Romanian National Known As “Virus” Extradited For Operating “Bulletproof Hosting” Service That Facilitated The Distribution Of Destructive Malware
Mihai Ionut Paunescu, known as 'Virus,' a dual Romanian-Latvian national, was extradited from Colombia to the U.S. for operating a bulletproof hosting service that enabled the distribution of the Gozi Virus and other malware, infecting over one million computers—including NASA systems—and causing tens of millions in losses, and now faces up to 60 years in prison on conspiracy charges for computer intrusion, bank fraud, and wire fraud.
Mihai Ionut Paunescu, known as 'Virus,' operated a bulletproof hosting service that provided cybercriminals with anonymous server infrastructure to distribute the Gozi Virus, Zeus Trojan, and SpyEye Trojan, infecting over one million computers globally, including at least 40,000 in the U.S. and systems at NASA. The malware stole banking credentials, enabling unauthorized fund transfers that resulted in tens of millions of dollars in losses. Paunescu is charged with conspiracy to commit computer intrusion, bank fraud, and wire fraud, carrying a combined maximum penalty of 60 years in prison, after being extradited from Colombia following an initial 2012 arrest in Romania.
Mihai Ionut Paunescu, a dual Romanian and Latvian national known as 'Virus,' was extradited from Colombia to the United States to face charges for operating a bulletproof hosting service that enabled global cybercriminal activity. His service provided anonymous IP addresses, servers, and command-and-control infrastructure to distribute destructive malware including the Gozi Virus, Zeus Trojan, and SpyEye Trojan, which infected over one million computers worldwide—including systems at NASA—and caused tens of millions of dollars in losses by stealing banking credentials and facilitating fraudulent fund transfers. Paunescu actively evaded detection by monitoring and relocating customer data across international networks to avoid blacklisting, while also supporting DDoS attacks and spam distribution. He was first arrested in Romania in December 2012 but released on bail, only to be apprehended again in Colombia in 2021 at the request of U.S. authorities. Presented before a U.S. magistrate in Manhattan, he was detained pending trial and now faces three federal conspiracy charges: computer intrusion (max 10 years), bank fraud (max 30 years), and wire fraud (max 20 years), for a potential total sentence of 60 years. The case underscores the U.S. Department of Justice’s commitment to pursuing cybercriminals internationally, with critical cooperation from Colombian police, NASA’s Office of Inspector General, and the FBI.
Extracted insights
- agency assistant director-in-charge of new york field office of fbi
- person bulletproof hosting service
- person colombia last year
- person damian williams
- person ddos attacks
- person gozi virus
- person michael j. driscoll
- person mihai ionut paunescu
- person personal bank account information
- Mihai Ionut Paunescu extradited from Colombia
- Mihai Ionut Paunescu operated Bulletproof Hosting Service
- Bulletproof Hosting Service facilitated distribution of Gozi Virus
- Gozi Virus infected Over 1 Million Computers Worldwide
- Gozi Virus caused losses of Tens of Millions of Dollars
- Mihai Ionut Paunescu arrested in Romania in December 2012
- Mihai Ionut Paunescu arrested in Colombia Last Year
- Mihai Ionut Paunescu enabled distribution of Zeus Trojan and SpyEye Trojan
- Mihai Ionut Paunescu enabled DDoS Attacks
- Gozi Virus infected At Least 40,000 Computers in United States
- Gozi Virus stole Personal Bank Account Information
- Damian Williams is United States Attorney for Southern District of New York
- Michael J. Driscoll is Assistant Director-in-Charge of New York Field Office of FBI
- Mihai Ionut Paunescu is national of Romania and Latvia
- Case assigned to U.S. District Judge Lorna G. Schofield
Press Release Romanian National Known As “Virus” Extradited For Operating “Bulletproof Hosting” Service That Facilitated The Distribution Of Destructive Malware Tuesday, July 19, 2022 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Damian Williams, the United States Attorney for the Southern District of New York, and Michael J. Driscoll, the Assistant Director-in-Charge of the New York Field Office of the Federal Bureau of Investigation (“FBI”), announced today that MIHAI IONUT PAUNESCU, a/k/a “Virus,” a dual Romanian and Latvian national, was extradited from Colombia for allegedly running a “bulletproof hosting” service that enabled cyber criminals to distribute the Gozi Virus, one of the most financially destructive computer viruses in history. PAUNESCU also allegedly enabled other cybercrimes, such as distributing malware including the “Zeus Trojan” and the “SpyEye Trojan,” initiating and executing distributed denial of service (“DDoS”) attacks, and transmitting spam. PAUNESCU was initially arrested in Romania in December 2012 and released on bail, and he was arrested again in Colombia last year at the request of the United States. PAUNESCU was presented yesterday before U.S. Magistrate Judge Gabriel W. Gorenstein and detained. The case is assigned to U.S. District Judge Lorna G. Schofield. U.S. Attorney Damian Williams said: “Mihai Ionut Paunescu is alleged to have run a “bulletproof hosting” service that enabled cyber criminals throughout the world to spread the Gozi Virus and other malware and to commit