Qakbot leader formally charged in US

23 May 2025 2 minutes Author: Newsman

The US Department of Justice has indicted Russian national Rustam Gallyamov, who is believed to be the main creator of the Qakbot malware, which has been implicated in massive ransomware campaigns around the world.

  • Qakbot, developed in 2008 according to the investigation, managed to infect more than 700,000 devices and was actively used by the Conti, REvil, Black Basta and Dopplepaymer groups. Gallyamov transferred access to the affected devices to his associates, who installed the ransomware, and he himself received a share of the profits.

In August 2023, an international special operation took place with the participation of six countries, including France, Germany, the Netherlands and the UK, as a result of which the Qakbot botnet was neutralized and the code was removed from the affected machines. The group then changed tactics, moving to “spam-bombing” company employees in order to fraudulently gain access to networks.

In addition, a civil lawsuit was filed to seize Gallyamov’s assets worth more than 24 million $

Qakbot played a key role in the cybercriminal landscape, providing the initial infection before ransomware attacks. The global operation to eliminate it, which took place in 2023, was one of the largest in the botnet industry. In addition to Qakbot, the US Department of Justice also charged 16 individuals in connection with DanaBot, another powerful malware that infected 300,000+ devices and caused over50 million $ in damage.

The Qakbot story demonstrates how the combination of technological developments, long-term operations, and partnerships on the darknet can lead to real financial attacks on businesses around the world. The developer’s arrest and indictment is a signal of international cooperation and law enforcement’s readiness to fight sophisticated cyber groups.

Other related articles
Found an error?
If you find an error, take a screenshot and send it to the bot.