ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

U.S. court sentences Russian hacker for running large-scale botnet operation

A U.S. District Court has sentenced a Russian national to two years in prison for managing a botnet operation to launch ransomware attacks on 70 U.S. corporations and extorting over $14 million in ransom payments.

 

The U.S. Department of Justice said in a press release that the Eastern District Court of Michigan sentenced 40-year-old Ilya Angelov for co-running a cybercrime group called "milan" and "okart" that used a network of compromised computers as a botnet to mount frequent ransomware attacks.

 

The group, also tracked by the FBI as Mario Kart and by cyber security researchers as TA-551, Shathak, GOLD CABIN, Monster Libra, ATK236, and G0127, compromised computer systems by delivered malware hidden in spam emails, and then sold access to the compromised machines to other malicious actors on the dark web to monetise the botnet.

 

Other criminal groups that purchased access to the botnet then used their access to launch ransomware attacks on U.S. corporations to lock victims out of their systems and demand ransom payments in cryptocurrency in exchange for sharing the decryption keys.

 

“The FBI has identified over 70 U.S. corporations that were infected with ransomware by one organization linked to Angelov’s group, resulting in over $14 million in extortion payments. Another group that distributed ransomware paid Angelov’s group over a million dollars for access to the Mario Kart botnet,” the Justice department said.

 

District Judge Nancy Edmunds, in addition to awarding a two-year prison sentence to Angelov, also fined him $100,000 and entered a $1.6 million money judgment against him.

 

“This successful investigation reflects the FBI’s ongoing commitment to identifying, tracking, and dismantling the criminal networks that financially exploit individuals and U.S. corporations,” said FBI Special Agent in Charge Jennifer Runyan.

 

The news of Angelov’s arrest comes not long after the Justice Department announced the takedown of the command-and-control infrastructure of four major botnets that were used by cyber criminals groups to mount large scale denial-of-service attacks against businesses and corporations worldwide.

 

The Department conducted a joint operation with law enforcement agencies from Canada and Germany to take down the isuru, KimWolf, JackSkid and Mossad IoT botnets that were used by criminal groups to infect millions of devices worldwide and then sell access to the infected devices to other criminal groups that used them to mount denial-of-service attacks.

 

“Court documents allege that the Aisuru botnet issued more than 200,000 DDoS attack commands, the KimWolf botnet issued more than 25,000 DDoS attack commands, the JackSkid botnet launched more than 90,000 DDoS attack commands and the Mossad botnet launched more than 1,000 DDoS attack commands,” the department said.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543