numerous other cybercrimes. His hosting service was specifically designed to allow cyber criminals to remain hidden and anonymous from law enforcement. Even though he was initially arrested in 2012, Paunescu will finally be held accountable inside a U.S. courtroom. This case demonstrates that we will work with our law enforcement partners here and abroad to pursue cyber criminals who target Americans, no matter how long it takes.” According to allegations in documents filed in Manhattan federal court[1]: The Gozi Virus is malicious computer code or “malware” that stole personal bank account information, including usernames and passwords, from the users of affected computers. The Gozi Virus infected over one million victim computers worldwide, among them at least 40,000 computers in the United States, including computers belonging to the National Aeronautics and Space Administration (“NASA”), as well as computers in Germany, Great Britain, Poland, France, Finland, Italy, Turkey and elsewhere, and it caused tens of millions of dollars in losses to the individuals, businesses, and government entities whose computers were infected. Once installed, the Gozi Virus – which was intentionally designed to be undetectable by anti-virus software – collected data from the infected computer in order to capture personal bank account information, including usernames and passwords. That data was then transmitted to various computer servers controlled by the cyber criminals who used the Gozi Virus. These cyber criminals then used the personal bank account information to transfer funds out of the victims’ bank accounts and ultimately into their own personal possession. “Bulletproof hosting” services helped cyber criminals distribute the Gozi Virus with little fear of detection by law enforcement. Bulletproof hosts provided cyber criminals using the Gozi Virus with the critical online infrastructure they needed, such as Internet Protocol (“IP”) addresses and computer servers, in a manner designed to enable them to preserve their anonymity. PAUNESCU operated a “bulletproof hosting” service that helped cyber criminals distribute the Gozi Virus and commit other cybercrimes, such as distributing malware including the “Zeus Trojan” and the “SpyEye Trojan,” initiating and executing DDoS attacks, and transmitting spam. PAUNESCU rented servers and IP addresses from legitimate Internet service providers and then in turn rented them to cyber criminals; provided servers that cyber criminals used as command-and-control servers to conduct DDoS attacks; monitored the IP addresses that he controlled to determine if they appeared on a special list of suspicious or untrustworthy IP addresses; and relocated his customers’ data to different networks and IP addresses, including networks and IP addresses in other countries, to avoid being blocked as a result of private security or law enforcement scrutiny. * * * PAUNESCU, 37, of Bucharest, Romania, is charged with one count of conspiracy to commit computer intrusion, which carries a maximum penalty of 10 years in prison; one count of conspiracy to commit bank fraud, which carries a maximum penalty of 30 years in prison; and one count of conspiracy to commit wire fraud, which carries a maximum penalty of 20 years in prison. The maximum and minimum potential sentences are prescribed by Congress and are provided here for informational purposes only, as any sentencing of the defendant will be determined by the judge. Mr. Williams praised the investigative work of the FBI. Mr. Williams also thanked the NASA Office of Inspector General, and the Columbian National Police. In addition, Mr. Williams thanked the Department of Justice’s Computer Crime and Intellectual Property Section (CCIPS) for its partnership in this matter. The U.S. Department of Justice’s Office of International Affairs of the Department’s Criminal Division, the Narcotic and Dangerous Drug Section (NDDS) Judicial Attachés in Bogota, Colombia, and the U.S. Marshal Service provided significant assistance in securing the defendant’s extradition from Colombia. This case is being handled by the Office’s Complex Frauds & Cybercrime Unit. Assistant United States Attorney Sarah Lai is in charge of the prosecution. The charges contained in the Indictment are merely accusations and the defendant is presumed innocent unless and until proven guilty. [1] As the introductory phrase signifies, the entirety of the text of the Indictment constitutes only allegations, and every fact described herein should be treated as an allegation. Contact Nicholas Biase (212) 637-2600 Updated July 22, 2022 Topic Cybercrime Component USAO - New York, Southern Press Release Number: 22-228
