{"id":8382,"date":"2025-11-04T13:16:44","date_gmt":"2025-11-04T13:16:44","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=8382"},"modified":"2025-11-04T13:16:44","modified_gmt":"2025-11-04T13:16:44","slug":"alleged-jabber-zeus-coder-mricq-in-u-s-custody-krebs-on-safety","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=8382","title":{"rendered":"Alleged Jabber Zeus Coder \u2018MrICQ\u2019 in U.S. Custody \u2013 Krebs on Safety"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>A Ukrainian man indicted in 2012 for conspiring with a prolific hacking group to steal tens of tens of millions of {dollars} from U.S. companies was arrested in Italy and is now in custody in the US, KrebsOnSecurity has realized.<\/p>\n<p>Sources near the investigation say <strong>Yuriy Igorevich Rybtsov<\/strong>, a 41-year-old from the Russia-controlled metropolis of Donetsk, Ukraine, was beforehand referenced in U.S. federal charging paperwork solely by his on-line deal with \u201c<strong>MrICQ<\/strong>.\u201d In line with <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.justice.gov\/iso\/opa\/resources\/2162014411104532407242.pdf\" target=\"_blank\" rel=\"noopener\">a 13-year-old indictment<\/a> (PDF) filed by prosecutors in Nebraska, MrICQ was a developer for a cybercrime group often known as \u201c<strong>Jabber Zeus<\/strong>.\u201d<\/p>\n<div id=\"attachment_72498\" style=\"width: 759px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" aria-describedby=\"caption-attachment-72498\" decoding=\"async\" class=\" wp-image-72498\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/11\/rybtsov-lockedup.png\" alt=\"\" width=\"749\" height=\"678\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/11\/rybtsov-lockedup.png 861w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/11\/rybtsov-lockedup-768x695.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/11\/rybtsov-lockedup-782x708.png 782w\" sizes=\"auto, (max-width: 749px) 100vw, 749px\"\/><\/p>\n<p id=\"caption-attachment-72498\" class=\"wp-caption-text\">Picture: lockedup dot wtf.<\/p>\n<\/div>\n<p>The Jabber Zeus title is derived from the malware they used \u2014 a customized model of the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/?s=zeus+trojan\" target=\"_blank\" rel=\"noopener\">ZeuS banking trojan<\/a> \u2014 that stole banking login credentials and would ship the group a Jabber on the spot message every time a brand new sufferer entered a one-time passcode at a monetary establishment web site. The gang focused largely small to mid-sized companies, they usually had been an early pioneer of so-called \u201cman-in-the-browser\u201d assaults, malware that may silently intercept any knowledge that victims submit in a web-based type.<\/p>\n<p>As soon as inside a sufferer firm\u2019s accounts, the Jabber Zeus crew would modify the agency\u2019s payroll so as to add dozens of \u201ccash mules,\u201d folks recruited via elaborate work-at-home schemes to deal with financial institution transfers. The mules in flip would ahead any stolen payroll deposits \u2014 minus their commissions \u2014 by way of wire transfers to different mules in Ukraine and the UK.<\/p>\n<p>The 2012 indictment\u00a0concentrating on the Jabber Zeus crew named MrICQ as \u201c<strong>John Doe #3<\/strong>,\u201d and mentioned this individual dealt with incoming notifications of newly compromised victims. The Division of Justice (DOJ) mentioned MrICQ additionally helped the group launder the proceeds of their heists via digital forex change companies.<\/p>\n<p>Two sources conversant in the Jabber Zeus investigation mentioned Rybtsov was arrested in Italy, though the precise date and circumstances of his arrest stay unclear. A <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.cortedicassazione.it\/resources\/cms\/documents\/Rassegna_mensile_MAGGIO_2025__settore_penale.pdf\" target=\"_blank\" rel=\"noopener\">abstract of current selections<\/a> (PDF) printed by the Italian Supreme Court docket states that in April 2025, Rybtsov misplaced a closing attraction to keep away from extradition to the US.<\/p>\n<p>In line with the mugshot web site <strong>lockedup[.]wtf<\/strong>, Rybtsov arrived in Nebraska on October 9, and was being held underneath an arrest warrant from the <strong>U.S. Federal Bureau of Investigation<\/strong> (FBI).<\/p>\n<p>The information breach monitoring service <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/constella.ai\" target=\"_blank\" rel=\"noopener\">Constella Intelligence<\/a> discovered breached data from the enterprise profiling web site bvdinfo[.]com exhibiting {that a} 41-year-old Yuriy Igorevich Rybtsov labored in a constructing at 59 Barnaulska St. in Donetsk. Additional looking on this deal with in Constella finds the identical condominium constructing was shared by a enterprise registered to <strong>Vyacheslav \u201cTank\u201d Penchukov<\/strong>, the chief of the Jabber Zeus crew in Ukraine.