Houston Chronicle

Russian spying built on hacker’s network

- By Michael Schwirtz and Joseph Goldstein

To the FBI, Evgeniy Bogachev is the most wanted cybercrimi­nal in the world. The bureau has announced a $3 million bounty for his capture, the most ever for computer crimes, and has been trying to track his movements in hopes of grabbing him if he strays outside his home turf in Russia.

He has been indicted in the U.S., accused of creating a sprawling network of virus-infected computers to siphon hundreds of millions of dollars from bank accounts around the world, targeting anyone with enough money worth stealing — from a pest control company in North Carolina to a police department in Massachuse­tts to a Native American tribe in Washington.

In December, the Obama administra­tion announced sanctions against Bogachev and five others in response to intelligen­ce agencies’ conclusion­s that Russia had meddled in the presidenti­al election. Publicly, law enforcemen­t officials said it was his criminal exploits that landed Bogachev on the sanctions list, not any specific role in the hacking of the Democratic National Committee.

But it is clear that for Russia, he is more than just a criminal. At one point, Bogachev had control over as many as 1 million computers in multiple countries, with possible access to everything from family vacation photograph­s and term papers to business proposals and highly confidenti­al personal informatio­n. It is almost certain that computers belonging to government officials and contractor­s in several countries were among the infected devices. For Russia’s surveillan­ce-obsessed intelligen­ce community, Bogachev’s exploits may have created an irresistib­le opportunit­y for espionage.

While Bogachev was draining bank accounts, it appears that Russian authoritie­s were looking over his shoulder, searching the same computers for files and emails. In effect, they were grafting an intelligen­ce operation onto a far-reaching cybercrimi­nal scheme, sparing themselves the hard work of hacking into the computers themselves, officials said.

His involvemen­t with Russian intelligen­ce may help explain why Bogachev, 33, is hardly a man on the run. FBI officials say he lives openly in Anapa, a rundown resort town on the Black Sea in southern Russia. He has a large apartment near the shore and possibly another in Moscow, officials say, as well as a collection of luxury cars, though he seems to favor driving his Jeep Grand Cherokee. U.S. investigat­ors say he enjoys sailing and owns a yacht.

Running the criminal scheme was hard work. Bogachev often complained of being exhausted and “of having too little time for his family,” said Alexander Panin, a Russian hacker, now in a federal prison in Kentucky for bank fraud, who used to communicat­e with Bogachev online. “He mentioned a wife and two kids as far as I remember,” Panin wrote in an email.

Beyond that, little is known about Bogachev. Even close business associates never met him in person or knew his real name. “He was very, very paranoid,” said Keith Mularski, an FBI supervisor in Pittsburgh whose investigat­ion of Bogachev led to an indictment in 2014. “He didn’t trust anybody.”

Russia does not have an extraditio­n treaty with the United States, and Russian officials say that so long as Bogachev has not committed a crime on Russian territory, there are no grounds to arrest him.

That Bogachev remains at large “is the most powerful argument” that he is an asset of the Russian government, said Austin Berglas, who was an assistant special agent in charge of cyberinves­tigations out of the FBI’s New York field office until 2015.

 ?? FBI via New York Times ?? Evgeniy Bogachev is the FBI’s most wanted cybercrimi­nal in the world. But for Russia, his exploits may have created an irresistib­le opportunit­y for espionage.
FBI via New York Times Evgeniy Bogachev is the FBI’s most wanted cybercrimi­nal in the world. But for Russia, his exploits may have created an irresistib­le opportunit­y for espionage.

Newspapers in English

Newspapers from United States