Skip to main content

FBI Cracks Down on Russian Cybercrime Kingpin, Seizes $24M in Crypto in Operation Endgame



In a major blow to global cybercrime, the U.S. Department of Justice (DOJ) has indicted Russian national Rustam Rafailevich Gallyamov, a 48-year-old Moscow resident accused of masterminding the Qakbot malware operation that infected over 700,000 computers worldwide. As part of the FBI’s “Operation Endgame,” authorities seized more than $24 million in cryptocurrency, including 30 Bitcoins and $700,000 in USDT tokens, linked to Gallyamov’s illicit activities. This takedown, made public on May 22, 2025, is a major milestone in the battle against ransomware attacks that have tormented businesses, healthcare organizations, and government networks worldwide.

The Qakbot Malware: An International Cyber Menace
For thousands of victims, the terror started with a locked-up screen, a flashing notice, and a ransom demand. From Los Angeles' small dental offices to Wisconsin manufacturers and Canadian real estate companies, the Qakbot malware of Gallyamov did the damage. Initially created in 2008, Qakbot developed into a sophisticated program that breached systems and supported ransomware attacks by notorious gangs such as Conti, REvil, Black Basta, and Cactus. Gallyamov allegedly provided access to infected devices, allowing his co-conspirators to deploy ransomware and extort millions, with Gallyamov taking a cut of the profits.

The malware spread broadly, infecting more than 700,000 computers at a cost to victims of tens of millions. During the 18 months prior to a 2023 disruption, Qakbot enabled at least 40 ransomware attacks, causing $58 million in damage. Victims included small businesses and critical infrastructure, demonstrating the indiscriminate nature of these cyberattacks.

Operation Endgame: A Global Effort
The indictment and seizures are a component of Operation Endgame, a joint international operation with the FBI, Europol, and French, German, Dutch, British, Danish, and Canadian law enforcement bodies. The operation, which commenced in May 2024, aims at the infrastructure underpinning ransomware groups, including malware such as Qakbot, Bumblebee, and TrickBot. In its final phase, authorities dismantled 300 servers, knocked out 650 domains, and took over €3.5 million in cryptocurrency, for a total seized under Operation Endgame of more than €21.2 million.

The FBI’s Los Angeles and Milwaukee field offices, alongside international partners like Germany’s Bundeskriminalamt and France’s Anti-Cybercrime Office, played a key role in tracking Gallyamov’s operations. A seizure warrant executed on April 25, 2025, netted 30 Bitcoins and $700,000 in USDT, while a civil forfeiture complaint filed in California’s Central District aims to permanently claim over $24 million in crypto assets to compensate victims.

A Persistent Threat, Evolving Tactics
Gallyamov's operation was initially disrupted in August 2023, when a U.S.-led task force had seized 52 servers and more than $8.6 million in cryptocurrency, including 170 Bitcoins. During that time, U.S. Attorney Martin Estrada described it as "the most significant technological and financial operation ever led by the DOJ against a botnet." However, Gallyamov was resilient. By January 2025, he and his colleagues had changed their strategy, employing "spam bomb" attacks—overwhelming victims' mailboxes with malicious messages to lure employees into granting network access.

This flexibility highlights the difficulty in fighting cybercrime. Even after the 2023 shutdown, Gallyamov went on to coordinate attacks, which were aimed at a variety of organizations. The DOJ's recent actions seek not just to dismantle his network but to send a message to cybercriminals across the globe. "We are committed to holding cybercriminals accountable," said Matthew Galeotti, chief of the DOJ's criminal division. "We will employ every available legal tool to find you, prosecute you, and seize your ill-gotten proceeds."

The Larger Picture: Ransomware and Crypto
Ransomware has emerged as an increasing threat with Russian-speaking cybercriminals leading the charge. A 2024 TRM Labs report disclosed that Russian-speaking actors control 69% of all cryptocurrency proceeds from ransomware in 2023, amounting to $500 million. Cryptocurrencies such as Bitcoin and stablecoins such as USDT have emerged as the hackers' payment medium of choice owing to their anonymity and ease of transfer. But as in this case, law enforcement is becoming more adept at following these transactions through blockchain analysis.

