{"id":8131,"date":"2025-11-03T03:03:31","date_gmt":"2025-11-03T03:03:31","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/03\/alleged-jabber-zeus-coder-mricq-in-u-s-custody\/"},"modified":"2025-11-03T03:03:31","modified_gmt":"2025-11-03T03:03:31","slug":"alleged-jabber-zeus-coder-mricq-in-u-s-custody","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/03\/alleged-jabber-zeus-coder-mricq-in-u-s-custody\/","title":{"rendered":"Alleged Jabber Zeus Coder \u2018MrICQ\u2019 in U.S. Custody"},"content":{"rendered":"<p>    Alleged Jabber Zeus Coder \u2018MrICQ\u2019 in U.S. Custody<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A Ukrainian man indicted in 2012 for conspiring with a prolific hacking group to steal tens of millions of dollars from U.S. businesses was arrested in Italy and is now in custody in the United States, KrebsOnSecurity has learned.<\/p>\n<p>Sources close to the investigation say <strong>Yuriy Igorevich Rybtsov<\/strong>, a 41-year-old from the Russia-controlled city of Donetsk, Ukraine, was previously referenced in U.S. federal charging documents only by his online handle \u201c<strong>MrICQ<\/strong>.\u201d According to <a href=\"https:\/\/www.justice.gov\/iso\/opa\/resources\/2162014411104532407242.pdf\" target=\"_blank\" rel=\"noopener\">a 13-year-old indictment<\/a> (PDF) filed by prosecutors in Nebraska, MrICQ was a developer for a cybercrime group known as \u201c<strong>Jabber Zeus<\/strong>.\u201d<\/p>\n<div id=\"attachment_72498\" style=\"width: 759px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" loading=\"lazy\" aria-describedby=\"caption-attachment-72498\" decoding=\"async\" class=\" wp-image-72498\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2025\/11\/rybtsov-lockedup.png?resize=749%2C678&#038;ssl=1\" alt=\"\" width=\"749\" height=\"678\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/11\/rybtsov-lockedup.png 861w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/11\/rybtsov-lockedup-768x695.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/11\/rybtsov-lockedup-782x708.png 782w\" sizes=\"(max-width: 749px) 100vw, 749px\"><\/p>\n<p id=\"caption-attachment-72498\" class=\"wp-caption-text\">Image: lockedup dot wtf.<\/p>\n<\/div>\n<p>The Jabber Zeus name is derived from the malware they used \u2014 a custom version of the <a href=\"https:\/\/krebsonsecurity.com\/?s=zeus+trojan\" target=\"_blank\" rel=\"noopener\">ZeuS banking trojan<\/a> \u2014 that stole banking login credentials and would send the group a Jabber instant message each time a new victim entered a one-time passcode at a financial institution website. The gang targeted mostly small to mid-sized businesses, and they were an early pioneer of so-called \u201cman-in-the-browser\u201d attacks, malware that can silently intercept any data that victims submit in a web-based form.<\/p>\n<p>Once inside a victim company\u2019s accounts, the Jabber Zeus crew would modify the firm\u2019s payroll to add dozens of \u201cmoney mules,\u201d people recruited through elaborate work-at-home schemes to handle bank transfers. The mules in turn would forward any stolen payroll deposits \u2014 minus their commissions \u2014 via wire transfers to other mules in Ukraine and the United Kingdom.<\/p>\n<p>The 2012 indictment\u00a0targeting the Jabber Zeus crew named MrICQ as \u201c<strong>John Doe #3<\/strong>,\u201d and said this person handled incoming notifications of newly compromised victims. The Department of Justice (DOJ) said MrICQ also helped the group launder the proceeds of their heists through electronic currency exchange services.<\/p>\n<p>Two sources familiar with the Jabber Zeus investigation said Rybtsov was arrested in Italy, although the exact date and circumstances of his arrest remain unclear. A <a href=\"https:\/\/www.cortedicassazione.it\/resources\/cms\/documents\/Rassegna_mensile_MAGGIO_2025__settore_penale.pdf\" target=\"_blank\" rel=\"noopener\">summary of recent decisions<\/a> (PDF) published by the Italian Supreme Court states that in April 2025, Rybtsov lost a final appeal to avoid extradition to the United States.<\/p>\n<p>According to the mugshot website <strong>lockedup[.]wtf<\/strong>, Rybtsov arrived in Nebraska on October 9, and was being held under an arrest warrant from the <strong>U.S. Federal Bureau of Investigation<\/strong> (FBI).<\/p>\n<p>The data breach tracking service <a href=\"https:\/\/constella.ai\/\" target=\"_blank\" rel=\"noopener\">Constella Intelligence<\/a> found breached records from the business profiling site bvdinfo[.]com showing that a 41-year-old Yuriy Igorevich Rybtsov worked in a building at 59 Barnaulska St. in Donetsk. Further searching on this address in Constella finds the same apartment building was shared by a business registered to <strong>Vyacheslav \u201cTank\u201d Penchukov<\/strong>, the leader of the Jabber Zeus crew in Ukraine.