Malware-as-a-Service Developers Identified and Charged
Prosecutors now pursue malware developers by tracing code, money, and operational mistakes.

Malware-as-a-service runs on subscriptions, tiers, and affiliate networks, just like any SaaS product you'd find on a pricing page. That similarity is exactly the problem for investigators: developers write the code and collect the money, while affiliates do the actual breaking-and-entering. This piece walks through how prosecutors have started closing that gap, using five recent cases as the evidence.
Picture a dark web forum where a stealer kit comes with tiered pricing, a reputation score, and a review section that reads like Yelp for identity theft. This is the actual product structure behind DanaBot, Qakbot, and the ransomware kits sitting under names like ALPHV/BlackCat. Stealers and remote access trojans have remained among the most common malware types on underground forums, with Windows machines the primary target. BrandDefense reported credential theft rose more than 160% in 2025, driven by automated phishing and AI-assisted social engineering, meaning the volume problem is getting worse.
The full attack chain gets sold in pieces: initial access brokers, loaders, infostealers, phishing kits, ransomware, each as its own line item. Conti took that logic further than most, running distinct job titles and internal role assignments closer to a corporate org chart than a criminal gang. That structure is precisely what makes charging a developer so different from charging the person who clicked "deploy." Here's how investigators have actually done it.
What investigators are actually trying to prove when they charge a MaaS developer
Charging the person who wrote the code requires entirely different evidence than charging the person who used it on a victim. Prosecutors need to connect authorship, platform administration, or control of the money to a specific criminal result. Each of the common charges (conspiracy to commit computer fraud and abuse, wire fraud conspiracy, civil forfeiture) needs its own separate evidence thread to hold up. Building a case this way is a bit like assembling a chain-link fence: any single link can be flimsy, but string enough of them together and the whole thing holds weight.
The evidence usually comes from five places: cryptocurrency wallet tracing, infrastructure registration records, mistakes in operational security, code artifacts, and internal communications. None of these alone tends to be enough, but together they build a chain that survives a defense attorney poking holes in it.
Here's the part that doesn't get said out loud enough: most of the named defendants in these cases are Russian nationals who will never see a US courtroom. An indictment functions as a legal record, an asset seizure mechanism, and a diplomatic pressure tool, all stapled to the same document.
Bulletproof hosting providers used to get treated as background noise, the internet equivalent of a landlord who doesn't ask questions. Operators who knowingly host criminal infrastructure now get charged as co-conspirators, a shift that closes off what used to be a workable legal defense.
The Conti leak from February 2022, comprising tens of thousands of internal messages, showed why this works. Internal role assignments like "loader developer" turned into charging language almost verbatim. When a criminal organization keeps HR records, prosecutors get to use them, and it turns out even ransomware gangs can't escape performance reviews.
How DanaBot's developers unraveled their own anonymity
DanaBot was first identified in 2018. By 2025, the Department of Justice had charged 16 defendants tied to it, which gives you a sense of how long a malware family can run before the paperwork catches up.
The scale by the time charges landed was substantial: over 300,000 infected computers worldwide, at least $50 million in damages, roughly 1,000 new victims a day across more than 40 countries, and around 150 active tier-one command-and-control servers running on any given day. The FBI identified at least 40 paying affiliates, each handing over $3,000 to $4,000 a month for access. That subscription model, the same one that makes SaaS revenue predictable, left a financial paper trail investigators could follow.
Here's the detail that makes this case almost funny, in a grim way: several defendants got caught because they infected their own computers with DanaBot. The malware they built and administered pulled data off their own machines the same way it pulled data off victims' machines, likely handing investigators real IP addresses, device identifiers, browser credentials, and file artifacts. It's the digital version of a burglar leaving his wallet at the scene. Ask any investigator what the best kind of criminal is, and the answer's always the same: the one who trips over his own equipment. If convicted, the most culpable defendants face up to 72 years in prison.
DanaBot came down as part of a coordinated international law enforcement campaign, one investigation feeding the next.
How the Qakbot indictment was built across a decade of infrastructure tracking
Rustam Gallyamov, 48, of Moscow, got indicted in May 2025. Court documents allege he started building Qakbot back in 2008, which means investigators were tracking activity stretching back to around 2008 by the time charges landed. That's a case that got worn down, slowly, over almost two decades, the way water wears a groove into stone rather than a single crack splitting it in half.
An August 2023 takedown seized 52 servers, pulled the malware off more than 700,000 victim computers, and grabbed over $8.6 million in cryptocurrency at the time. Most people would call that the end of the story.
Gallyamov, allegedly, kept operating. The indictment claims he pivoted to "spam bomb" attacks as recently as January 2025, meaning he kept operating after his own infrastructure got dismantled. That detail matters legally, not just narratively: it extends the conspiracy timeline and knocks out any argument that he'd walked away from the business. The DOJ also filed a civil forfeiture complaint against more than $24 million in cryptocurrency tied to him, running the financial case in parallel with the criminal one.
Gallyamov is believed to still be in Russia, not in custody. The charges function as a hold and a record more than an arrest warrant, built with cooperation from France, Germany, the Netherlands, Denmark, the UK, and Canada.
Why bulletproof hosting operators are now treated as primary defendants, not infrastructure vendors
A December 2024 indictment, unsealed in July 2026, named three Russian nationals along with two associated companies, all charged in federal court. The alleged damage: more than $63 million across victims in 21 states, with the indictment accusing the defendants of supporting 17 separate criminal groups running ransomware, malware, or brute-force attacks.
