The ProtectedGround Zero · The Crew That Became the Bloodline

The Business Club

GameOver Zeus · CryptoLocker · 2009–2014

By day they emptied the bank accounts of American companies. By night one of them was a wedding DJ, another was drag-racing through Moscow, and their boss was photographed on a boat off the Black Sea coast. They were a crew before they were a syndicate. A decade later their names sit at the head of almost every major Russian ransomware operation. This is who they were.

By Reno July 2026 14 min read Open Research
Vyacheslav Penchukov, alias Tank, in custody Vyacheslav Penchukov, alias “Tank” · editorial treatment, arrest and sentencing coverage

Start with the people, because the people are the point.

In the years around 2010, a loose crew of Russians and Ukrainians was stealing tens of millions of dollars from banks and businesses in the United States and Britain, and living, more or less, like anyone else their age. Their ringleader on the operational side, a young man from Donetsk, ran the theft during working hours and moonlighted as a nightclub DJ under the name “DJ Slava Rich.” Viktor Yanukovych Jr., son of Ukraine’s president at the time, was godfather to his daughter. Their money man drove a Lamborghini and would, a few years on, pose for a photograph holding a fat stack of cash with his face half-hidden behind his hand. Their architect, the quiet one who actually wrote the malware, liked boats and cats and kept a home near the Black Sea. Credible

They called themselves, in their own chat logs, the Business Club. It was not a brand or a forum handle. It was what a few dozen criminals called the thing they had built together: an invitation-only outfit with a core of trusted principals, a wider ring of specialists, an entry fee, and a profit-sharing agreement. You did not join it by buying a kit. You joined it by being vouched for, and you earned full access over time. Credible

This file is a group biography, and the origin point of everything else in The Protected. Almost everyone who came later started in this room. Two of its principals have their own profiles in this series and appear here only in outline. The people this profile lingers on are the ones who do not get their own page: the coordinator, the coders, the launderers, the mule managers, the men who built the plumbing and then carried it into everything that followed.

Tank

The coordinator was Vyacheslav Penchukov, and inside the crew he was “tank,” sometimes “father.” He is the one member the West eventually put in a cell, and the fullest human portrait we have of the Business Club comes from him, because in 2025 he sat down with the BBC for six hours from a federal prison in Colorado and talked. Confirmed

Penchukov was a sociable, heavyset man from Donetsk, genuinely liked by the people around him: a former boxer and footballer, well read, calm, and (by one fellow DJ’s account) more interested in the music than the partying. “I am a friendly guy, I make friends easily,” he told the BBC, and then, a beat later, the professional truth underneath it: “You can’t make friends in cyber-crime, because the next day, your friends will be arrested and become an informant.” He ran the movement of stolen credentials and the mule network by day and spun records at night. His protection, for years, was not Russian but Ukrainian: that same connection to the president’s son, plus a 2010 tip-off, helped him slip a police raid. Credible

“You can’t make friends in cyber-crime. Paranoia is a constant friend of hackers.”

That is the thread worth holding onto about Tank. He was not caught for lack of evidence. He was caught the moment he left his protection. He traveled to Geneva in 2022 and was arrested there in October of that year, and he describes the arrest as a shock staged for his family: “They put me on the ground in front of my kids. There were snipers on the roof.” He pleaded guilty in February 2024 and was sentenced that July to nine years, with restitution and forfeiture together approaching $74 million. Confirmed He expressed remorse for exactly one of his victims, a charity for disabled children, and argued the rest had been made whole by insurance. That last part is his own telling, vivid but self-serving. Credible

The architect and the money man

Evgeniy Bogachev, “Slavik,” was the crew’s center of gravity and the one who wrote the malware. Fox-IT, whose 2015 study of the group remains the definitive account, found that the Business Club had two leaders at its core, and one of them was him. He was reclusive where Tank was gregarious, known to enjoy boating on the Black Sea and to keep property near Anapa in southern Russia. He held something none of the others did: the sole key that could command the entire botnet, so that even inside his own club, no one could run the full network without him. He has never been arrested, and the reward on him reached $3 million in 2015, at the time the highest ever offered for a cybercriminal. He is the nearest thing this whole story has to a Patient Zero, and his own profile tells the rest. Confirmed

Maksim Yakubets, “aqua,” ran the money. He recruited and managed the mules who turned stolen credentials into cash, and he did it with a flamboyance the others avoided: the Lamborghini whose vanity plate read “vor,” the Russian word for thief, a reported lavish wedding, the now-famous photograph with the stack of banknotes. He married into influence; his father-in-law was a former officer of the FSB’s elite Vympel unit. When the Business Club era ended, Yakubets did not retire. He built the successor, Evil Corp, and became one of the most heavily sanctioned cybercriminals in the world, with a $5 million reward on his head. His own profile carries that story. Confirmed

