Monday, March 3, 2025
HomeComputer SecurityRussian Hacker Who Operated Kelihos Botnet Pleads Guilty in US Federal Court

Russian Hacker Who Operated Kelihos Botnet Pleads Guilty in US Federal Court

Published on

SIEM as a Service

Follow Us on Google News

A Russian man who operates Kelihos Botnet Pleads in U.S. Federal Court to Fraud, Conspiracy, Computer Crime and Identity Theft Offenses.

Peter Levashov operated the botnet for decades to facilitate the malicious activities such as credentials harvesting, bulk spam e-mails, Delivering ransomware and other malware’s.

U.S. Attorney Durham said, “Mr. Levashov used the Kelihos botnet to distribute thousands of spam e-mails, harvest login credentials, and install malicious software on computers around the world.” He also participated in online forums to sell the stolen identities such as credit card information and another cybercrime tool.

Kelihos Botnet

The Kelihos botnet first appeared in December 2010, it is also known as a peer-to-peer botnet, it empowers every individual node to go about as a Command and Control server.

The first version of the botnet performed denial-of-service attacks and email spam, with the later version threat actors, added ability to steal Bitcoin wallets to mine cryptocurrencies.

Peter Levashov was arrested on April 7, 2017, in Barcelona by Spanish authorities based on the complaint and arrest warrant issued by the U.S District Court. At the time of arrest, Kelihos had at least 50,000 computers in botnet chain.

“Levashov lived quite comfortably while his criminal behavior disrupted the lives of thousands of computer users and today justice has finally arrived for Peter Levashov,” said FBI Special Agent in Charge Turner.

Levashov pleaded guilty before U.S. District Judge Robert N. Chatigny for damage to a protected computer, one count of conspiracy, one count of wire fraud and one count of aggravated identity theft. He is due to be sentenced on 6-Sept-2019 reads DoJ press release.

Related Read

Raise of IoT Botnets Responsible for Massive DDoS Attacks – Q2 2018 Threat Report

Android Based Malicious CryptoMiner Spreading by Worm that has Infected more than 5,000 devices in 24 hours

Ursnif Malware Variant Performs Malicious Process Injection in Memory using TLS Anti-Analysis Evasion Trick

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Threat Actors Exploiting AES Encryption for Stealthy Payload Protection

Cybersecurity researchers have uncovered a surge in the use of Advanced Encryption Standard (AES)...

33.3 Million Cyber Attacks Targeted Mobile Devices in 2024 as Threats Surge

Kaspersky's latest report on mobile malware evolution in 2024 reveals a significant increase in...

Routers Under Attack as Scanning Attacks on IoT and Networks Surge to Record Highs

In a concerning trend, the frequency of scanning attacks targeting Internet of Things (IoT)...

Google Launches Shielded Email to Keep Your Address Hidden from Apps

Google is rolling out a new privacy-focused feature called Shielded Email, designed to prevent apps...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

INDOHAXSEC Hacker Group Allegedly Breaches Malaysia’s National Tuberculosis Registry

The Indonesian hacker group "INDOHAXSEC" has allegedly breached the National Tuberculosis Registry (NTBR) of...

Is this Website Safe: How to Check Website Safety – 2025

is this website safe? In this digital world, Check a website is safe is...

Firefox 133.0 Released with Multiple Security Updates – What’s New!

Mozilla has officially launched Firefox 133.0, offering enhanced features, significant performance improvements, and critical...