Russian Hacker Who Used NeverQuest Malware To Steal Money From Victims’ Bank Accounts Sentenced In Manhattan Federal Court To Four Years In Prison
Russian hacker Stanislav Vitaliyevich Lisov, aka 'Black,' was sentenced to 48 months in prison for conspiring to deploy the NeverQuest malware botnet to steal 1.7 million banking credentials and steal over $481,000 from victims, after being extradited from Spain and pleading guilty in Manhattan federal court.
Stanislav Vitaliyevich Lisov, a Russian national known as 'Black,' was sentenced to 48 months in prison for conspiring to deploy the NeverQuest banking Trojan, which infected victims’ computers to steal login credentials and facilitate unauthorized financial transfers. Between June 2012 and January 2015, he maintained infrastructure for a botnet containing approximately 1.7 million stolen credentials and had administrative access to the servers hosting them, enabling account takeovers and fund theft. He was arrested in Spain in 2017, extradited to the U.S. in 2018, pleaded guilty, and was ordered to pay $481,388.04 in restitution and $50,000 in forfeiture, plus three years of supervised release.
Stanislav Vitaliyevich Lisov, a Russian hacker also known as 'Black' and 'Blackf,' was sentenced to 48 months in prison for conspiring to deploy and administer the NeverQuest banking Trojan, a malware designed to steal online banking credentials from victims’ computers. Between June 2012 and January 2015, Lisov played a key role in operating a botnet that infected computers via phishing emails and social media, harvesting approximately 1.7 million sets of login credentials—including usernames, passwords, and security answers—stored on servers he managed. He had administrative access to these servers, used them to remotely control compromised systems, and personally harvested victim data, including discussing the trafficking of stolen information. Lisov was arrested in Spain on January 13, 2017, and extradited to the United States on January 19, 2018, after which he pleaded guilty in Manhattan federal court. In addition to his prison term, he was ordered to pay $481,388.04 in restitution to victims and $50,000 in forfeiture, along with three years of supervised release. The case was prosecuted by the Southern District of New York’s Complex Frauds and Cybercrime Unit, underscoring the Department of Justice’s commitment to holding foreign cybercriminals accountable. U.S. Attorney Geoffrey Berman emphasized that Lisov’s conviction sends a clear message that cybercrime targeting financial systems will be met with severe consequences.
Extracted insights
- $481K $481,388 $100K–$1M
- $50K $50,000 $10K–$100K
- person Geoffrey S. Berman
- person neverquest malware
- person sentencing date
- person stanislav vitaliyevich lisov
- person Valerie E. Caproni
- Stanislav Vitaliyevich Lisov sentenced to 48 months in prison
- Stanislav Vitaliyevich Lisov used NeverQuest malware
- Stanislav Vitaliyevich Lisov stole money from victims' bank accounts
- Stanislav Vitaliyevich Lisov pled guilty to conspiring to deploy and use NeverQuest malware
- Valerie E. Caproni sentenced Stanislav Vitaliyevich Lisov
- Geoffrey S. Berman announced sentencing of Stanislav Vitaliyevich Lisov
- NeverQuest malware responsible for millions of dollars in theft attempts
- Stanislav Vitaliyevich Lisov maintained infrastructure for botnet infected with NeverQuest between June 2012 and January 2015
- Computer servers managed by Lisov contained approximately 1.7 million stolen login credentials
- Stanislav Vitaliyevich Lisov harvested login information from NeverQuest victims
- Sentencing date occurred on November 21, 2019
- Stanislav Vitaliyevich Lisov also known as Black, Blackf
Press Release Russian Hacker Who Used NeverQuest Malware To Steal Money From Victims’ Bank Accounts Sentenced In Manhattan Federal Court To Four Years In Prison Thursday, November 21, 2019 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Geoffrey S. Berman, the United States Attorney for the Southern District of New York, announced that STANISLAV VITALIYEVICH LISOV, a/k/a “Black,” a/k/a “Blackf” (“LISOV”), was sentenced to 48 months in prison today for conspiring to deploy and use a type of malicious software known as NeverQuest to infect the computers of unwitting victims, steal their login information for online banking accounts, and use that information to steal money out of the victims’ accounts. NeverQuest has been responsible for millions of dollars’ worth of attempts by hackers to steal money out of victims’ bank accounts. LISOV was sentenced by U.S. District Judge Valerie E. Caproni, who presided over his guilty plea earlier this year. U.S. Attorney Geoffrey S. Berman stated: “Stanislav Vitaliyevich Lisov, a Russian hacker, used malware to infect victims’ computers, obtain their login credentials for online banking accounts, and steal money from their accounts. This type of cybercrime threatens personal privacy and harms financial institutions. Lisov’s arrest, extradition, conviction, and prison sentence should send an unmistakable message about this Office’s firm commitment to prosecuting hackers – domestic and foreign alike.” According to the allegations in the Indictment to which LISOV pled guilty, public court filings, and statements made in court: NeverQuest is a type of malicious software, or malware, known as a banking Trojan. It can be introduced to victims’ computers through social media websites, phishing emails, or file transfers. Once surreptitiously installed on a victim’s computer, NeverQuest is able to identify when a victim attempted to log onto an online banking website and transfer the victim’s login credentials – including his or her username and password – back to a computer server used to administer the NeverQuest malware. Once surreptitiously installed, NeverQuest enables its administrators remotely to control a victim’s computer and log into the victim’s online banking or other financial accounts, transfer