Press Release Romanian National Known As “Virus” Extradited For Operating “Bulletproof Hosting” Service That Facilitated The Distribution Of Destructive Malware Tuesday, July 19, 2022 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Damian Williams, the United States Attorney for the Southern District of New York, and Michael J. Driscoll, the Assistant Director-in-Charge of the New York Field Office of the Federal Bureau of Investigation (“FBI”), announced today that MIHAI IONUT PAUNESCU, a/k/a “Virus,” a dual Romanian and Latvian national, was extradited from Colombia for allegedly running a “bulletproof hosting” service that enabled cyber criminals to distribute the Gozi Virus, one of the most financially destructive computer viruses in history. PAUNESCU also allegedly enabled other cybercrimes, such as distributing malware including the “Zeus Trojan” and the “SpyEye Trojan,” initiating and executing distributed denial of service (“DDoS”) attacks, and transmitting spam. PAUNESCU was initially arrested in Romania in December 2012 and released on bail, and he was arrested again in Colombia last year at the request of the United States. PAUNESCU was presented yesterday before U.S. Magistrate Judge Gabriel W. Gorenstein and detained. The case is assigned to U.S. District Judge Lorna G. Schofield. U.S. Attorney Damian Williams said: “Mihai Ionut Paunescu is alleged to have run a “bulletproof hosting” service that enabled cyber criminals throughout the world to spread the Gozi Virus and other malware and to commit numerous other cybercrimes. His hosting service was specifically designed to allow cyber criminals to remain hidden and anonymous from law enforcement. Even though he was initially arrested in 2012, Paunescu will finally be held accountable inside a U.S. courtroom. This case demonstrates that we will work with our law enforcement partners here and abroad to pursue cyber criminals who target Americans, no matter how long it takes.” According to allegations in documents filed in Manhattan federal court[1]: The Gozi Virus is malicious computer code or “malware” that stole personal bank account information, including usernames and passwords, from the users of affected computers. The Gozi Virus infected over one million victim computers worldwide, among them at least 40,000 computers in the United States, including computers belonging to the National Aeronautics and Space Administration (“NASA”), as well as computers in Germany, Great Britain, Poland, France, Finland, Italy, Turkey and elsewhere, and it caused tens of millions of dollars in losses to the individuals, businesses, and government entities whose computers were infected. Once installed, the Gozi Virus – which was intentionally designed to be undetectable by anti-virus software – collected data from the infected computer in order to capture personal bank account information, including usernames and passwords. That data was then transmitted to various computer servers controlled by the cyber criminals who used the Gozi Virus. These cyber criminals then used the personal bank account information to transfer funds out of the victims’ bank accounts and ultimately into their own personal possession. “Bulletproof hosting” services helped cyber criminals distribute the Gozi Virus with little fear of detection by law enforcement. Bulletproof hosts provided cyber criminals using the Gozi Virus with the critical online infrastructure they needed, such as Internet Protocol (“IP”) addresses and computer servers, in a manner designed to enable them to preserve their anonymity. PAUNESCU operated a “bulletproof hosting” service that helped cyber criminals distribute the Gozi Virus and commit other cybercrimes, such as distributing malware including the “Zeus Trojan” and the “SpyEye Trojan,” initiating and executing DDoS attacks, and transmitting spam. PAUNESCU rented servers and IP addresses from legitimate Internet service providers and then in turn rented them to cyber criminals; provided servers that cyber criminals used as command-and-control servers to conduct DDoS attacks; monitored the IP addresses that he controlled to determine if they appeared on a special list of suspicious or untrustworthy IP addresses; and relocated his customers’ data to different networks and IP addresses, including networks and IP addresses in other countries, to avoid being blocked as a result of private security or law enforcement scrutiny. * * * PAUNESCU, 37, of Bucharest, Romania, is charged with one count of conspiracy to commit computer intrusion, which carries a maximum penalty of 10 years in prison; one count of conspiracy to commit bank fraud, which carries a maximum penalty of 30 years in prison; and one count of conspiracy to commit wire fraud, which carries a maximum penalty of 20 years in prison. The maximum and minimum potential sentences are prescribed by Congress and are provided here for informational purposes only, as any sentencing of the defendant will be determined by the judge. Mr. Williams praised the investigative work of the FBI. Mr. Williams also thanked the NASA Office of Inspector General, and the Columbian National Police. In addition, Mr. Williams thanked the Department of Justice’s Computer Crime and Intellectual Property Section (CCIPS) for its partnership in this matter. The U.S. Department of Justice’s Office of International Affairs of the Department’s Criminal Division, the Narcotic and Dangerous Drug Section (NDDS) Judicial Attachés in Bogota, Colombia, and the U.S. Marshal Service provided significant assistance in securing the defendant’s extradition from Colombia. This case is being handled by the Office’s Complex Frauds & Cybercrime Unit. Assistant United States Attorney Sarah Lai is in charge of the prosecution. The charges contained in the Indictment are merely accusations and the defendant is presumed innocent unless and until proven guilty. [1] As the introductory phrase signifies, the entirety of the text of the Indictment constitutes only allegations, and every fact described herein should be treated as an allegation. Contact Nicholas Biase (212) 637-2600 Updated July 22, 2022 Topic Cybercrime Component USAO - New York, Southern Press Release Number: 22-228