{"id":569,"date":"2025-05-23T14:29:10","date_gmt":"2025-05-23T14:29:10","guid":{"rendered":"https:\/\/cryptocoinnewslink.com\/?p=569"},"modified":"2025-05-23T14:29:10","modified_gmt":"2025-05-23T14:29:10","slug":"us-doj-seizes-24m-in-crypto-from-accused-qakbot-malware-developer","status":"publish","type":"post","link":"https:\/\/cryptocoinnewslink.com\/?p=569","title":{"rendered":"US DOJ seizes $24M in crypto from accused Qakbot malware developer"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/images\/840_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjQtMTIvMDE5M2UwYmEtZGE2Ni03ZjI3LWI3NDAtZmJkNDgyMTRjYWNk.jpg\" \/><\/p>\n\n<p><img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/images\/840_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjQtMTIvMDE5M2UwYmEtZGE2Ni03ZjI3LWI3NDAtZmJkNDgyMTRjYWNk.jpg\" alt=\"US DOJ seizes $24M in crypto from accused Qakbot malware developer\" \/><\/p>\n<p>The US Department of Justice (DOJ) has filed a civil forfeiture complaint to seize more than $24 million in cryptocurrency from Rustam Rafailevich Gallyamov, a Russian national accused of developing the Qakbot malware.<\/p>\n<p>According to a May 22\u00a0<a data-ct-non-breakable=\"null\" href=\"https:\/\/www.justice.gov\/opa\/pr\/leader-qakbot-malware-conspiracy-indicted-involvement-global-ransomware-scheme\" title=\"null\">announcement<\/a>,\u00a0the DOJ unsealed charges against the 48-year-old Moscovite with a federal\u00a0<a data-ct-non-breakable=\"null\" href=\"https:\/\/www.justice.gov\/d9\/2025-05\/qakbot_indictment.pdf\" title=\"null\">indictment<\/a>. Gallyamov is allegedly the malware developer behind the Qakbot botnet. <\/p>\n<p>\u201cToday\u2019s announcement of the Justice Department\u2019s latest actions to counter the Qakbot malware scheme sends a clear message to the cybercrime community,\u201d said Matthew Galeotti, head of the DOJ\u2019s criminal division.<\/p>\n<figure><img decoding=\"async\" alt=\"US DOJ seizes $24M in crypto from accused Qakbot malware developer\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2025-05\/0196fd7a-8cc0-7a42-84e7-a7c72b4d6427\" title=\"\" \/><figcaption><em>Screenshot of the indictment. Source: <\/em><a href=\"https:\/\/www.justice.gov\/d9\/2025-05\/qakbot_indictment.pdf\" rel=\"nofollow noopener\" target=\"_blank\" title=\"https:\/\/www.justice.gov\/d9\/2025-05\/qakbot_indictment.pdf\"><em>US Department of Justice<\/em><\/a><\/figcaption><\/figure>\n<p>Galeotti highlighted that the DOJ is \u201cdetermined to hold cybercriminals accountable.\u201d He added that the department will \u201cuse every legal tool\u201d to \u201cidentify you, charge you, forfeit your ill-gotten gains, and disrupt your criminal activity.\u201d<\/p>\n<p><em><strong>Related: <\/strong><\/em><a href=\"https:\/\/cointelegraph.com\/news\/microsoft-legal-action-against-infostealer-lumma\" rel=\"\" target=\"_self\" title=\"https:\/\/cointelegraph.com\/news\/microsoft-legal-action-against-infostealer-lumma\"><em><strong>Microsoft takes legal action against infostealer Lumma<\/strong><\/em><\/a><\/p>\n<h2>Over $24 million forfeited<\/h2>\n<p>US Attorney Bill Essayli for the Central District of California explained that \u201cthe criminal charges and forfeiture case announced today are part of an ongoing effort\u201d to \u201cidentify, disrupt, and hold accountable cybercriminals.\u201d He added:<\/p>\n<blockquote data-ct-non-breakable=\"undefined\"><p>\u201cThe forfeiture action against more than $24 million in virtual assets also demonstrates the Justice Department\u2019s commitment to seizing ill-gotten assets from criminals in order to ultimately compensate victims.