On June 2, 2014, the U.S. Department of Justice announced two related but distinct disruption actions. Court-authorized redirection cut the GameOver Zeus (GOZeuS) botnet off from its criminal command infrastructure, while a separate operation seized servers central to CryptoLocker ransomware. The same announcement unsealed charges against Evgeniy Mikhailovich Bogachev, whom prosecutors alleged administered GameOver Zeus. The filings were accusations; DOJ said he was presumed innocent unless and until proven guilty.
What the June 2014 operation did
The announcement combined three developments:
- GameOver Zeus disruption: Authorities redirected infected computers’ automated requests for instructions to substitute servers established under court orders.
- CryptoLocker infrastructure seizure: Investigators identified and seized command-and-control servers used by the ransomware in a separate coordinated action.
- Criminal charges: A Pittsburgh grand jury indictment and a separate Omaha criminal complaint were unsealed in connection with alleged malware activity.
These measures were multinational. DOJ said they depended on cooperation among law-enforcement agencies in more than 10 countries, private-sector specialists and national computer-response teams.
How GameOver Zeus worked
GameOver Zeus, also called Peer-to-Peer Zeus, secretly turned infected computers into nodes in a decentralized botnet. It captured online-banking credentials, which criminals allegedly used to initiate or redirect wire transfers to overseas accounts. Its peer-to-peer design made it more difficult to disable than earlier, more centrally managed Zeus variants.
The court-authorized redirection
Instead of entering victims’ computers, authorities obtained civil orders permitting them to redirect automated requests from infected machines away from criminal servers. Substitute servers received those requests and supplied enough information for responders to identify the Internet Protocol addresses contacting them.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
Those addresses could be passed to US-CERT, national response organizations and private-sector partners so victims could be notified and helped with removal. The DOJ release stated: “At no point during the operation did the FBI or law enforcement access the content of any of the victims’ computers or electronic communications.” The process did collect connection information, such as IP addresses, for remediation; that is different from accessing the contents of files or communications.
How CryptoLocker differed—and how it was connected
CryptoLocker began appearing around September 2013 and used cryptographic key pairs to encrypt victims’ files. It then demanded ransom in exchange for access. GameOver Zeus stole credentials and enabled financial fraud; CryptoLocker denied access to data and demanded payment.
DOJ described GameOver Zeus as a common distribution mechanism for CryptoLocker. That wording establishes a significant link between the operations, but it does not mean every CryptoLocker infection came through GOZeuS.
Rank #2
The separate CryptoLocker action
Investigators identified the ransomware’s command-and-control infrastructure and seized servers central to its operation. The seizure was not the same technical step as redirecting GOZeuS traffic, although the actions were coordinated and announced together.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Operation chronology
- May 7, 2014: Ukrainian authorities seized and copied key GameOver Zeus command servers in Kyiv and Donetsk.
- May 19: Sealed criminal charges were obtained.
- May 28: Civil orders authorizing the redirection operation were obtained.
- Weekend before the June 2 announcement: Coordinated server seizures and traffic redirection took place.
- June 2: DOJ announced the disruption, the CryptoLocker action and the unsealed charges.
Assistant Attorney General Leslie R. Caldwell said more than 300,000 victim computers had been freed from the botnet over that initial weekend, while warning that disruption alone was not a complete solution and that threats could re-emerge.
Who was indicted?
The Pittsburgh indictment charged Bogachev in 14 counts alleging conspiracy, computer hacking, wire fraud, bank fraud and money laundering connected to his alleged GameOver Zeus role. A distinct criminal complaint filed in Omaha concerned an earlier Zeus variant; it should not be treated as part of the 14-count Pittsburgh indictment.
At the time of the announcement, Bogachev had been charged, not convicted. DOJ expressly stated that the indictment and related filings contained allegations and that he was presumed innocent unless and until proven guilty. The 2014 materials do not establish his eventual legal outcome.
What the official numbers meant
All figures below were historical 2014 estimates or statements, not measurements of current prevalence.
Recommended Free Tools
| Measure | Figure and qualification |
|---|---|
| GameOver Zeus infections | Security researchers estimated 500,000 to 1 million computers worldwide, with about 25% in the United States (DOJ release, June 2, 2014). |
| GameOver Zeus losses | The FBI estimated losses to U.S. victims above $100 million; worldwide losses were unknown in Deputy Attorney General James Cole’s remarks (June 2, 2014). |
| CryptoLocker infections | More than 234,000 infections as of April 2014, about half in the United States (security researchers, as reported in the DOJ release). |
| CryptoLocker ransom | One estimate put payments above $27 million during the ransomware’s first two months (reported by DOJ, June 2, 2014). |
| Initial remediation | Caldwell reported more than 300,000 victim computers freed during the initial weekend (June 2, 2014). |
| July remediation status | DOJ reported a 31% reduction in infected computers since disruption began (July 11, 2014). |
Figures in official June remarks were not perfectly identical: Cole referred to more than 200,000 CryptoLocker infections, while the DOJ press release gave the more specific figure of more than 234,000 as of April. They are different statements and should not be merged into one reconciled count.
What changed by July 2014?
In its July 11 follow-up, DOJ reported that the number of GameOver Zeus-infected computers had fallen 31% since the disruption commenced. It also said CryptoLocker was effectively non-functional at that time: the malware could not communicate with the infrastructure used to control it and could not encrypt newly infected computers.
That status described the infrastructure then disrupted. It did not establish that every later ransomware threat, or every program using the CryptoLocker name, had disappeared. Nor do these 2014 updates provide current infection-rate data.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why the takedown mattered
The operation demonstrated a hybrid approach: court orders enabled a controlled technical substitute for criminal command servers; international partners seized or copied infrastructure; and private companies and response teams used contact data to help victims clean infected systems. As Cole put it, the effort combined “innovative legal and technical tactics with traditional law enforcement tools” and cooperation across more than 10 countries.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteBest Value
It was also a reminder that disabling servers is not the same as repairing every compromised computer. Victim notification and malware removal remained necessary, and Caldwell cautioned that disruption measures alone could not guarantee that the threats would never return.
Bottom line for the 2014 event
GameOver Zeus and CryptoLocker were not the same malware. GOZeuS primarily stole banking credentials through a decentralized botnet; CryptoLocker encrypted files for ransom. Authorities redirected GOZeuS traffic under court order and separately seized CryptoLocker infrastructure, while prosecutors charged an alleged GOZeuS administrator. The June announcement and July update describe a substantial, documented interruption in 2014—not a finding of guilt and not a statement about present-day malware prevalence.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

