[Back to the takedown index](https://takedownindex.org/takedowns)

# Operation Tovar

May 2014, Malware and botnets
Led by [Federal Bureau of Investigation](https://takedownindex.org/organizations/federal-bureau-of-investigation), [National Crime Agency](https://takedownindex.org/organizations/national-crime-agency)

Verified core entry, last reviewed August 21, 2026

What was taken down?

Peer-to-peer and DGA command-and-control infrastructure seized and sinkholed; infected machines redirected to law-enforcement-controlled servers; CryptoLocker key server infrastructure disrupted.[[1]](#source-1)[[2]](#source-2)[[3]](#source-3)

[See what happened](#what-happened)

What happened to the people?

Officials reported 1 charged and 1 publicly wanted.
1 charged and 1 publicly wanted named in the public record.
Group accounted for: Partial

[See people and accountability](#people)

Did it stay down?

After this action the service returned on replacement infrastructure, first seen July 2014. No later seizure of the replacement is recorded. High confidence in the link between the two.

[See what happened afterward](#afterward)

## What happened

Multinational operation that redirected and sinkholed the Gameover Zeus peer-to-peer and domain-generation infrastructure, simultaneously disrupting the CryptoLocker ransomware distribution channel.[[1]](#source-1)[[2]](#source-2)[[3]](#source-3)

Announced June 2, 2014.

**Date:** May 30 to June 2, 2014

**Target:** Gameover Zeus botnet and CryptoLocker ransomware, peer to peer botnet

**Activity:** Malware and botnets, Ransomware, Fraud and stolen data

**Operational lead:** FBI and NCA

**Partners**

EC3, USAO-WDPA, and 3 more[[1]](#source-1)[[2]](#source-2)[[3]](#source-3)

- [European Cybercrime Centre](https://takedownindex.org/organizations/european-cybercrime-centre), coordinator
- [United States Attorney's Office for the Western District of Pennsylvania](https://takedownindex.org/organizations/united-states-attorney-s-office-for-the-western-district-of-pennsylvania), charging
- [CrowdStrike](https://takedownindex.org/organizations/crowdstrike), technical partner
- [Secureworks](https://takedownindex.org/organizations/secureworks), technical partner
- [The Shadowserver Foundation](https://takedownindex.org/organizations/the-shadowserver-foundation), technical partner

**Jurisdiction:** United States, United Kingdom, Netherlands, Germany, Ukraine, and European Union

**Outcome:** Peer-to-peer and DGA command-and-control infrastructure seized and sinkholed; infected machines redirected to law-enforcement-controlled servers; CryptoLocker key server infrastructure disrupted.

**Status:** Completed

**Legal mechanism:** US civil and criminal court orders (Western District of Pennsylvania) authorizing redirection and sinkholing; parallel foreign judicial process

**Group accounted for:** Partial

### Infrastructure

500,000 malware installations sinkholed. Domains sinkholed and command and control servers taken over, with no count in the record.

| Identifier | Recorded as | Status | Notes |
| --- | --- | --- | --- |
| Not published | Domain | Sinkholed | Domain-generation-algorithm domains registered and sinkholed under court order. Exact count not published in the primary release.[[1]](#source-1) |
| Not published | Command and control server | Taken over | Peer-to-peer command-and-control layer poisoned and redirected to law-enforcement-controlled infrastructure.[[3]](#source-3) |
| Not published | approximately 500,000 malware installations | Sinkholed | Estimates range from approximately 500,000 to one million infected machines. Range preserved rather than harmonized.[[1]](#source-1) |

Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.

## People and accountability

Named in the public record: 1 charged and 1 publicly wanted.

Figures count individuals named in charging documents and official statements, each person once per outcome. People alleged to be involved but not publicly identified are not counted.

Reported and named. Officials reported 1 charged and 1 publicly wanted. 1 charged and 1 publicly wanted named in the public record. The two figures come from different places and are never added together. Officials publish a headline total, and this index counts only the individuals it can name from the cited record.

