Free tools Windows power users keep installed
One-click scans. No signup required.
Vyacheslav Igorevich Penchukov, a cybercriminal once on the FBI’s Most Wanted list, pleaded guilty to two conspiracy charges tied to the Zeus banking-malware enterprise and the IcedID group. The U.S. Department of Justice announced the pleas on February 15, 2024: one count was a RICO conspiracy for his leadership role in Zeus, and the other was a wire-fraud conspiracy for his leadership role in IcedID.
What did Penchukov plead guilty to?
DOJ said Penchukov, also known as Vyacheslav Igoravich Andreev and “Tank,” pleaded guilty in the District of Nebraska to a RICO conspiracy count connected to the Zeus enterprise. He also pleaded guilty in the Eastern District of North Carolina to a wire-fraud conspiracy count connected to the IcedID group. Prosecutors described him as a leader in both operations. DOJ’s February 15, 2024 announcement reported the pleas.
That distinction matters: the guilty pleas establish Penchukov’s admissions to those conspiracy charges. The broader technical descriptions and harms below are DOJ’s account of the schemes and their effects; they should not be mistaken for a finding that every detail was separately admitted in the pleas.
How did Zeus steal banking credentials and move money?
According to DOJ, the Zeus enterprise began operating in May 2009 and infected thousands of business computers without authorization. The malware captured online-banking information such as account details, passwords and personal identification numbers. Conspirators allegedly used the stolen credentials to access victims’ accounts and falsely presented themselves to banks as the account holders’ employees authorized to make transfers. DOJ’s case account describes the transfer scheme.
#1 Best Overall
People in the United States and other countries acted as money mules: they received unauthorized funds and sent them onward to accounts controlled by co-conspirators. In practical terms, Zeus combined credential theft with deception at banks and a network for moving the proceeds.
What role did IcedID play?
DOJ said the IcedID, also known as Bokbot, conspiracy infected victim computers from at least November 2018 through February 2021. The malware collected and transmitted personal information, including bank credentials. It also gave other malicious software access to infected computers, including ransomware. That made the alleged role of IcedID broader than direct banking theft: it could also serve as an entry point for follow-on attacks.
One ransomware incident connected by DOJ to the broader IcedID conspiracy targeted the University of Vermont Medical Center. DOJ attributed more than $30 million in losses to that incident and said the hospital could not provide many critical patient services for more than two weeks, creating a risk of death or serious bodily injury. The figure concerns this hospital incident alone; it is not a total for the Zeus and IcedID operations.
How the two operations differed
| Operation | Period DOJ described | Alleged malware role | Penchukov’s plea |
|---|---|---|---|
| Zeus | Beginning in May 2009 | Stole online-banking credentials; conspirators allegedly used impersonation and money mules to route unauthorized transfers. | RICO conspiracy |
| IcedID/Bokbot | At least November 2018 through February 2021 | Collected personal information and bank credentials, and provided access for follow-on malware, including ransomware. | Wire-fraud conspiracy |
The time periods, methods and legal counts in the table reflect DOJ’s descriptions of the case, not an assertion that the malware families had no other uses or activity.
Rank #3
Arrest, extradition and what is known about sentencing
DOJ said Penchukov was arrested in Switzerland in 2022 and extradited to the United States in 2023. At the time it announced the pleas, DOJ said each count carried a maximum possible penalty of 20 years in prison and listed May 9, 2024, as the scheduled sentencing date. The release also said the judge would consider sentencing guidelines and statutory factors. Those were the maximum and scheduled date stated in February 2024, not the sentence imposed. A later DOJ Criminal Division fact sheet confirms the February 2024 conviction but does not establish the eventual prison sentence.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why the case matters beyond the malware names
The case illustrates two different routes from malware infection to harm. Zeus was described as a way to steal banking credentials and facilitate fraudulent transfers. IcedID was described as both an information-stealing malware and a means of enabling other malicious software, with the hospital ransomware incident demonstrating the possible impact on essential services. As U.S. Attorney Susan T. Lehr said in the February 15, 2024 DOJ announcement, “This case demonstrates that cybercrime can affect anyone, no matter where they are. It also demonstrates that no matter where the cybercriminals are, the department can and will bring them to justice.”
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

