar illustrated the time-bounded nature of law enforcement botnet actions. The disruption of Gameover Zeus was effective for approximately two weeks - the time window the FBI publicly announced in advance, asking users to clean their machines. This transparency about the limited window was unusual and operationally sound: victims needed to know why and how long they had to act. But the window also made clear to Bogachev and his associates exactly when they needed to reconstitute their infrastructure. The botnet did partially recover after the two-week window, though at reduced scale. CryptoLocker as a specific family never fully reconstituted - the infrastructure seizure was more damaging to it than to the GOZ botnet itself. However, the CryptoLocker model was immediately cloned by other ransomware operators; TorrentLocker, CryptoWall, and dozens of other families appeared within months, copying the asymmetric encryption model and Bitcoin payment mechanism. You can disrupt a criminal operation; you cannot unlearn a criminal technique once it has been demonstrated to work at scale. The ransomware industry that exists today is built on the CryptoLocker proof of concept.

Bogachev and the Intelligence Question

The US indictment of Bogachev described a criminal operation with sophisticated money laundering infrastructure - proceeds from GOZ banking fraud moved through money mule accounts, cryptocurrency, and international wire transfers. But separate intelligence reporting, first published by Reuters in 2015, suggested that Bogachev's operation had an intelligence dimension beyond criminal profit.

US intelligence sources suggested that Gameover Zeus was used to search compromised computers in Ukraine, Georgia, and Turkey for sensitive government and military documents - specifically timed to periods of geopolitical tension (the 2013-2014 Maidan protests and the 2008 Russia-Georgia war). If accurate, this would mean Bogachev was either working for or selling intelligence to Russian state services alongside running his criminal operation. The FBI's reward for Bogachev is explicitly for information leading to his arrest or conviction - not for intelligence, suggesting the US government views him primarily as a criminal. But the dual-use hypothesis - criminal cyber operation as intelligence collection platform - has become a template for understanding Russian state-criminal relationships.

[IOC]
Operation Tovar summary: executed June 2, 2014. Target: Gameover Zeus P2P botnet (estimated 500,000-1,000,000 infected machines globally) and CryptoLocker ransomware infrastructure. Method: pre-registration of DGA domains to sinkhole fallback traffic; coordination with ISPs to disrupt P2P node routing; simultaneous seizure of CryptoLocker C2 servers in multiple countries. Law enforcement participants: FBI, Europol, NCA (UK), law enforcement from Netherlands, Germany, France, Ukraine, Luxembourg, and others. Private sector participants: CrowdStrike, Dell SecureWorks, McAfee, Microsoft, Symantec, F-Secure, Trend Micro, others. CryptoLocker key recovery: approximately 500,000 victims' keys recovered; DecryptCryptoLocker.com service operated by Fox-IT and FireEye. GOZ banking fraud losses: estimated $100M+ (US businesses); total global losses estimated at $1B+. Operator: Evgeniy Bogachev (lucky12345/slavik), Russian national, resident of Anapa, Russia. US Federal charges: Computer Fraud and Abuse Act, wire fraud, bank fraud, money laundering. Bogachev reward: $3 million for information leading to arrest or conviction. Status: at liberty in Russia; not extradited as of mid-2025. The ransomware industry spawned by CryptoLocker has caused estimated losses of $20-30 billion annually by the 2020s.