The rest of the room

Yuriy Rybtsov, “MrICQ,” was a coder from Donetsk, and for years he was a blank on the public record: charged in the 2012 Nebraska indictment only by his handle, one of three John Does with no face. To investigators, he was almost certainly not a mystery for nearly as long. You do not arrest a man in Italy and then find out he is MrICQ; the arrest happened because US authorities had already tied the handle to Rybtsov, which is what made the extradition possible. Analyst inference He was detained in Italy, lost his final appeal against extradition in April 2025, and arrived in US custody in Nebraska that October, photographed in an orange jumpsuit, a middle-aged man with graying hair and glasses. He is the most recent member of the crew to be brought in, more than a decade after the fact, and his case was still unfolding at the time of writing. Confirmed

Yevhen Kulibaba (“jonni”) and Yuriy Konovalenko (“jtk0”) were the crew’s British cell, collecting stolen banking data and running the mule accounts that cashed out the UK side of the operation. They were convicted in Britain, extradited to the United States in 2014, and given short sentences they have long since served. Older accounts called Kulibaba the ringleader of the whole enterprise; the better reading, and the one the crew’s own hierarchy supports, puts the leadership with Bogachev, Penchukov, and Yakubets, not him. Confirmed

Ivan Klepikov, “petr0vich,” was the system administrator, a Donetsk man who kept the infrastructure running. He was picked up in the 2010 raids and then let go, because Ukraine’s constitution forbids extraditing its own citizens, and he was never handed over. Alexey Bron, “thehead,” handled the money settlement layer and was, by the account of one researcher who read the intercepts, almost disarmingly honest about himself in chat, giving out a real email address that checked out. He is a fugitive still, Ukrainian, born around 1988. Alexey Tikonov, “kusanagi,” was a coder and the only Russian national among the core defendants, based in the Siberian city of Tomsk. He has never been reported arrested, and he has quietly disappeared from the FBI’s current wanted page. Confirmed What that disappearance means is anyone’s guess. Analyst inference

Fig. 1 · The core of the room
BogachevBogachev
YakubetsYakubets
PenchukovPenchukov
RybtsovRybtsov
The architect, the money man, the coordinator, and the coder. Evgeniy Bogachev (“Slavik”); Maksim Yakubets (“aqua”), in the cash photograph that became his signature image; Vyacheslav Penchukov (“Tank”); Yuriy Rybtsov (“MrICQ”), extradited to the US in October 2025. Sources: FBI, US State Department, and press materials.

What bound them

The Business Club held together the way an organized-crime family does, not the way an online forum does. Fox-IT described a core of a couple of leaders sitting above a support crew and a set of preferred suppliers, more than fifty people in all, each with a specialty: one man for fraud execution, one for mule recruitment, one for technical support, one to supply the extra crimeware. New members paid to get in and agreed to share their proceeds with the core. Trust was rationed. You were given menial tasks first and full access only once you had proven reliable. The whole thing ran on a private Jabber server the group kept for itself, at an address that told you exactly how they saw themselves: businessclub.so. Credible It ran less like a gang than a company, with separate teams for malware, quality control, and cash-out, and even a help desk for members. What the lineage inherited was not only the people but this corporate structure, the same departmental model Conti would industrialize a decade later. Analyst inference

Fig. 2 · The crew and where they ended up
NameHandleRoleWhere they are now
Evgeniy Bogachev ↗ own profileSlavikArchitect; sole master key-holderAt large, Russia; $3M reward
Maksim Yakubets ↗ own profileaquaMoney and mules; founded Evil CorpAt large, Russia; $5M reward
Vyacheslav Penchukovtank, fatherCoordinator; DJ; later led IcedIDUS federal prison, 9 years
Yuriy RybtsovmricqCoder; victim alerts; launderingUS custody, Nebraska, 2025
Yevhen KulibabajonniUK cell leadServed UK/US term; released
Yuriy Konovalenkojtk0UK mule coordinationServed term; released
Ivan Klepikovpetr0vichSystem administratorUkraine; not extradited
Alexey BrontheheadWebMoney settlementAt large; on FBI poster
Alexey TikonovkusanagiCoderAt large (Tomsk, Russia)
The working membership as named in the US charging documents and Fox-IT’s research. Two carry their own profiles in this series. Sources: DOJ (District of Nebraska), FBI, Fox-IT.