<\/p>\n<div id=\"attachment_61804\" style=\"width: 753px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" aria-describedby=\"caption-attachment-61804\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-61804\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2022\/11\/tank-dj.png?resize=743%2C587&#038;ssl=1\" alt=\"\" width=\"743\" height=\"587\"><\/p>\n<p id=\"caption-attachment-61804\" class=\"wp-caption-text\">Vyacheslav \u201cTank\u201d Penchukov, seen here performing as \u201cDJ Slava Rich\u201d in Ukraine, in an undated photo from social media.<\/p>\n<\/div>\n<p>Penchukov was <a href=\"https:\/\/krebsonsecurity.com\/2022\/11\/top-zeus-botnet-suspect-tank-arrested-in-geneva\/\" target=\"_blank\" rel=\"noopener\">arrested in 2022<\/a> while traveling to meet his wife in Switzerland. Last year, a federal court in Nebraska <a href=\"https:\/\/www.wired.com\/story\/vyacheslav-igorevich-penchukov-tank-zeus-malware-sentencing\/\" target=\"_blank\" rel=\"noopener\">sentenced Penchukov to 18 years in prison<\/a> and ordered him to pay more than $73 million in restitution.<span id=\"more-72496\"><\/span><\/p>\n<p><strong>Lawrence Baldwin<\/strong> is founder of <a href=\"https:\/\/mynetwatchman.com\/\" target=\"_blank\" rel=\"noopener\">myNetWatchman<\/a>, a threat intelligence company based in Georgia that began tracking and disrupting the Jabber Zeus gang in 2009. myNetWatchman had secretly gained access to the Jabber chat server used by the Ukrainian hackers, allowing Baldwin to eavesdrop on the daily conversations between MrICQ and other Jabber Zeus members.<\/p>\n<p>Baldwin shared those real-time chat records with multiple state and federal law enforcement agencies, and with this reporter. Between 2010 and 2013, I spent several hours each day alerting small businesses across the country that their payroll accounts were about to be drained by these cybercriminals.<\/p>\n<p>Those notifications, and Baldwin\u2019s tireless efforts, saved countless would-be victims a great deal of money. In most cases, however, we were already too late. Nevertheless, the pilfered Jabber Zeus group chats provided the basis for dozens of stories published here about <a href=\"https:\/\/krebsonsecurity.com\/category\/smallbizvictims\/\" target=\"_blank\" rel=\"noopener\">small businesses fighting their banks<\/a> in court over six- and seven-figure financial losses.<\/p>\n<p>Baldwin said the Jabber Zeus crew was far ahead of its peers in several respects. For starters, their intercepted chats showed they worked to create a highly customized botnet directly with the author of the original Zeus Trojan \u2014 <strong>Evgeniy Mikhailovich Bogachev<\/strong>, a Russian man who has long been on the FBI\u2019s \u201cMost Wanted\u201d list. The feds have a <a href=\"https:\/\/krebsonsecurity.com\/2015\/02\/fbi-3m-bounty-for-zeus-trojan-author\/\" target=\"_blank\" rel=\"noopener\">standing $3 million reward<\/a> for information leading to Bogachev\u2019s arrest.<\/p>\n<div id=\"attachment_49974\" style=\"width: 753px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" aria-describedby=\"caption-attachment-49974\" decoding=\"async\" loading=\"lazy\" class=\"size-full wp-image-49974\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2019\/12\/bogachev.png?resize=743%2C456&#038;ssl=1\" alt=\"\" width=\"743\" height=\"456\"><\/p>\n<p id=\"caption-attachment-49974\" class=\"wp-caption-text\">Evgeniy M. Bogachev, in undated photos.<\/p>\n<\/div>\n<p>The core innovation of Jabber Zeus was an alert that MrICQ would receive each time a new victim entered a one-time password code into a phishing page mimicking their financial institution. The gang\u2019s internal name for this component was \u201c<strong>Leprechaun<\/strong>,\u201d (the <a href=\"https:\/\/www.youtube.com\/watch?v=UiAg3puABeA\" target=\"_blank\" rel=\"noopener\">video below<\/a> from myNetWatchman shows it in action). Jabber Zeus would actually re-write the HTML code as displayed in the victim\u2019s browser, allowing them to intercept any passcodes sent by the victim\u2019s bank for multi-factor authentication.<\/p>\n<p>\u201cThese guys had compromised such a large number of victims that they were getting buried in a tsunami of stolen banking credentials,\u201d Baldwin told KrebsOnSecurity. \u201cBut the whole point of Leprechaun was to isolate the highest-value credentials \u2014 the commercial bank accounts with two-factor authentication turned on. They knew these were far juicier targets because they clearly had a lot more money to protect.\u201d<\/p>\n<p><iframe loading=\"lazy\" title=\"YouTube video player\" src=\"https:\/\/www.youtube.com\/embed\/UiAg3puABeA?si=pEHck5AXQ5mBKhz9\" width=\"740\" height=\"315\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/p>\n<p>Baldwin said the Jabber Zeus trojan also included a custom \u201cbackconnect\u201d component that allowed the hackers to relay their bank account takeovers through the victim\u2019s own infected PC.<\/p>\n<p>\u201cThe Jabber Zeus crew were literally connecting to the victim\u2019s bank account from the victim\u2019s IP address, or from the remote control function and by fully emulating the device,\u201d he said. \u201cThat trojan was like a hot knife through butter of what everyone thought was state-of-the-art secure online banking at the time.