Operation Tovar
Verified core entry, last reviewed August 21, 2026
What was taken down?
Peer-to-peer and DGA command-and-control infrastructure seized and sinkholed; infected machines redirected to law-enforcement-controlled servers; CryptoLocker key server infrastructure disrupted.[1][2][3]
See what happenedWhat happened to the people?
Officials reported 1 charged and 1 publicly wanted.
1 charged and 1 publicly wanted named in the public record.
Group accounted for: Partial
Did it stay down?
After this action the service returned on replacement infrastructure, first seen July 2014. No later seizure of the replacement is recorded. High confidence in the link between the two.
See what happened afterwardMultinational operation that redirected and sinkholed the Gameover Zeus peer-to-peer and domain-generation infrastructure, simultaneously disrupting the CryptoLocker ransomware distribution channel.[1][2][3]
Announced June 2, 2014.
- Date
- May 30 to June 2, 2014
- Target
- Gameover Zeus botnet and CryptoLocker ransomware, peer to peer botnet
- Activity
- Malware and botnets, Ransomware, Fraud and stolen data
- Operational lead
- FBI and NCA
- Partners
- EC3, USAO-WDPA, and 3 more[1][2][3]
- European Cybercrime Centre , coordinator
- United States Attorney's Office for the Western District of Pennsylvania , charging
- CrowdStrike , technical partner
- Secureworks , technical partner
- The Shadowserver Foundation , technical partner
- Jurisdiction
- United States, United Kingdom, Netherlands, Germany, Ukraine, and European Union
- Outcome
- Peer-to-peer and DGA command-and-control infrastructure seized and sinkholed; infected machines redirected to law-enforcement-controlled servers; CryptoLocker key server infrastructure disrupted.
- Status
- Completed
- Legal mechanism
- US civil and criminal court orders (Western District of Pennsylvania) authorizing redirection and sinkholing; parallel foreign judicial process
- Group accounted for
- Partial
Infrastructure
500,000 malware installations sinkholed. Domains sinkholed and command and control servers taken over, with no count in the record.
- approximately 500,000
- malware installations sinkholed
| Identifier | Recorded as | Status | Notes |
|---|---|---|---|
| Not published | Domain | Sinkholed | Domain-generation-algorithm domains registered and sinkholed under court order. Exact count not published in the primary release.[1] |
| Not published | Command and control server | Taken over | Peer-to-peer command-and-control layer poisoned and redirected to law-enforcement-controlled infrastructure.[3] |
| Not published | approximately 500,000 malware installations | Sinkholed | Estimates range from approximately 500,000 to one million infected machines. Range preserved rather than harmonized.[1] |
Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.
- 1
- charged
- 1
- publicly wanted
Named in the public record: 1 charged and 1 publicly wanted.
Figures count individuals named in charging documents and official statements, each person once per outcome. People alleged to be involved but not publicly identified are not counted.
| Person | Role | Current public status |
|---|---|---|
| Administrator of the Gameover Zeus botnet | ChargedPublicly wanted | |
|
||
Evgeniy Mikhailovich Bogachev
Administrator of the Gameover Zeus botnet. Current public status: Charged and Publicly wanted.
- Charging authority
- United States Attorney's Office for the Western District of Pennsylvania
- Main charges
- Conspiracy; Computer fraud; Wire fraud; Bank fraud; Money laundering
- Case number
- Not established in the public record
- Arresting authority
- Not established in the public record
- Arrest location
- Not established in the public record
- Extradition status
- Not established in the public record
- Conviction or plea
- Not established in the public record
- Sentence
- Not established in the public record
- Segment
- Core operator
- Sources
- [1]
Rows expand to show charging authority, case identifiers, custody status, and sources.
Group accounted for: Partial
The named leader was charged but never apprehended; the wider group was never publicly identified or accounted for.
Bogachev was described as leading a tightly knit criminal group whose membership was never fully enumerated publicly.
Evgeniy Bogachev indicted and remains at large in Russia with a 3 million USD State Department reward.[1][2][3]
-
July 2014
Gameover Zeus DGA variant. Same service on replacement infrastructure. Confidence: High. No later seizure recorded.[3]
A variant using the same codebase with a modified distribution mechanism appeared within approximately six weeks of the disruption, documented by multiple independent technical vendors.
July 2014
Gameover Zeus DGA variant. Same service on replacement infrastructure. Confidence: High. No later seizure recorded.[3]
A variant using the same codebase with a modified distribution mechanism appeared within approximately six weeks of the disruption, documented by multiple independent technical vendors.
Return class B. The class is a research grading carried in the source dataset and its scale is not published, so this page relies on the relationship and confidence values instead. How this index handles it.
Numbered markers throughout this entry link to the source that supports the claim beside them.
Official sources
-
[1]
U.S. Leads Multi-National Action Against 'Gameover Zeus' Botnet and 'Cryptolocker' Ransomware, Charges Botnet Administrator
Disruption technique, Bogachev indictment, infection and loss estimates, partner roster
-
[2]
NCA statement on Operation Tovar
UK role and victim notification window
Additional reporting and technical analysis
-
[3]
Secureworks analysis of the Gameover Zeus peer-to-peer network and its disruption
Technical mechanics of the sinkhole and the subsequent variant resurgence
- Approximately 500,000 to 1 million infected machines and more than 100 million USD in losses are official estimates.
- A Gameover Zeus variant reappeared within weeks of the disruption, recorded as a Class B resurgence.