\u201d<\/p><\/blockquote>\n<p>Assistant Director in Charge Akil Davis of the FBI\u2019s Los Angeles Field Office said that Qakbot was crippled by the agency and its partners in 2023. Still, Gallyamov allegedly continued deploying alternative methods to offer his malware to potential partners.<\/p>\n<p><em><strong>Related: <\/strong><\/em><a href=\"https:\/\/cointelegraph.com\/news\/bitcoin-stealer-malware-found-in-official-printer-drivers\" rel=\"\" target=\"_self\" title=\"https:\/\/cointelegraph.com\/news\/bitcoin-stealer-malware-found-in-official-printer-drivers\"><em><strong>Chinese printer maker spread Bitcoin stealing malware \u2014 Report<\/strong><\/em><\/a><\/p>\n<h2>Qakbot used in global ransomware attacks<\/h2>\n<p>Gallyamov allegedly operated the Qakbot malware as far back as 2008. In 2019, he allegedly used it to infect thousands of victim computers to establish a so-called botnet.<\/p>\n<p>Access to computers that were part of the botnet was sold to others who infected them with ransomware, including Prolock, Dopplepaymer, Egregor, REvil, Conti, Name Locker, Black Bast and Cactus. In 2023, a US-led international operation\u00a0<a data-ct-non-breakable=\"null\" href=\"https:\/\/www.justice.gov\/archives\/opa\/pr\/qakbot-malware-disrupted-international-cyber-takedown\" title=\"null\">disrupted the Qakbot botnet and malware<\/a>.<\/p>\n<p>At the time, over 170 Bitcoin (<a href=\"https:\/\/cointelegraph.com\/bitcoin-price\">BTC<\/a>) and over $4 million in USDt (<a href=\"https:\/\/cointelegraph.com\/tether-price-index\">USDT<\/a>) and USDC (<a href=\"https:\/\/cointelegraph.com\/usdc-price-index\">USDC<\/a>) stablecoins were seized from Gallyamov. According to the indictment, he and his collaborators continued the activity after it was disrupted, adopting new techniques, including directly deploying Black Basta and Cactus ransomware.<\/p>\n<p><em><strong>Magazine: <\/strong><\/em><a href=\"https:\/\/cointelegraph.com\/magazine\/crypto-exchange-hacks\/\" rel=\"\" target=\"_self\" title=\"https:\/\/cointelegraph.com\/magazine\/crypto-exchange-hacks\/\"><em><strong>Report on Crypto Exchange Hacks<\/strong><\/em><\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>The US Department of Justice (DOJ) has filed a civil forfeiture complaint to seize more than $24 million in cryptocurrency from Rustam Rafailevich Gallyamov, a Russian national accused of developing the Qakbot malware. According to a May 22\u00a0announcement,\u00a0the DOJ unsealed charges against the 48-year-old Moscovite with a federal\u00a0indictment. Gallyamov is allegedly the malware developer behind [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":570,"comment_status":"","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-569","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/cryptocoinnewslink.com\/index.php?rest_route=\/wp\/v2\/posts\/569","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptocoinnewslink.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptocoinnewslink.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptocoinnewslink.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptocoinnewslink.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=569"}],"version-history":[{"count":0,"href":"https:\/\/cryptocoinnewslink.com\/index.php?rest_route=\/wp\/v2\/posts\/569\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptocoinnewslink.com\/index.php?rest_route=\/wp\/v2\/media\/570"}],"wp:attachment":[{"href":"https:\/\/cryptocoinnewslink.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=569"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptocoinnewslink.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=569"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptocoinnewslink.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=569"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}