The DOJ's asset forfeiture emphasis is a central strategy. By taking ransomware illicit crypto and returning it to victims, the government hopes to break the financial incentives fueling the attacks. This tactic has worked before, including the 2021 Bitcoin seizure of $2.3 million from the DarkSide gang behind the Colonial Pipeline attack and the 2022 recovery of $500,000 from North Korean hackers targeting U.S. healthcare providers.

Challenges Ahead
Although the indictment of Gallyamov is a success, there are challenges. He is thought to be in Russia, which has no extradition treaty with the U.S., so his arrest is unlikely unless he does travel outside the country. The fact that ransomware groups continue to operate despite significant disruptions indicates the necessity for continued international cooperation and investment in cybersecurity.
Operation Endgame's success demonstrates the strength of international cooperation, but cybercrooks adapt continuously. As Assistant Director Akil Davis of the Los Angeles Field Office of the FBI explained, "Gallyamov's bot net was brought to its knees in 2023, but he boldly persisted." To stay ahead of such threats, vigilance, creativity, and commitment to bringing perpetrators to justice will be needed.

A Step Toward Justice
The capture of $24 million in cryptocurrency and the indictment of Rustam Gallyamov represent a major victory in the battle against ransomware. For the victims, from small business to critical infrastructure, the recovery of these funds represents the promise of restitution. For the international cybersecurity community, Operation Endgame is a reminder that no hacker is untouchable when countries cooperate.

As the DOJ and its allies are dismantling cybercrime syndicates, there is one message: the era of being able to act with impunity in the dark recesses of the web is coming to an end. At least for the time being, the priority is to return the seized money to the victims and hold cybercrooks accountable for what they did.

Comments

Popular posts from this blog

U.S.-China Trade Talks: A Temporary Thaw as the EU Seeks a Stronger Foothold with the U.S.

The new world economic order is re-configuring once again, and this time it is because of the U.S.-China trade talks and the strategic realignment of the European Union. After months of escalating tensions, a temporary roll-back of US tariffs on China has generated cautious optimism, with de-escalation talks still in progress. Meanwhile, the European Union promised to escalate negotiations with the U.S. on trade, an action that boosted equity-index futures for Asian and American equities. But what does it mean for world trade overall, and are we witnessing a genuine thaw or just a temporary respite in a larger economic standoff? Let's untangle it. A Fragile Truce: U.S.-China Trade Talks Take a Step Forward The United States and China, the world's largest two economies, have been embroiled in a bitter trade war that has disrupted markets and realigned global supply chains for over a year. Tariffs on Chinese imports had surged up to 145% since President Donald Trump took office i...

Trump’s Tariff Plans Threaten to Unleash a Global Economic Shockwave

On May 23, 2025, U.S. President Donald Trump dropped a bombshell that rattled global markets and reignited fears of a trade war: a proposed 50% tariff on all European Union imports and a 25% tariff on iPhones not manufactured in the U.S., both set to take effect on June 1. Announced in a fiery Truth Social post just hours ago, Trump’s latest trade gambit has sent shockwaves through an already fragile global economy, with economists warning of a potential economic shock that could ripple across continents. As the world grapples with the fallout, the stakes couldn’t be higher for international trade, consumer prices, and geopolitical stability. A Bold and Sudden Move Trump’s tariff threats came without warning, following a period of relative calm after months of tariff-related turbulence. In his post, he accused the EU of exploiting the U.S. through unfair trade practices, claiming the bloc’s trade surplus with America—pegged at $235.6 billion in 2024 by the U.S. Trade Representative—amo...

Supreme Court Blocks Trump’s Deportation Push Under 1798 Law as DHS Floats Controversial Reality TV Show

  As part of a series of high-stakes actions in U.S. immigration policy, the Supreme Court has again put the brakes on President Donald Trump's aggressive attempt to deport suspected Venezuelan gang members under the little-used Alien Enemies Act of 1798. The ruling, coupled with allegations that the Trump administration was in contempt of court and an eleventh-hour proposal by the Department of Homeland Security (DHS) to produce a reality television show in which immigrants compete for citizenship, is used to demonstrate the polarizing and chaotic nature of immigration enforcement in 2025. Supreme Court Rejects Trump's Application of Wartime Provision The U.S. Supreme Court on May 17, 2025, in a 7-2 ruling, denied the Trump administration's attempt to revive deportations of Venezuelan migrants who were arrested in the north Texas region under the Alien Enemies Act. This 18th-century statute, applied for decades only during wartime to arrest or deport nationals of belligere...