Banking Trojan Developer Cases From Eastern Europe
Banking trojans operate as organized criminal enterprises with specialized roles, not lone hackers.

Alexander Konovolov didn't write a single line of GozNym's code. He ran it like a staffing agency. The Georgian national organized one of the most damaging banking trojan operations on record by recruiting specialists off Russian-language underground forums, the same way a contractor might post a job listing and wait for resumes. That's the detail prosecutors want you to sit with, because it undoes the lazy shorthand of "Eastern European hacker" as a single guy in a hoodie. Europol's own breakdown of the GozNym network lists bulletproof hosters, money mule networks, crypters, spammers, coders, organizers, and technical support as separate, recruited roles. Those are job titles, not personality traits. The case record describes a supply chain with hiring managers, specialists, and subcontractors, and treating it as anything simpler means missing most of what actually keeps it running.
How the Zeus prosecutions made the mule-network layer visible
The architecture goes back further than GozNym. Arrests in late September 2010 tied to the Zeus trojan put the mule layer on display in court filings for the first time, showing it as a distinct, managed workforce rather than a loose group of opportunists. More than eighty people were charged across federal and state courts in Manhattan, and prosecutors laid out how the mule tier worked: individuals from Russia, Ukraine, Kazakhstan, and Belarus entered the U.S. on J1 student visas, opened bank accounts under their real names, and got recruited through social-networking sites and newspaper ads. That's a formal hiring pipeline, built with the same tools a legitimate temp agency would use.
Almost everyone picked up in that sweep was a mule or one of four people managing mules. The developers writing the actual code, sitting in Eastern Europe, weren't touched. That gap in the investigation was the business model working as intended: the technical tier stays insulated from the cash-out tier by design.
Zeus itself had been identified back in July 2007, spreading through man-in-the-browser keystroke logging and form grabbing. By March 2009 it was everywhere, and Damballa estimated it had infected millions of PCs in the U.S. alone that year. That kind of scale doesn't come from one person running campaigns by hand. Noa Bar-Yosef, senior security strategist at Imperva at the time, explained the mechanics to reporters covering the 2010 arrests: criminals either ran their own botnets, or, more commonly, rented one from a "bot farmer" who built and maintained it separately. Renting infrastructure instead of owning it is the oldest trick in business, and the Zeus ecosystem had already figured that out by 2010. The architecture was mature a full decade before GozNym made headlines, and the identical pattern in later cases traces back to this same continuity.
GozNym, Trickbot, and the structural picture
If Zeus proved the mule layer was a managed workforce, GozNym and Trickbot proved the developer layer was too, and added something Zeus never showed: banking trojans turning into ransomware delivery systems.
Start with GozNym. Vladimir Gorin's role in the indictment wasn't "hacker." It was overseeing the creation, development, management, and leasing of the malware itself, a development-and-licensing function closer to a software vendor than a street criminal. GozNym worked as a keystroke logger and injected fake banking login pages into browsers to grab credentials. Around that core product sat a cast of specialists with their own job descriptions: a Bulgarian network member working as "casher," or account takeover specialist, using stolen credentials to break into accounts, while others handled laundering as "cash-outs" or "drop masters". Those are titles, as specific as anything on an org chart at a real financial firm, not underworld nicknames picked for flavor.
Trickbot is where the story turns. Vladimir Dunaev, a Russian national from Amur Oblast, got five years and four months in prison for developing and deploying Trickbot, which DOJ filings describe as a suite of tools built to steal money and help install ransomware, turning Trickbot from a fraud tool into general-purpose criminal infrastructure that could open the door for a ransomware crew down the line. Alla Witte, a Latvian national and Trickbot developer, pleaded guilty to conspiracy to commit computer fraud and got two years and eight months. Her case matters for a reason beyond her sentence: it shows the ecosystem's geography runs through Latvia and the Baltics, not just Russia.
The fugitive residual: why prosecution reaches the operator layer but structurally cannot close the developer tier
The same ceiling appears in Zeus, GozNym, and Trickbot alike. Prosecutors can reach the mules, the cashers, the account managers. The developers based in Russia stay out of reach because Russian law enforcement never appears on the list of cooperating countries.
Five Russian nationals charged in the GozNym indictment remain fugitives, Vladimir Gorin among them, the malware developer himself. The countries that cooperated on GozNym were the U.S., Germany, Georgia, Ukraine, Moldova, Bulgaria, Europol, and Eurojust. Russia wasn't one of them. The Zeus case tells the same story at larger scale: more than one hundred arrests across the U.S., UK, and Ukraine, and still no core developers in custody. The Zeus source code, instead of being seized, reportedly got handed off to a competitor in late 2010. Prosecution didn't just fail to reach the code. The code kept circulating.
GozNym itself got described as unprecedented, the first operation to launch criminal prosecutions in four countries at once. That's a real milestone in international cooperation, and it still didn't touch the people most responsible for building the malware. The lesson for anyone defending against these threats is that taking down the operator layer or the mule layer leaves the development-and-licensing business completely intact.
The 2026 Filimonov case and the Commerzbank operation: what active prosecutions show about how the model has adapted
None of this is historical. The most recent confirmed prosecutions show the same supply-chain structure running today, with the technical methods updated and the org chart basically unchanged.