#### Evgeniy Mikhailovich Bogachev

Administrator of the Gameover Zeus botnet. Current public status: Charged and Publicly wanted.

**Charging authority:** United States Attorney's Office for the Western District of Pennsylvania

**Main charges:** Conspiracy; Computer fraud; Wire fraud; Bank fraud; Money laundering

**Case number:** Not established in the public record

**Arresting authority:** Not established in the public record

**Arrest location:** Not established in the public record

**Extradition status:** Not established in the public record

**Conviction or plea:** Not established in the public record

**Sentence:** Not established in the public record

**Segment:** Core operator

**Sources:** [[1]](#source-1)

**Full record:** [Everything indexed for Evgeniy Mikhailovich Bogachev](https://takedownindex.org/people/evgeniy-mikhailovich-bogachev)

Group accounted for: Partial

The named leader was charged but never apprehended; the wider group was never publicly identified or accounted for.

Bogachev was described as leading a tightly knit criminal group whose membership was never fully enumerated publicly.

[See the organizations and roles behind this action](https://takedownindex.org/takedowns/operation-tovar/organizations)

## What happened afterward

Evgeniy Bogachev indicted and remains at large in Russia with a 3 million USD State Department reward.[[1]](#source-1)[[2]](#source-2)[[3]](#source-3)

July 2014

Gameover Zeus DGA variant. Same service on replacement infrastructure. Confidence: High. No later seizure recorded.[[3]](#source-3)

A variant using the same codebase with a modified distribution mechanism appeared within approximately six weeks of the disruption, documented by multiple independent technical vendors.

Return class B. The class is a research grading carried in the source dataset and its scale is not published, so this page relies on the relationship and confidence values instead. [How this index handles it](https://takedownindex.org/about).

## Sources

Numbered markers throughout this entry link to the source that supports the claim beside them.

### Official sources

1.
[U.S. Leads Multi-National Action Against 'Gameover Zeus' Botnet and 'Cryptolocker' Ransomware, Charges Botnet Administrator](https://takedownindex.org/sources/united-states-department-of-justice-u-s-leads-multi-national-action-against-game)

United States Department of Justice, June 2, 2014, Source grade P1

Disruption technique, Bogachev indictment, infection and loss estimates, partner roster

No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

2.
[NCA statement on Operation Tovar](https://takedownindex.org/sources/national-crime-agency-nca-statement-on-operation-tovar)

National Crime Agency, June 2, 2014, Source grade P2

UK role and victim notification window

No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

### Additional reporting and technical analysis

1.
[Secureworks analysis of the Gameover Zeus peer-to-peer network and its disruption](https://takedownindex.org/sources/secureworks-secureworks-analysis-of-the-gameover-zeus-peer-to-peer-network-and-i)

Secureworks, July 1, 2014, Source grade T1

Technical mechanics of the sinkhole and the subsequent variant resurgence

No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

Coverage note.
- Approximately 500,000 to 1 million infected machines and more than 100 million USD in losses are official estimates.
- A Gameover Zeus variant reappeared within weeks of the disruption, recorded as a Class B resurgence.

Research context

## How this entry was checked

This entry went through a dedicated source verification pass. Publisher, title, publication date, and docket numbers were confirmed against each cited source.

Source review: Verified core

Sources cited: 3

Research cutoff: August 20, 2026

Last reviewed August 21, 2026

See also

[About the Internet Takedown Index](https://takedownindex.org/about)

Related entries

- [Operation Onymous](https://takedownindex.org/takedowns/operation-onymous)
- [ZeroAccess botnet disruption](https://takedownindex.org/takedowns/zeroaccess-botnet-disruption)
- [Silk Road seizure](https://takedownindex.org/takedowns/silk-road-seizure)

Report updates or corrections

Help keep this record accurate.

[Submit feedback](https://takedownindex.org/about#corrections-and-updates)
