Skip to main content
Back to the takedown index

Operation Tovar

May 2014, Malware and botnets
Led by Federal Bureau of Investigation, National Crime Agency

Verified core entry, last reviewed August 21, 2026

What was taken down?

Peer-to-peer and DGA command-and-control infrastructure seized and sinkholed; infected machines redirected to law-enforcement-controlled servers; CryptoLocker key server infrastructure disrupted.[1][2][3]

See what happened

What happened to the people?

Officials reported 1 charged and 1 publicly wanted.
1 charged and 1 publicly wanted named in the public record.
Group accounted for: Partial

See people and accountability

Did it stay down?

After this action the service returned on replacement infrastructure, first seen July 2014. No later seizure of the replacement is recorded. High confidence in the link between the two.

See what happened afterward

Multinational operation that redirected and sinkholed the Gameover Zeus peer-to-peer and domain-generation infrastructure, simultaneously disrupting the CryptoLocker ransomware distribution channel.[1][2][3]

Announced June 2, 2014.

Date
May 30 to June 2, 2014
Target
Gameover Zeus botnet and CryptoLocker ransomware, peer to peer botnet
Activity
Malware and botnets, Ransomware, Fraud and stolen data
Operational lead
FBI and NCA
Partners
EC3, USAO-WDPA, and 3 more[1][2][3]
Jurisdiction
United States, United Kingdom, Netherlands, Germany, Ukraine, and European Union
Outcome
Peer-to-peer and DGA command-and-control infrastructure seized and sinkholed; infected machines redirected to law-enforcement-controlled servers; CryptoLocker key server infrastructure disrupted.
Status
Completed
Legal mechanism
US civil and criminal court orders (Western District of Pennsylvania) authorizing redirection and sinkholing; parallel foreign judicial process
Group accounted for
Partial

Infrastructure

500,000 malware installations sinkholed. Domains sinkholed and command and control servers taken over, with no count in the record.

approximately 500,000
malware installations sinkholed
Identifier Recorded as Status Notes
Not published Domain Sinkholed Domain-generation-algorithm domains registered and sinkholed under court order. Exact count not published in the primary release.[1]
Not published Command and control server Taken over Peer-to-peer command-and-control layer poisoned and redirected to law-enforcement-controlled infrastructure.[3]
Not published approximately 500,000 malware installations Sinkholed Estimates range from approximately 500,000 to one million infected machines. Range preserved rather than harmonized.[1]

Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.

1
charged
1
publicly wanted

Named in the public record: 1 charged and 1 publicly wanted.

Figures count individuals named in charging documents and official statements, each person once per outcome. People alleged to be involved but not publicly identified are not counted.

Reported and named. Officials reported 1 charged and 1 publicly wanted. 1 charged and 1 publicly wanted named in the public record. The two figures come from different places and are never added together. Officials publish a headline total, and this index counts only the individuals it can name from the cited record.
Person Role Current public status
Administrator of the Gameover Zeus botnet ChargedPublicly wanted
Charging authority
United States Attorney's Office for the Western District of Pennsylvania
Main charges
Conspiracy; Computer fraud; Wire fraud; Bank fraud; Money laundering
Case number
Not established in the public record
Arresting authority
Not established in the public record
Arrest location
Not established in the public record
Extradition status
Not established in the public record
Conviction or plea
Not established in the public record
Sentence
Not established in the public record
Segment
Core operator
Sources
[1]

Evgeniy Mikhailovich Bogachev

Administrator of the Gameover Zeus botnet. Current public status: Charged and Publicly wanted.

Charging authority
United States Attorney's Office for the Western District of Pennsylvania
Main charges
Conspiracy; Computer fraud; Wire fraud; Bank fraud; Money laundering
Case number
Not established in the public record
Arresting authority
Not established in the public record
Arrest location
Not established in the public record
Extradition status
Not established in the public record
Conviction or plea
Not established in the public record
Sentence
Not established in the public record
Segment
Core operator
Sources
[1]

Rows expand to show charging authority, case identifiers, custody status, and sources.

Group accounted for: Partial

The named leader was charged but never apprehended; the wider group was never publicly identified or accounted for.

Bogachev was described as leading a tightly knit criminal group whose membership was never fully enumerated publicly.

See the organizations and roles behind this action

Evgeniy Bogachev indicted and remains at large in Russia with a 3 million USD State Department reward.[1][2][3]

  1. July 2014

    Gameover Zeus DGA variant. Same service on replacement infrastructure. Confidence: High. No later seizure recorded.[3]

    A variant using the same codebase with a modified distribution mechanism appeared within approximately six weeks of the disruption, documented by multiple independent technical vendors.

July 2014

Gameover Zeus DGA variant. Same service on replacement infrastructure. Confidence: High. No later seizure recorded.[3]

A variant using the same codebase with a modified distribution mechanism appeared within approximately six weeks of the disruption, documented by multiple independent technical vendors.

Return class B. The class is a research grading carried in the source dataset and its scale is not published, so this page relies on the relationship and confidence values instead. How this index handles it.

Numbered markers throughout this entry link to the source that supports the claim beside them.

Official sources

  1. [1]
    U.S. Leads Multi-National Action Against 'Gameover Zeus' Botnet and 'Cryptolocker' Ransomware, Charges Botnet Administrator

    United States Department of Justice, June 2, 2014, Source grade P1

    Disruption technique, Bogachev indictment, infection and loss estimates, partner roster

    No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

  2. [2]
    NCA statement on Operation Tovar

    National Crime Agency, June 2, 2014, Source grade P2

    UK role and victim notification window

    No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

Additional reporting and technical analysis

  1. [3]
    Secureworks analysis of the Gameover Zeus peer-to-peer network and its disruption

    Secureworks, July 1, 2014, Source grade T1

    Technical mechanics of the sinkhole and the subsequent variant resurgence

    No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

Coverage note.
  • Approximately 500,000 to 1 million infected machines and more than 100 million USD in losses are official estimates.
  • A Gameover Zeus variant reappeared within weeks of the disruption, recorded as a Class B resurgence.