What they built and what they stole

The tool that made all of it possible was a piece of banking malware called GameOver Zeus, and the one thing worth understanding about it is that it was theirs alone. Earlier versions of Zeus were sold as kits on criminal markets; GameOver was closed, custom, and available to no one outside the club. It was also built to survive. Where earlier botnets were killed by seizing their command servers, GameOver was designed with no single server to seize, which is why it took an international operation to bring it down. At any moment it controlled hundreds of thousands of infected computers around the world. Confirmed

The money came out through business bank accounts. Once the malware was on a company’s computer, the crew could ride the victim’s own online-banking session and move money out by ordinary bank transfer, prompting the victim in real time for any security codes the bank asked for. The losses were named and specific: a Pennsylvania plastics manufacturer, Haysite Reinforced Plastics, lost a fraudulent transfer of almost $200,000; the government of Bullitt County, Kentucky, lost $415,000. Across its life the FBI put GameOver Zeus behind more than $100 million in losses in the United States alone, and Fox-IT, watching the group hit banks in many countries, judged the true worldwide figure higher. Confirmed

In 2013 Bogachev turned the same botnet to a new purpose and pushed out CryptoLocker, the ransomware that taught the criminal world that encrypting a victim’s files and demanding payment could work at scale. It hit more than 234,000 computers, asked $300 to $400 a head in Bitcoin or prepaid vouchers, and, by Fox-IT’s estimate, netted its operators around $3 million. Confirmed It was, in a real sense, the ancestor of the entire modern ransomware economy, and it was invented as a side hustle by a bank-fraud crew looking for a second revenue stream. Analyst inference

The money, and why it is the interesting part

If there is one place this crew’s tradecraft still matters for anyone thinking about how to hit their descendants, it is the cash-out. The malware was never the hard part. Turning stolen access into spendable money, moving it out of reach, and getting it home to Russia was, and the Business Club was unusually disciplined about it. Analyst inference

They ran two separate classes of money mule. The disposable kind were ordinary people recruited through fake work-from-home job offers, used to withdraw small sums and burned through as their accounts got flagged; the FBI counted more than 3,500 of them in this era. The valuable kind were dedicated corporate accounts, set up with real care to move hundreds of thousands or millions at a time, checked against fraud blacklists before use so a good account was never wasted, and opened by trusted associates in China, Hong Kong, Cyprus, and Latvia. Credible That second tier, scarce, expensive, and insider-dependent, is the real chokepoint, and it still is. Analyst inference

The routes were human and specific. Bron moved settled proceeds through the Russian payment system WebMoney. The far-eastern cash-out ran through shell “trading companies” in Chinese border towns along the Russian frontier, one of them named, almost as a joke, Muling Shuntong Trading, which took a wire straight from a bank in New York. Confirmed The CryptoLocker Bitcoin was laundered out through an exchange called BTC-e, whose operator was later arrested, though that link is documented at the ecosystem level rather than tied to Bogachev by name. Credible A decade on, the shape of all this is unchanged; only the rails moved, from bank wires and WebMoney to crypto exchanges and stablecoins. Analyst inference

The fall, one arrest at a time

The crew’s first scare came in the autumn of 2010, in a coordinated sweep across the US, Britain, and Ukraine. It swept up mostly low-level mules, dozens of them, many of them foreign students doing the cash-out legwork. Only a handful of actual members were caught: five detained in Donetsk, Klepikov among them. No one was touched in Russia. Penchukov himself, warned off by a fellow crew member the BBC identifies as “Guslik,” walked away. Credible It was a disruption, not an ending. Confirmed

Fig. 3 · Three of the crew on the FBI poster
FBI JabberZeus Subjects wanted poster
Ivan Klepikov (“petr0vich”), Alexey Bron (“thehead”), and Vyacheslav Penchukov (“tank”) on the FBI’s wanted poster. Of the three, only Penchukov has been arrested. Source: FBI Cyber Most Wanted.