Sergei Anatolyevich Filimonov was arraigned on September 8, 2026, and pleaded not guilty to running a scheme from November 2023 through October 2025. The operation used spoofed domains built to mimic federally insured financial institutions, bought sponsored search engine links to redirect banking customers onto fake login pages, and ran infrastructure that included interactive databases holding thousands of stolen credentials plus software built to capture and transmit login data. The FBI put total attempted losses in the tens of millions of dollars, with confirmed losses running roughly half that figure. Filimonov was extradited from the Republic of Georgia and faces a long potential sentence.
Separately, in August 2026, German and Brazilian authorities announced arrests tied to a November 2023 operation that pulled an estimated €30 million out of accounts at what BleepingComputer reported as Commerzbank. The method here wasn't phishing. It exploited a vulnerability introduced by a faulty software update at a payment and transaction-processing provider. The laundering network moved money through Brazil and four European countries, with arrests in Rio de Janeiro, Guarulhos, Goiânia, and Carapicuíba, and three more suspects headed for prosecution in Spain and Bulgaria. Bulgaria appears again, the same country that turned up in the GozNym case years earlier. The Record's coverage of the arrests added details that read almost like fiction: one suspect had run for elected office in 2024 using illicit funds, and police seized a 3-D printer used to manufacture weapons. Money laundering networks don't stay in their lane. They fund whatever else the people running them are into.
Technically, Filimonov's operation marks real evolution. Browser-injection keystroke logging has given way to search engine manipulation as the way in, buying ad placement instead of hijacking a form field. But strip away the method and the org chart reads exactly like GozNym's: a developer maintaining the infrastructure, co-conspirators running the fraud on top of it. The technology moves. The staffing structure doesn't.
How the malware adapts to published defender research
Malware developers in these ecosystems read security research the way a competitor reads your product roadmap, and they build against it.
Intel 471's analysis of TgToxic and its successor ToxicPanda found that payload changes "reflect the actors' ongoing surveillance of open source intelligence and demonstrate their commitment to enhancing the malware's capabilities to improve security measures and keep researchers at bay". That's about as direct a confirmation as researchers ever get: the people writing this malware are reading the writeups, and rewriting their code in response. BitSight tracked the same campaign in 2025 peaking at 4,500 infected devices as it spread across Europe.
Variants discovered in late 2024 added improved emulator detection, checking device hardware properties to spot when they're running in an analysis sandbox rather than on a real phone. The malware also moved away from hard-coded command-and-control domains toward a domain generation algorithm, so new domains get created automatically once old ones are seized. Each change answers a specific takedown method that had been made public.
BitSight's July 2025 analysis traced ToxicPanda's geographic path: Southeast Asia first, then a pivot to Europe starting in Italy in late 2024, with Portugal and Spain becoming the main targets by early 2025 as the botnet doubled in size. The malware overlays PIN and pattern codes on the screen and lets an operator remotely control a compromised device to push through unauthorized transfers. That's a shift toward a human operator driving fraud directly on the device, mimicking normal user behavior closely enough to slip past automated detection. The loop runs in both directions: defenders publish, developers read, developers patch around it, and each new wave of malware becomes harder to catch than the last.
Producing and timing threat intelligence content around the case architecture
The case files, put side by side, show the structure a security vendor needs to describe: developer, operator, casher, drop-master, bulletproof hosting, all mapped as separate layers. Content that only describes what the malware does on a device, without touching who built it and who ran it, leaves out the half of the picture that matters most for understanding how the threat survives an arrest. Anyone who's worked an actual incident will spot that gap in about one paragraph.
The TgToxic and ToxicPanda feedback loop raises the stakes on timing. Publishing command-and-control indicators before a coordinated takedown is complete hands developers exactly the signal they need to rotate infrastructure before defenders can act on it. The judgment call has to be made case by case, by someone who understands the threat, not by a content calendar built around keywords and publishing cadence.
ENISA's Finance Sector Threat Landscape, covering January 2023 through June 2024, found that attackers tailor campaigns to specific institutions closely enough that it demands continuous threat intelligence gathering and scenario planning, and the report recommends financial institutions share intelligence with each other rather than working in isolation. Vendors writing about this space need to hold themselves to that same standard if they want the CISOs and security engineers reading their work to take it seriously.
That audience runs a simple test. A security engineer reading a vendor's piece on banking trojans will know within a paragraph whether the writer understands that GozNym's five fugitive Russian developers are a permanent feature of how this threat works. Getting that right is the entry fee for being read at all by the people who actually defend against this stuff, and the case record above is the only thing that pays it.
Sources
- More Than 80 Arrested In Alleged Zeus Banking Scam
- ToxicPanda: The Android Banking Trojan Targeting Europe
- Investigation of banking hack leads to arrests in Europe, Brazil
- Hackers arrested over €30M bank fraud exploiting service provider flaw
- Zeus (malware)
- New TgToxic Banking Trojan Variant Evolves with Anti-Analysis Upgrades
- 0 ENISA THREAT LANDSCAPE: FINANCE SECTOR JANUARY 2023 TO JUNE 2024