<\/p>\n<div id=\"attachment_61804\" style=\"width: 753px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-61804\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-61804\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/11\/tank-dj.png\" alt=\"\" width=\"743\" height=\"587\"\/><\/p>\n<p id=\"caption-attachment-61804\" class=\"wp-caption-text\">Vyacheslav \u201cTank\u201d Penchukov, seen right here performing as \u201cDJ Slava Wealthy\u201d in Ukraine, in an undated picture from social media.<\/p>\n<\/div>\n<p>Penchukov was <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2022\/11\/top-zeus-botnet-suspect-tank-arrested-in-geneva\/\" target=\"_blank\" rel=\"noopener\">arrested in 2022<\/a> whereas touring to satisfy his spouse in Switzerland. Final 12 months, a federal courtroom in Nebraska <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.wired.com\/story\/vyacheslav-igorevich-penchukov-tank-zeus-malware-sentencing\/\" target=\"_blank\" rel=\"noopener\">sentenced Penchukov to 18 years in jail<\/a> and ordered him to pay greater than $73 million in restitution.<span id=\"more-72496\"\/><\/p>\n<p><strong>Lawrence Baldwin<\/strong> is founding father of <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/mynetwatchman.com\" target=\"_blank\" rel=\"noopener\">myNetWatchman<\/a>, a menace intelligence firm based mostly in Georgia that started monitoring and disrupting the Jabber Zeus gang in 2009. myNetWatchman had secretly gained entry to the Jabber chat server utilized by the Ukrainian hackers, permitting Baldwin to snoop on the each day conversations between MrICQ and different Jabber Zeus members.<\/p>\n<p>Baldwin shared these real-time chat data with a number of state and federal regulation enforcement companies, and with this reporter. Between 2010 and 2013, I spent a number of hours every day alerting small companies throughout the nation that their payroll accounts had been about to be drained by these cybercriminals.<\/p>\n<p>These notifications, and Baldwin\u2019s tireless efforts, saved numerous would-be victims an excessive amount of cash. Normally, nonetheless, we had been already too late. However, the pilfered Jabber Zeus group chats offered the idea for dozens of tales printed right here about <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/category\/smallbizvictims\/\" target=\"_blank\" rel=\"noopener\">small companies preventing their banks<\/a> in courtroom over six- and seven-figure monetary losses.<\/p>\n<p>Baldwin mentioned the Jabber Zeus crew was far forward of its friends in a number of respects. For starters, their intercepted chats confirmed they labored to create a extremely custom-made botnet immediately with the creator of the unique Zeus Trojan \u2014 <strong>Evgeniy Mikhailovich Bogachev<\/strong>, a Russian man who has lengthy been on the FBI\u2019s \u201cMost Needed\u201d record. The feds have a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2015\/02\/fbi-3m-bounty-for-zeus-trojan-author\/\" target=\"_blank\" rel=\"noopener\">standing $3 million reward<\/a> for data resulting in Bogachev\u2019s arrest.<\/p>\n<div id=\"attachment_49974\" style=\"width: 753px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-49974\" decoding=\"async\" loading=\"lazy\" class=\"size-full wp-image-49974\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2019\/12\/bogachev.png\" alt=\"\" width=\"743\" height=\"456\"\/><\/p>\n<p id=\"caption-attachment-49974\" class=\"wp-caption-text\">Evgeniy M. Bogachev, in undated photographs.<\/p>\n<\/div>\n<p>The core innovation of Jabber Zeus was an alert that MrICQ would obtain every time a brand new sufferer entered a one-time password code right into a phishing web page mimicking their monetary establishment. The gang\u2019s inner title for this element was \u201c<strong>Leprechaun<\/strong>,\u201d (the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.youtube.com\/watch?v=UiAg3puABeA\" target=\"_blank\" rel=\"noopener\">video under<\/a> from myNetWatchman reveals it in motion). Jabber Zeus would truly re-write the HTML code as displayed within the sufferer\u2019s browser, permitting them to intercept any passcodes despatched by the sufferer\u2019s financial institution for multi-factor authentication.<\/p>\n<p>\u201cThese guys had compromised such a lot of victims that they had been getting buried in a tsunami of stolen banking credentials,\u201d Baldwin advised KrebsOnSecurity. \u201cHowever the entire level of Leprechaun was to isolate the highest-value credentials \u2014 the industrial financial institution accounts with two-factor authentication turned on. They knew these had been far juicier targets as a result of they clearly had much more cash to guard.\u201d<\/p>\n<div class=\"jeg_video_container jeg_video_content\"><iframe loading=\"lazy\" title=\"leprechaun lite\" width=\"500\" height=\"375\" src=\"https:\/\/www.youtube.com\/embed\/UiAg3puABeA?