money to other accounts, change login credentials, write online checks, and purchase goods from online vendors. Between June 2012 and January 2015, LISOV was responsible for key aspects of the creation and administration of a network of victim computers known as a “botnet” that was infected with NeverQuest. Among other things, LISOV maintained infrastructure for this criminal enterprise, including by renting and paying for computer servers used to manage the botnet that had been compromised by NeverQuest. Those computer servers contained lists with approximately 1.7 million stolen login credentials – including usernames, passwords, and security questions and answers – for victims’ accounts on banking and other financial websites. LISOV had administrative-level access to those computer servers. LISOV also personally harvested login information from unwitting victims of NeverQuest malware, including usernames, passwords, and security questions and answers. In addition, LISOV discussed trafficking in stolen login information and personally identifying information of victims. On January 13, 2017, LISOV was arrested in Spain pursuant to a provisional arrest warrant. On January 19, 2018, LISOV was extradited from Spain to the United States. * * * In addition to his prison term, LISOV, 34, a citizen of Russia, was sentenced to three years of supervised release, and was ordered to pay forfeiture of $50,000 and restitution of $481,388.04. Mr. Berman praised the outstanding investigative efforts of the Federal Bureau of Investigation. The matter is being handled by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorney Michael D. Neff is in charge of the prosecution. Contact Jim Margolin, Nicholas Biase (212) 637-2600 Updated November 21, 2019 Topics Cybercrime Financial Fraud Component USAO - New York, Southern Press Release Number: 19-393
Press Release Russian Hacker Who Used NeverQuest Malware To Steal Money From Victims’ Bank Accounts Sentenced In Manhattan Federal Court To Four Years In Prison Thursday, November 21, 2019 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Geoffrey S. Berman, the United States Attorney for the Southern District of New York, announced that STANISLAV VITALIYEVICH LISOV, a/k/a “Black,” a/k/a “Blackf” (“LISOV”), was sentenced to 48 months in prison today for conspiring to deploy and use a type of malicious software known as NeverQuest to infect the computers of unwitting victims, steal their login information for online banking accounts, and use that information to steal money out of the victims’ accounts. NeverQuest has been responsible for millions of dollars’ worth of attempts by hackers to steal money out of victims’ bank accounts. LISOV was sentenced by U.S. District Judge Valerie E. Caproni, who presided over his guilty plea earlier this year. U.S. Attorney Geoffrey S. Berman stated: “Stanislav Vitaliyevich Lisov, a Russian hacker, used malware to infect victims’ computers, obtain their login credentials for online banking accounts, and steal money from their accounts. This type of cybercrime threatens personal privacy and harms financial institutions. Lisov’s arrest, extradition, conviction, and prison sentence should send an unmistakable message about this Office’s firm commitment to prosecuting hackers – domestic and foreign alike.” According to the allegations in the Indictment to which LISOV pled guilty, public court filings, and statements made in court: NeverQuest is a type of malicious software, or malware, known as a banking Trojan. It can be introduced to victims’ computers through social media websites, phishing emails, or file transfers. Once surreptitiously installed on a victim’s computer, NeverQuest is able to identify when a victim attempted to log onto an online banking website and transfer the victim’s login credentials – including his or her username and password – back to a computer server used to administer the NeverQuest malware. Once surreptitiously installed, NeverQuest enables its administrators remotely to control a victim’s computer and log into the victim’s online banking or other financial accounts, transfer money to other accounts, change login credentials, write online checks, and purchase goods from online vendors. Between June 2012 and January 2015, LISOV was responsible for key aspects of the creation and administration of a network of victim computers known as a “botnet” that was infected with NeverQuest. Among other things, LISOV maintained infrastructure for this criminal enterprise, including by renting and paying for computer servers used to manage the botnet that had been compromised by NeverQuest. Those computer servers contained lists with approximately 1.7 million stolen login credentials – including usernames, passwords, and security questions and answers – for victims’ accounts on banking and other financial websites. LISOV had administrative-level access to those computer servers. LISOV also personally harvested login information from unwitting victims of NeverQuest malware, including usernames, passwords, and security questions and answers. In addition, LISOV discussed trafficking in stolen login information and personally identifying information of victims. On January 13, 2017, LISOV was arrested in Spain pursuant to a provisional arrest warrant. On January 19, 2018, LISOV was extradited from Spain to the United States. * * * In addition to his prison term, LISOV, 34, a citizen of Russia, was sentenced to three years of supervised release, and was ordered to pay forfeiture of $50,000 and restitution of $481,388.04. Mr. Berman praised the outstanding investigative efforts of the Federal Bureau of Investigation. The matter is being handled by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorney Michael D. Neff is in charge of the prosecution. Contact Jim Margolin, Nicholas Biase (212) 637-2600 Updated November 21, 2019 Topics Cybercrime Financial Fraud Component USAO - New York, Southern Press Release Number: 19-393