\u201d<\/p>\n<p>Although the Jabber Zeus crew was in direct contact with the Zeus author, the chats intercepted by myNetWatchman show Bogachev frequently ignored the group\u2019s pleas for help. The government says the real leader of the Jabber Zeus crew was <strong>Maksim Yakubets<\/strong>, a 38-year Ukrainian man with Russian citizenship who went by the hacker handle \u201c<strong>Aqua<\/strong>.\u201d<\/p>\n<div id=\"attachment_49935\" style=\"width: 760px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" aria-describedby=\"caption-attachment-49935\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-49935\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2019\/12\/yukabets.png?resize=750%2C611&#038;ssl=1\" alt=\"\" width=\"750\" height=\"611\"><\/p>\n<p id=\"caption-attachment-49935\" class=\"wp-caption-text\">Alleged Evil Corp leader Maksim \u201cAqua\u201d Yakubets. Image: FBI<\/p>\n<\/div>\n<p>The Jabber chats intercepted by Baldwin show that Aqua interacted almost daily with MrICQ, Tank and other members of the hacking team, often facilitating the group\u2019s money mule and cashout activities remotely from Russia.<\/p>\n<p>The government says Yakubets\/Aqua would later emerge as the leader of an elite cybercrime ring of at least 17 hackers that referred to themselves internally as \u201c<strong>Evil Corp<\/strong>.\u201d Members of Evil Corp developed and used the <strong>Dridex<\/strong> (a.k.a. <strong>Bugat<\/strong>) trojan, which helped them siphon more than $100 million from hundreds of victim companies in the United States and Europe.<\/p>\n<p><a href=\"https:\/\/krebsonsecurity.com\/2019\/12\/inside-evil-corp-a-100m-cybercrime-menace\/\" target=\"_blank\" rel=\"noopener\">This 2019 story about the government\u2019s $5 million bounty<\/a> for information leading to Yakubets\u2019s arrest includes excerpts of conversations between Aqua, Tank, Bogachev and other Jabber Zeus crew members discussing stories I\u2019d written about their victims. Both Baldwin and I were interviewed at length for a new weekly six-part podcast by the <strong>BBC<\/strong> that delves deep into the history of Evil Corp. <a href=\"https:\/\/www.bbc.com\/audio\/play\/w3ct89y8\" target=\"_blank\" rel=\"noopener\">Episode One<\/a> focuses on the evolution of Zeus, while <a href=\"https:\/\/www.bbc.com\/audio\/play\/w3ct89y9\" target=\"_blank\" rel=\"noopener\">the second episode<\/a> centers on an investigation into the group by former FBI agent <strong>Jim Craig<\/strong>.<\/p>\n<div id=\"attachment_72504\" style=\"width: 757px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" aria-describedby=\"caption-attachment-72504\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-72504\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2025\/11\/bbc-cyberhack.png?resize=747%2C423&#038;ssl=1\" alt=\"\" width=\"747\" height=\"423\"><\/p>\n<p id=\"caption-attachment-72504\" class=\"wp-caption-text\">Image: https:\/\/www.bbc.co.uk\/programmes\/w3ct89y8<\/p>\n<\/div>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    BrianKrebs<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/krebsonsecurity.com\/2025\/11\/alleged-jabber-zeus-coder-mricq-in-u-s-custody\/\">Go to krebsonsecurity<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Alleged Jabber Zeus Coder \u2018MrICQ\u2019 in U.S. Custody A Ukrainian man indicted in 2012 for conspiring with a prolific hacking group to steal tens of millions of dollars from U.S. businesses was arrested in Italy and is now in custody in the United States, KrebsOnSecurity has learned. Sources close to the investigation say Yuriy Igorevich [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[188,1993,1994,1995,1996,1997,1998,1454,1999,2000,55,2001,2002,2003,2004,190,1612,690,2005,2006,2007],"tags":[72],"class_list":["post-8131","post","type-post","status-publish","format-standard","hentry","category-a-little-sunshine","category-aqua","category-bbc","category-bugat","category-dridex","category-evgeniy-mikhailovich-bogachev","category-evil-corp","category-federal-bureau-of-investigation","category-jabber-zeus","category-jim-craig","category-krebsonsecurity","category-lawrence-baldwin","category-leprechaun","category-maksim-yakubets","category-mricq","category-neer-do-well-news","category-target-small-businesses","category-u-s-department-of-justice","category-vyacheslav-tank-penchukov","category-yuriy-igorevich-rybtsov","category-zeus-trojan","tag-krebsonsecurity"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8131"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8131"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8131\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8131"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8131"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8131"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}