2019-02-22 DOJ SDNY press_release 118 KB 5,397 chars

Russian Hacker Who Used Neverquest Malware To Steal Money From Victims’ Bank Accounts Pleads Guilty In Manhattan Federal Court

Caption
United States v. Stanislav Vitaliyevich Lisov
summary

Russian hacker Stanislav Vitaliyevich Lisov, a.k.a. 'Black,' pled guilty to conspiring to deploy the NeverQuest malware to steal banking credentials and steal millions in funds, leading to his arrest in Spain, extradition to the U.S., and a pending sentencing of up to five years in prison.

paragraph

Stanislav Vitaliyevich Lisov, a Russian national, pled guilty to one count of conspiracy to commit computer hacking for his role in deploying the NeverQuest banking Trojan between June 2012 and January 2015. He maintained botnet infrastructure, including servers storing millions of stolen login credentials, and personally harvested and discussed trafficking victims’ personally identifiable information, enabling unauthorized bank transfers and causing millions of dollars in losses. Lisov was arrested in Spain in January 2017, extradited to the U.S. in January 2018, and faces a statutory maximum of five years in prison, with sentencing scheduled for June 27, 2019.

narrative

Stanislav Vitaliyevich Lisov, a Russian national also known as 'Black' and 'Blackf,' pled guilty in Manhattan federal court to conspiring to deploy the NeverQuest banking malware, a type of Trojan designed to steal online banking credentials. Between June 2012 and January 2015, he played a key role in creating and administering a botnet that infected victims’ computers through phishing emails and social media, capturing usernames, passwords, and security answers from millions of accounts. Lisov maintained the criminal infrastructure by renting and paying for servers that stored stolen data and had administrative access to the botnet’s backend systems. He also personally harvested victim information and engaged in discussions about trafficking stolen credentials and personally identifiable information. Arrested in Spain on January 13, 2017, he was extradited to the United States on January 19, 2018, following a provisional arrest warrant. Lisov admitted to his role in the scheme during a guilty plea before Judge Valerie E. Caproni, facing a maximum sentence of five years for conspiracy to commit computer hacking. His sentencing is scheduled for June 27, 2019, and the case was prosecuted by the Southern District of New York’s Complex Frauds and Cybercrime Unit with support from the FBI and DOJ Office of International Affairs.

Enriched metadata

Scheme
cyber-fraud (100%)
Court
Southern District of New York
Outcome
pleaded
Classified cyber-fraud(confidence 100%). No EDGAR filing fingerprint (criminal/DOJ-side scheme). detection rule →
Parties
United States of AmericaStanislav Vitaliyevich Lisov
Keywords
neverquestlisovvictimsaccountsneverquest malwaresteal moneymalwarestealmoneyrussian hackervictims bankbank accountsonline bankinglogin credentialslogin

