WASHINGTON — In a secret 72-hour weekend blitz, the FBI, several foreign governments, and security firms dismantled what officials say was the most sophisticated operation ever to commandeer private computers and siphon tens of millions of dollars from US bank accounts.
The alleged Russian ringleader has been indicted on charges of hacking, conspiracy, and bank fraud, Justice Department officials said. Evgeniy Bogachev, 30, who goes by the handle ‘‘lucky12345,’’ was the mastermind behind a ‘‘botnet,’’ or network of infected computers whose owners were unaware their machines had been hijacked, officials said.
He also ran a scheme in which he encrypted victims’ computer files and refused to unlock them until receiving a ransom, officials said.
Deputy Attorney General James Cole called the botnet, dubbed Gameover Zeus, as ‘‘the most sophisticated and damaging . . . we have ever encountered.’’ Between 500,000 and 1 million computers worldwide were infected, and the losses exceeded $100 million for US victims alone, he said.
Cole said officials had ‘‘some sense’’ of Bogachev’s location. ‘‘Our goal right now is to find him and bring him into custody,’’ he said.
Beginning in 2011, Bogachev allegedly used ‘‘spearphishing”e-mails to infect computers with malware. When unwitting users clicked on links or attachments, the malicious code would burrow into their machines. That let Bogachev and others in his ring to watch from Russia as the malware ‘‘intercepted the bank account numbers and passwords that unwitting victims typed into computers,’’ said Leslie Caldwell, an assistant attorney general.
In a novel twist, officials said, Bogachev used the botnet to deliver malicious software called Cryptolocker, which encrypted victims’ files. It then placed a message on their screens informing them they could unlock their files by paying up to $700.
In the first two months, Cole said, the ring collected more than $27 million in ransom payments.
The botnet takedown involved federal prosecutors, FBI agents, foreign law enforcement officials in more than 10 countries, and at least a dozen commercial security firms who provided technical assistance.
The groundwork for the operation involved coordination with Ukrainian authorities, who seized servers in Kiev and Donetsk used by the hackers. On May 19, prosecutors brought sealed charges against Bogachev in Pittsburgh, where some victims were located.
Last week, officials obtained civil court orders permitting them to reroute communications from the infected computers to a server set up by US officials. At the same time, Caldwell said, foreign law enforcement partners seized other critical computer servers, preventing the hackers from encrypting other targets’ files.
Beginning early Friday, authorities around the world began the coordinated seizure of the servers that formed the backbone of the botnet and Cryptolocker, Caldwell said. Over the weekend, more than 300,000 computers were freed from the botnet, which was ‘‘effectively dismantled,’’ she said.
David Hickton, US attorney for the Western District of Pennsylvania, said the investigation is still open.