This investigation stretched over years, with no single dramatic break and no self-infection moment, just sustained tracking of infrastructure over a long stretch of time. That's a different kind of case than DanaBot, and arguably a harder one to build.
The pressure didn't stop at an indictment. Coordinated sanctions followed, targeting the hosting companies and the named individuals. The State Department's Rewards for Justice program is offering up to $10 million for information on foreign government-linked associates. The legal theory behind all of it: hosting criminal infrastructure while knowing what it's for is conspiracy. That closes the "we just rent servers" defense for good.
For anyone tracking these threats professionally, bulletproof hosts are now worth watching directly. Their customer lists connect to multiple active threat actors at once, which makes them a high-value target rather than background plumbing.
What the BlackCat insider case reveals about attribution when the attacker already knows the defender's playbook
An indictment was filed that read less like a hacking case and more like a workplace betrayal story. Ryan Goldberg, a former incident response manager at Sygnia, and Kevin Martin, a ransomware negotiator at DigitalMint, got charged with deploying ALPHV/BlackCat ransomware against at least five US companies.
The attack sequence: a May 2023 hit on a Florida firm demanded $10 million and collected roughly $1.27 million in cryptocurrency; a July 2023 attack targeted a California medical practice for $5 million; more attacks followed in October and November 2023.
Here's what makes this one stand out. Both defendants had worked the defender's side of the table professionally, and they understood incident response procedures, ransom negotiation norms, and how forensic investigations usually unfold. Their operational security was shaped by that knowledge. In theory, that should have made them harder to catch than a typical affiliate.
They got caught anyway. Cryptocurrency tracing and identity linkages work regardless of how much you know about incident response; a blockchain ledger is permanent regardless of how sophisticated the person on the other end is. Insider knowledge of the defender's playbook proved worthless against a financial trail that records everything permanently. Knowing how the alarm system works is useless when the getaway car has a license plate made of glass.
The broader point here: Insider threat and external threat have blurred into a single category in the MaaS world. Affiliates include people with legitimate security credentials on their resume. That argues for behavioral and financial monitoring that accounts for technical sophistication on the other side.
How the Conti leak turned internal job titles into criminal charges
A loader developer who worked inside Conti pleaded guilty to wire fraud conspiracy. Conti, as an organization, is estimated to have collected at least $150 million from more than 1,000 victims, which puts the scale of that single criminal group somewhere near a mid-sized company's annual revenue.
The arrest came with tooling still active on the machine — a reminder that operational security has to hold up every single hour, including the routine ones.
The February 2022 Conti leak, tens of thousands of internal messages and documents, laid out organizational roles and task assignments in detail. That documentation became evidence. The defendant was charged specifically as a loader developer, because the leaked records and technical evidence supported that exact role.
The lesson for anyone sitting on leaked criminal data: once shared with law enforcement, it becomes the scaffolding for a prosecutorial timeline, narrowing a charge down to one function in a much longer attack chain.
The intelligence tradecraft behind successful MaaS prosecutions
Five patterns show up across these cases, and they repeat often enough to call them a playbook rather than coincidence.
First, operational security failure is usually the actual break in the case. DanaBot's defendants were exposed in part through their own infrastructure, and the Conti loader developer was caught with tooling still running. These people build sophisticated malware while remaining sloppy about their own digital hygiene.
Second, cryptocurrency is a permanent evidence trail. Every case here involved tracing crypto transactions, and blockchain's immutability is arguably the single most reliable tool against pseudonymous actors, regardless of how good they are technically.
Third, patience beats a single breakthrough. Qakbot got tracked from 2008 to 2025, and the bulletproof hosting case got built over years of sustained infrastructure tracking. Both cases got built through sustained collection over years.
Fourth, no recent major case was a solo US effort. Operation Endgame was a coordinated international effort, the Qakbot indictment pulled in seven nations, and the bulletproof hosting sanctions involved multiple governments acting together. Multinational coordination is the mechanism that makes these cases work at all.
Fifth, legal tools get stacked rather than used one at a time. Criminal charges, civil forfeiture, infrastructure seizure, sanctions, and domain takeovers (Microsoft seizing 2,300 Lumma Stealer domains, for instance) all run in parallel. And because most named defendants stay in Russia, the indictment itself becomes the deterrent: a legal record, an asset freeze, a travel restriction, and a basis for extradition if the person ever makes the mistake of leaving.
What this pattern of enforcement means for practitioners tracking MaaS threats
MaaS infrastructure has become a shared target. The bulletproof hosts, command-and-control networks, and affiliate payment rails that law enforcement investigates are the same infrastructure defenders should already be mapping, the same territory for cops and security teams alike.
Leaked criminal data (chat logs, internal documents, role assignments) deserves to be preserved as more than a source for indicators of compromise. It's potential evidence for a law enforcement referral down the line, and treating it that way from the start saves time later.
The BlackCat case is an argument for taking insider access as seriously as external threats, since the line between the two has gotten blurry enough that a former incident responder can end up on the other side of the table. Cryptocurrency tracing, meanwhile, belongs in a defender's attribution toolkit too, alongside its established role as a law enforcement tool.
None of this stays still for long. Lumma Stealer ranked as the most common infostealer in Microsoft's 2025 Digital Defense Report, and Qakbot has shown signs of reconstituting after its 2023 takedown. Disruption is temporary, so tracking whether a threat comes back matters just as much as tracking it the first time. The cases above are the operating manual for what happens next.