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/div>\n<p>Baldwin mentioned the Jabber Zeus trojan additionally included a customized \u201cbackconnect\u201d element that allowed the hackers to relay their checking account takeovers via the sufferer\u2019s personal contaminated PC.<\/p>\n<p>\u201cThe Jabber Zeus crew had been actually connecting to the sufferer\u2019s checking account from the sufferer\u2019s IP deal with, or from the distant management operate and by totally emulating the machine,\u201d he mentioned. \u201cThat trojan was like a sizzling knife via butter of what everybody thought was state-of-the-art safe on-line banking on the time.\u201d<\/p>\n<p>Though the Jabber Zeus crew was in direct contact with the Zeus creator, the chats intercepted by myNetWatchman present Bogachev often ignored the group\u2019s pleas for assist. The federal government says the actual chief of the Jabber Zeus crew was <strong>Maksim Yakubets<\/strong>, a 38-year Ukrainian man with Russian citizenship who glided by the hacker deal with \u201c<strong>Aqua<\/strong>.\u201d<\/p>\n<div id=\"attachment_49935\" style=\"width: 760px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-49935\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-49935\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2019\/12\/yukabets.png\" alt=\"\" width=\"750\" height=\"611\"\/><\/p>\n<p id=\"caption-attachment-49935\" class=\"wp-caption-text\">Alleged Evil Corp chief Maksim \u201cAqua\u201d Yakubets. Picture: FBI<\/p>\n<\/div>\n<p>The Jabber chats intercepted by Baldwin present that Aqua interacted nearly each day with MrICQ, Tank and different members of the hacking staff, typically facilitating the group\u2019s cash mule and cashout actions remotely from Russia.<\/p>\n<p>The federal government says Yakubets\/Aqua would later emerge because the chief of an elite cybercrime ring of not less than 17 hackers that referred to themselves internally as \u201c<strong>Evil Corp<\/strong>.\u201d Members of Evil Corp developed and used the <strong>Dridex<\/strong> (a.ok.a. <strong>Bugat<\/strong>) trojan, which helped them siphon greater than $100 million from lots of of sufferer firms in the US and Europe.<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2019\/12\/inside-evil-corp-a-100m-cybercrime-menace\/\" target=\"_blank\" rel=\"noopener\">This 2019 story in regards to the authorities\u2019s $5 million bounty<\/a> for data resulting in Yakubets\u2019s arrest consists of excerpts of conversations between Aqua, Tank, Bogachev and different Jabber Zeus crew members discussing tales I\u2019d written about their victims. Each Baldwin and I had been interviewed at size for a brand new weekly six-part podcast by the <strong>BBC<\/strong> that delves deep into the historical past of Evil Corp. <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bbc.com\/audio\/play\/w3ct89y8\" target=\"_blank\" rel=\"noopener\">Episode One<\/a> focuses on the evolution of Zeus, whereas <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bbc.com\/audio\/play\/w3ct89y9\" target=\"_blank\" rel=\"noopener\">the second episode<\/a> facilities on an investigation into the group by former FBI agent <strong>Jim Craig<\/strong>.<\/p>\n<div id=\"attachment_72504\" style=\"width: 757px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-72504\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-72504\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/11\/bbc-cyberhack.png\" alt=\"\" width=\"747\" height=\"423\"\/><\/p>\n<p id=\"caption-attachment-72504\" class=\"wp-caption-text\">Picture: https:\/\/www.bbc.co.uk\/programmes\/w3ct89y8<\/p>\n<\/div><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>A Ukrainian man indicted in 2012 for conspiring with a prolific hacking group to steal tens of tens of millions of {dollars} from U.S. companies was arrested in Italy and is now in custody in the US, KrebsOnSecurity has realized. Sources near the investigation say Yuriy Igorevich Rybtsov, a 41-year-old from the Russia-controlled metropolis of [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":8384,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[2074,6251,6253,6250,262,6252,211,2058,4936],"class_list":["post-8382","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-alleged","tag-coder","tag-custody","tag-jabber","tag-krebs","tag-mricq","tag-security","tag-u-s","tag-zeus"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/8382","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8382"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/8382\/revisions"}],"predecessor-version":[{"id":8383,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/8382\/revisions\/8383"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/8384"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8382"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8382"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8382"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-05 10:27:59 UTC -->