The real blow came in Operation Tovar over a weekend at the end of May 2014, when law enforcement in ten countries seized the botnet’s guts and cut it off from its operators. More than 300,000 infected computers were freed within days. Because the CryptoLocker keys were seized too, victims were soon able to unlock their files for free. Indictments were unsealed against Bogachev; the older Nebraska charges resurfaced. Confirmed

And then, again, nothing reached the people. Bogachev was in Russia and stayed there, beyond any extradition treaty. Klepikov was shielded by Ukrainian law. Yakubets, Bron, and Tikonov were out of reach. The machine fell in a weekend. Rounding up the crew took another decade, and it is still not finished: Penchukov not until Geneva in 2022, Rybtsov not until Italy in 2025, and Bron and Tikonov not at all. Confirmed

The bloodline

The reason the Business Club leads this project is that its people did not scatter into obscurity. They scattered into the org charts of everything that followed. Confirmed

Yakubets took his mule expertise and a set of former Business Club members and, in the same year the botnet fell, founded Evil Corp, which spent the next decade cycling through ransomware strains and, by the UK’s assessment, extorted at least $300 million. Evil Corp is also where the state connection stops being a rumor: British investigators named Yakubets’s father-in-law, the ex-Vympel officer Eduard Benderskiy, as a key enabler of the group’s relationship with Russian intelligence, and stated that before 2019 the group had been tasked by that intelligence to attack NATO countries. Yakubets’s deputy, Aleksandr Ryzhenkov, who came up through a Business Club sub-cell that specialized in defrauding British banks, later surfaced as an affiliate of LockBit. And Penchukov, years after Jabber Zeus, went on to lead the IcedID banking-malware operation. Confirmed

And one thread runs straight to the top of this whole project. The same British report that anatomized Evil Corp states plainly that the Business Club was formed by a group that included Yakubets and one Vitaly Kovalev, the man German investigators would later unmask as “Stern,” the boss of TrickBot and Conti. A founding member of this crew went on to run one of the two largest ransomware empires the West has ever faced. Confirmed The distinction matters: this is a personal bridge, one man carrying the trade from the first room into the last, not a claim that Conti descended from the Business Club as an organization. The people carried across; the org charts stayed their own. Analyst inference

The room, and where its people went (excerpt)
Group: The Business Club / GameOver Zeus / CryptoLocker (2009–2014)
Core: two leaders (one Bogachev “Slavik”), support crew, 50+ people
In a cell: Penchukov (Geneva 2022, 9 yrs), Rybtsov (Italy 2025)
Still protected: Bogachev, Yakubets, Bron, Tikonov (Russia / CIS)
Where the crew went: Evil Corp (Yakubets), IcedID (Penchukov), LockBit (Ryzhenkov), TrickBot / Conti (Kovalev, per NCA)
Compiled from US DOJ, FBI, UK NCA (2024), and Fox-IT (2015) public records. Reproduced for analysis.

Why they are protected, and what we still do not know

The through-line of every fate above is simple. The infrastructure could always be seized; the people could not, as long as they stayed home and stayed useful. Bogachev sits in Russia with a $3 million price on him and his fortune untouched. Yakubets operates openly, married into the security services. The only two the West has put in a cell, Penchukov and Rybtsov, were both caught outside their protection, one in Switzerland, one in Italy. That is the whole thesis of The Protected in miniature: the roof does not require a contract, only that the West cannot reach the man at home. The facts underneath are a matter of record; the reading of them is the project’s own. Analyst inference

The honest gaps remain. Fox-IT confirmed two leaders at the core but never named the second beside Bogachev; the best-supported candidates today are Yakubets and Kovalev, but no source pins either to that exact seat. Analyst inference Rybtsov’s case has not yet reached a public conclusion, no agency ever totted up the group’s worldwide take (the $100 million figure is a US floor), and Bron and Tikonov have left no trace since 2012. Confirmed

The clean version is the one this project keeps returning to. A room of about fifty people, most of whom knew each other by face and handle both, stole a fortune, accidentally invented modern ransomware, and then dissolved not into prison but into the ecosystem. Their names became Evil Corp, IcedID, LockBit, TrickBot, and Conti, and when those fractured in turn, the line ran on into the groups still working today, such as Black Basta, Akira, and the Silent Ransom Group. Credible The West took their machine in a single weekend and has spent the decade since failing to take them.

Sourcing & confidence

This profile draws on US DOJ records from the Districts of Nebraska and Western Pennsylvania, FBI Cyber Most Wanted materials, US Treasury OFAC designations, the UK NCA paper “Evil Corp: Behind the Screens” (October 2024), the Fox-IT / Michael Sandee GameOver ZeuS whitepaper (2015), FinCEN’s BTC-e action, and reporting by the BBC, KrebsOnSecurity, and MIT Technology Review. Some persona detail comes from Penchukov’s own 2025 prison interview and is labeled Credible accordingly. Confidence labels follow the End Krysha standard.

Confirmed · official record, or multiple independent sources.
Credible · single strong source or consistent vendor reporting, not yet officially confirmed.
Analyst inference · the project’s own assessment, drawn from the evidence above.

Business ClubGameOver ZeusCryptoLockerTankBogachevYakubetsEvil CorpThe Protected