CASE DOSSIER pleaded

U.S. v. Peter Levashov (Kelihos Botnet)

Docket: 3:17-cr-00083 Court: U.S. District Court for the District of Connecticut Opened: 2017-04-07 Sector: E-Commerce, Consumer Services, Telecommunications

Key Facts

Status
PLEADED
Legal disposition
Loss Amount
$25.0 million
Generated tens of millions in fraudulent spam income and illicit botnet lease fees.
Techniques
1
Verified mappings
Defendants
1
Named in charges
  • Legal Status: PLEADED in U.S. District Court for the District of Connecticut.
  • Primary Target Sector: E-Commerce, Consumer Services, Telecommunications.
  • Documented Financial Loss: $25.0 million.
  • 1 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Russian operator (Severa) of the notorious Kelihos botnet, controlling over 100,000 infected computers worldwide used to harvest credentials, distribute ransomware, and blast billions of spam and stock pump-and-dump emails daily.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Unauthorized intrusion originating from targeted infiltration directed against E-Commerce, Consumer Services, Telecommunications networks. Russian operator (Severa) of the notorious Kelihos botnet, controlling over 100,000 infected computers worldwide used to harvest credentials, distribute ransomware, and blast billions of spam and stock pump-and-dump emails daily.

Operational & Financial Fallout

Generated tens of millions in fraudulent spam income and illicit botnet lease fees. Impacted E-Commerce, Consumer Services, Telecommunications infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: PLEADED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Unauthorized intrusion originating from targeted infiltration directed against E-Commerce, Consumer Services, Telecommunications networks. Russian operator (Severa) of the notorious Kelihos botnet, controlling over 100,000 infected computers worldwide used to harvest credentials, distribute ransomware, and blast billions of spam and stock pump-and-dump emails daily.

Adversary Kill Chain Flow

2 Documented Phases
1
Phase 1: Infiltration Perimeter Ingress
MITRE ATT&CK T1190 →

Operatives secured access to victim infrastructure within the E-Commerce, Consumer Services, Telecommunications sector.

Artifacts & Tooling: Network perimeter logs
2
Phase 2: Execution Payload Deployment
MITRE ATT&CK T1486 →

Russian operator (Severa) of the notorious Kelihos botnet, controlling over 100,000 infected computers worldwide used to harvest credentials, distribute ransomware, and blast billions of spam and stock pump-and-dump emails daily.

Artifacts & Tooling: Malicious payload
Real-World Blast Radius & Operational Fallout

Generated tens of millions in fraudulent spam income and illicit botnet lease fees. Impacted E-Commerce, Consumer Services, Telecommunications infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2017-04-07 arrest

Levashov arrested while vacationing in Barcelona, Spain, by Spanish National Police.

2018-02-02 extradition

Extradited from Spain to the District of Connecticut.

2018-09-12 plea

Pleads guilty to wire fraud, computer fraud, and identity theft charges.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Peter Yuryevich Levashov Russian Federation pleaded Pending None Operator of the Kelihos botnet; pleaded guilty in the District of Connecticut.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1584 Compromise Infrastructure
Resource Development
"Levashov leased out compromised zombie computers as an automated bulletproof proxy network to shield criminal infrastructure." Indictment ¶ 11, Page 5 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Peter Levashov (Kelihos Botnet), No. 3:17-cr-00083 (U.S. District Court for the District of Connecticut 2017), https://cybercaselibrary.com/cases/us-v-levashov-kelihos-botnet/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-levashov-kelihos-botnet" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>