DOJ Seizes $24 Million in Crypto from Alleged Qakbot Malware Developer
The US Department of Justice (DOJ) has initiated civil forfeiture proceedings to seize over $24 million in cryptocurrency from Rustam Rafailevich Gallyamov, a Russian national indicted for his alleged role in developing the notorious Qakbot malware.
In a May 22 announcement, the DOJ unveiled federal charges against the 48-year-old Gallyamov, accusing him of masterminding the Qakbot botnet. The indictment details his alleged development and deployment of the malware, highlighting its significant impact on global cybersecurity.
“This action underscores the DOJ’s unwavering commitment to pursuing cybercriminals,” stated Matthew Galeotti, head of the DOJ’s criminal division, emphasizing their resolve to utilize all available legal resources to bring perpetrators to justice and recover stolen assets.
Screenshot of the indictment. Source: US Department of Justice
The DOJ’s seizure of over $24 million in digital assets is a significant step in their ongoing efforts to disrupt cybercrime and compensate victims, according to US Attorney Bill Essayli for the Central District of California. The action follows a 2023 operation that crippled the Qakbot botnet, though Gallyamov allegedly continued his activities using alternative methods.
Gallyamov’s alleged involvement with Qakbot dates back to 2008. The botnet was reportedly used to facilitate large-scale ransomware attacks, including those using Prolock, Dopplepaymer, Egregor, REvil, Conti, Name Locker, Black Basta, and Cactus ransomware. Even after the 2023 takedown, the indictment alleges Gallyamov and his associates persisted, deploying new tactics.
This seizure adds to the previously confiscated 170 Bitcoin (BTC) and millions of dollars in stablecoins. The DOJ’s assertive response underscores the escalating battle against sophisticated cybercriminals and their exploitation of cryptocurrency.