Skip to main content
Back to the takedown index

Dridex/Bugat/Cridex disruption

October 2015, Malware and botnets
Led by Federal Bureau of Investigation, National Crime Agency

Extended pass entry, last reviewed August 21, 2026

What was taken down?

Botnet infrastructure sinkholed/disrupted; UK technical action plus a US civil restraining order/injunction redirected portions of the infrastructure.

See what happened

What happened to the people?

Officials reported 1 charged and 1 apprehended.
1 charged and 1 apprehended named in the public record.
Group accounted for: Partial

See people and accountability

Did it stay down?

Not established in the public record. No later activity is recorded against this entry.

See what happened afterward

FBI/DOJ and UK NCA, with international partners, sinkholed and disrupted infrastructure for the Dridex banking-malware botnet; alleged administrator Andrey Ghinkul was federally charged and arrested in Cyprus at US request.

Date
October 2015
Target
Dridex (also known as Bugat/Cridex), banking trojan botnet
Activity
Malware and botnets
Operational lead
FBI and NCA
Jurisdiction
Not established
Outcome
Botnet infrastructure sinkholed/disrupted; UK technical action plus a US civil restraining order/injunction redirected portions of the infrastructure.
Status
Completed
Legal mechanism
Federal criminal charges; civil restraining order/injunction; UK technical action.
Group accounted for
Partial

1
charged
1
apprehended

Named in the public record: 1 charged and 1 apprehended.

Figures count individuals named in charging documents and official statements, each person once per outcome. People alleged to be involved but not publicly identified are not counted.

Reported and named. Officials reported 1 charged and 1 apprehended. 1 charged and 1 apprehended named in the public record. The two figures come from different places and are never added together. Officials publish a headline total, and this index counts only the individuals it can name from the cited record.
Person Role Current public status
Alleged administrator of Dridex ArrestedCharged
Charging authority
Federal Bureau of Investigation
Main charges
Conspiracy; Computer fraud; Bank fraud
Case number
Not established in the public record
Arresting authority
Not established in the public record
Arrest location
Cyprus
Extradition status
Not established in the public record
Conviction or plea
Not established in the public record
Sentence
Not established in the public record
Segment
Core operator
Sources
[1]

Andrey Ghinkul

Alleged administrator of Dridex. Current public status: Arrested and Charged.

Charging authority
Federal Bureau of Investigation
Main charges
Conspiracy; Computer fraud; Bank fraud
Case number
Not established in the public record
Arresting authority
Not established in the public record
Arrest location
Cyprus
Extradition status
Not established in the public record
Conviction or plea
Not established in the public record
Sentence
Not established in the public record
Segment
Core operator
Sources
[1]

Rows expand to show charging authority, case identifiers, custody status, and sources.

Group accounted for: Partial

Sole named alleged administrator charged and arrested; the Dridex family and related operators persisted in later forms.

See the organizations and roles behind this action

Not established in the public record. No later activity is recorded against this entry.

Numbered markers throughout this entry link to the source that supports the claim beside them.

Official sources

  1. [1]
    Dridex botnet disrupted; administrator Andrey Ghinkul charged

    US DOJ / FBI / UK NCA, October 13, 2015, Source grade S2

    Establishes the Dridex disruption and the charge/arrest of Andrey Ghinkul in Cyprus.

    No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

Coverage note. Added from deep-research aggregation pass. Not independently re-verified source-by-source to the same standard as the original 38-incident core; source_quality capped at S2/P2 pending a dedicated verification pass.