Extracted insights

Entities 5
  • person computer servers
  • agency fbi assistant director william f. sweeney jr.
  • person neverquest malware
  • person russian hacker
  • agency the fbi and our partners will continue to bring these actors to justice
Triples 29
  • Russian Hacker Used Neverquest Malware
  • Russian Hacker Steal Money From Victims’ Bank Accounts
  • LISOV Plead Guilty In Manhattan Federal Court
  • LISOV Conspire To Deploy Neverquest Malware
  • LISOV Infect Computers Of Unwitting Victims
  • LISOV Steal Login Information For Online Banking Accounts
  • LISOV Steal Money Out Of The Victims’ Accounts
  • Neverquest Be Responsible For Millions Of Dollars’ Worth Of Attempts
  • LISOV Plead Guilty Before United States District Judge Valerie E. Caproni
  • U.S. Attorney Geoffrey S. Berman Say Stanislav Vitaliyevich Lisov Used Malware To Infect Victims’ Computers
  • U.S. Attorney Geoffrey S. Berman Say This Type Of Cybercrime Extends Across Borders
  • U.S. Attorney Geoffrey S. Berman Say This Type Of Cybercrime Poses A Malicious Threat To Personal Privacy
  • U.S. Attorney Geoffrey S. Berman Say This Type Of Cybercrime Causes Widespread Financial Harm
  • FBI Assistant Director William F. Sweeney Jr. Say Stanislav Lisov Gathered Personally Identifiable Information Of Neverquest Victims
  • FBI Assistant Director William F. Sweeney Jr. Say Stanislav Lisov Discussed Illegally Trafficking That Information
  • FBI Assistant Director William F. Sweeney Jr. Say The FBI And Our Partners Will Continue To Bring These Actors To Justice
  • Neverquest Be A Type Of Malicious Software Known As A Banking Trojan
  • Neverquest Be Introduced To Victims’ Computers Through Social Media Websites, Phishing Emails, Or File Transfers
  • Neverquest Be Able To Identify When A Victim Attempts To Log Onto An Online Banking Website
  • Neverquest Transfer The Victim’s Login Credentials Back To A Computer Server Used To Administer The Neverquest Malware
  • Neverquest Enable Its Administrators Remotely To Control A Victim’s Computer
  • Neverquest Enable Its Administrators To Log Into The Victim’s Online Banking Or Other Financial Accounts
  • Neverquest Enable Its Administrators To Transfer Money To Other Accounts
  • Neverquest Enable Its Administrators To Change Login Credentials Of The Victim’s Accounts
  • Neverquest Enable Its Administrators To Write Online Checks From The Victim’s Accounts
  • Neverquest Enable Its Administrators To Purchase Goods From Online Vendors
  • LISOV Be Responsible For Key Aspects Of The Creation And Administration Of A Network Of Victim Computers Known As A Botnet
  • LISOV Maintain Infrastructure For This Criminal Enterprise Including By Renting And Paying For Computer Servers Used To Manage The Botnet
  • Computer Servers Contain Lists Of Millions Of Stolen Login Credentials Including Usernames, Passwords, And Security Questions And Answers
View original DOJ press releasejustice.gov
Extracted body text (5,397c)
Press Release Russian Hacker Who Used Neverquest Malware To Steal Money From Victims’ Bank Accounts Pleads Guilty In Manhattan Federal Court Friday, February 22, 2019 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Geoffrey S. Berman, the United States Attorney for the Southern District of New York, and William F. Sweeney Jr., Assistant Director-in-Charge of the New York Office of the Federal Bureau of Investigation (“FBI”), announced that STANISLAV VITALIYEVICH LISOV, a/k/a “Black,” a/k/a “Blackf” (“LISOV”), pled guilty today to conspiring to deploy and use a type of malicious software known as NeverQuest to infect the computers of unwitting victims, steal their login information for online banking accounts, and use that information to steal money out of the victims’ accounts. NeverQuest has been responsible for millions of dollars’ worth of attempts by hackers to steal money out of victims’ bank accounts. LISOV pled guilty before United States District Judge Valerie E. Caproni. U.S. Attorney Geoffrey S. Berman said: “As he admitted today, Stanislav Vitaliyevich Lisov used malware to infect victims’ computers, obtain their login credentials for online banking accounts, and steal money out of their accounts. This type of cybercrime extends across borders, poses a malicious threat to personal privacy, and causes widespread financial harm. For his audacious crime, this Russian hacker now faces justice in an American court.” FBI Assistant Director William F. Sweeney Jr. said: “'In addition to creating and maintaining a botnet infected with NeverQuest malware, Stanislav Lisov, a Russian national, gathered personally identifiable information of NeverQuest victims and discussed illegally trafficking that information. As today's plea should demonstrate, the FBI and our partners will continue to bring these actors to justice, regardless of where they may hide.” According to the Indictment, Complaint, and other statements made during public court proceedings: NeverQuest is a type of malicious software, or malware, known as a banking Trojan. It can be introduced to victims’ computers through social media websites, phishing emails, or file transfers. Once surreptitiously installed on a victim’s computer, NeverQuest is able to identify when a victim attempts to log onto an online banking website and transfer the victim’s login credentials – including his or her username and password – back to a computer server used to administer the NeverQuest malware. Once surreptitiously installed, NeverQuest enables its administrators remotely to control a victim’s computer and log into the victim’s online banking or other financial accounts, transfer money to other accounts, change login credentials, write online checks, and purchase goods from online vendors. Between June 2012 and January 2015, LISOV was responsible for key aspects of the creation and administration of a network of victim computers known as a “botnet” that was infected with NeverQuest. Among other things, LISOV maintained infrastructure for this criminal enterprise, including by renting and paying for computer servers used to manage the botnet that had been compromised by NeverQuest. Those computer servers contained lists of millions of stolen login credentials – including usernames, passwords, and security questions and answers – for victims’ accounts on banking and other financial websites. LISOV had administrative-level access to those computer servers. LISOV also personally harvested login information from unwitting victims of the NeverQuest malware, including usernames, passwords, and security questions and answers. In addition, LISOV discussed trafficking in stolen login information and personally identifiable information of victims. On January 13, 2017, LISOV was arrested in Spain pursuant to a provisional arrest warrant. On January 19, 2018, LISOV was extradited from Spain to the United States. * * * LISOV, 33, a citizen of Russia, pled guilty to one count of conspiracy to commit computer hacking, which carries a maximum sentence of five years in prison. The statutory maximum sentence is prescribed by Congress and is provided here for informational purposes only, as any sentencing of the defendant will be determined by the judge. LISOV’s sentencing is scheduled for June 27, 2019 at 11:00 a.m. before Judge Caproni. Mr. Berman praised the outstanding investigative efforts of the FBI. Mr. Berman also thanked the DOJ Office of International Affairs for its assistance in this case. The matter is being handled by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorney Michael D. Neff is in charge of the prosecution. Updated February 22, 2019 Component USAO - New York, Southern Press Release Number: 19-053
OCR text (5,397c · plain-text · 99% conf)
Press Release Russian Hacker Who Used Neverquest Malware To Steal Money From Victims’ Bank Accounts Pleads Guilty In Manhattan Federal Court Friday, February 22, 2019 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Geoffrey S. Berman, the United States Attorney for the Southern District of New York, and William F. Sweeney Jr., Assistant Director-in-Charge of the New York Office of the Federal Bureau of Investigation (“FBI”), announced that STANISLAV VITALIYEVICH LISOV, a/k/a “Black,” a/k/a “Blackf” (“LISOV”), pled guilty today to conspiring to deploy and use a type of malicious software known as NeverQuest to infect the computers of unwitting victims, steal their login information for online banking accounts, and use that information to steal money out of the victims’ accounts. NeverQuest has been responsible for millions of dollars’ worth of attempts by hackers to steal money out of victims’ bank accounts. LISOV pled guilty before United States District Judge Valerie E. Caproni. U.S. Attorney Geoffrey S. Berman said: “As he admitted today, Stanislav Vitaliyevich Lisov used malware to infect victims’ computers, obtain their login credentials for online banking accounts, and steal money out of their accounts. This type of cybercrime extends across borders, poses a malicious threat to personal privacy, and causes widespread financial harm. For his audacious crime, this Russian hacker now faces justice in an American court.” FBI Assistant Director William F. Sweeney Jr. said: “'In addition to creating and maintaining a botnet infected with NeverQuest malware, Stanislav Lisov, a Russian national, gathered personally identifiable information of NeverQuest victims and discussed illegally trafficking that information. As today's plea should demonstrate, the FBI and our partners will continue to bring these actors to justice, regardless of where they may hide.” According to the Indictment, Complaint, and other statements made during public court proceedings: NeverQuest is a type of malicious software, or malware, known as a banking Trojan. It can be introduced to victims’ computers through social media websites, phishing emails, or file transfers. Once surreptitiously installed on a victim’s computer, NeverQuest is able to identify when a victim attempts to log onto an online banking website and transfer the victim’s login credentials – including his or her username and password – back to a computer server used to administer the NeverQuest malware. Once surreptitiously installed, NeverQuest enables its administrators remotely to control a victim’s computer and log into the victim’s online banking or other financial accounts, transfer money to other accounts, change login credentials, write online checks, and purchase goods from online vendors. Between June 2012 and January 2015, LISOV was responsible for key aspects of the creation and administration of a network of victim computers known as a “botnet” that was infected with NeverQuest. Among other things, LISOV maintained infrastructure for this criminal enterprise, including by renting and paying for computer servers used to manage the botnet that had been compromised by NeverQuest. Those computer servers contained lists of millions of stolen login credentials – including usernames, passwords, and security questions and answers – for victims’ accounts on banking and other financial websites. LISOV had administrative-level access to those computer servers. LISOV also personally harvested login information from unwitting victims of the NeverQuest malware, including usernames, passwords, and security questions and answers. In addition, LISOV discussed trafficking in stolen login information and personally identifiable information of victims. On January 13, 2017, LISOV was arrested in Spain pursuant to a provisional arrest warrant. On January 19, 2018, LISOV was extradited from Spain to the United States. * * * LISOV, 33, a citizen of Russia, pled guilty to one count of conspiracy to commit computer hacking, which carries a maximum sentence of five years in prison. The statutory maximum sentence is prescribed by Congress and is provided here for informational purposes only, as any sentencing of the defendant will be determined by the judge. LISOV’s sentencing is scheduled for June 27, 2019 at 11:00 a.m. before Judge Caproni. Mr. Berman praised the outstanding investigative efforts of the FBI. Mr. Berman also thanked the DOJ Office of International Affairs for its assistance in this case. The matter is being handled by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorney Michael D. Neff is in charge of the prosecution. Updated February 22, 2019 Component USAO - New York, Southern Press Release Number: 19-053