TexasBitcoin

911 S5 Botnet Dismantled and Its Administrator Arrested in Coordinated International Operation

May 29, 2024 · Sourced to the U.S. Department of Justice

The charges described here are allegations. The defendant(s) are presumed innocent unless and until proven guilty in a court of law. This page reflects only what the Department of Justice has publicly announced, and links to the original release.

A court-authorized international law enforcement operation led by the U.S. Justice Department disrupted a botnet used to commit cyber attacks, large-scale fraud, child exploitation, harassment, bomb threats, and export violations.

Announced

May 29, 2024

Forfeiture

$129M

Status

Charged

Defendants

  • YunHe Wangage 35 · arrested and indicted

Charges

  • Conspiracy to commit computer fraud

    YunHe Wang· indicted

  • Substantive computer fraud

    YunHe Wang· indicted

  • Conspiracy to commit wire fraud

    YunHe Wang· indicted

  • Conspiracy to commit money laundering

    YunHe Wang· indicted

Financial actions

  • forfeiture: $99 millionProceeds received from sales of hijacked proxied IP addresses through 911 S5 operation, subject to forfeiture including assets and properties
  • forfeitureDozens of assets and properties subject to forfeiture, including a 2022 Ferrari F8 Spider S-A, a BMW i8, a BMW X7 M50d, a Rolls Royce, more than a dozen bank accounts, over two dozen cryptocurrency wallets, several luxury wristwatches, 21 residential or investment properties, and 20 domains
  • seizure: $30 millionAssets seized during the coordinated international operation
  • forfeiture: $30 millionAdditional forfeitable property identified during the operation
  • seizure23 domains and over 70 servers constituting the backbone of Wang's residential proxy service
  • fraud loss: $5.9 billionConfirmed fraudulent loss from 560,000 fraudulent unemployment insurance claims originating from compromised IP addresses
  • fraud loss: $5.5 millionValue of approximately 2,525 fraudulent orders submitted on ShopMyExchange using stolen credit cards
  • fraud loss: $254,000Actual loss from fraudulent orders after fraud detection systems thwarted the bulk of purchases

From the announcement

This Justice Department-led operation brought together law enforcement partners from around the globe to disrupt 911 S5, a botnet that facilitated cyber-attacks, large-scale fraud, child exploitation, harassment, bomb threats, and export violations. As a result of this operation, YunHe Wang was arrested on charges that he created and operated the botnet and deployed malware. This case makes clear that the long arm of the law stretches across borders and into the deepest shadows of the dark web, and the Justice Department will never stop fighting to hold cybercriminals to account.
Merrick B. Garland, Attorney General, U.S. Department of Justice
Working with our international partners, the FBI conducted a joint, sequenced cyber operation to dismantle the 911 S5 Botnet—likely the world’s largest botnet ever. We arrested its administrator, Yunhe Wang, seized infrastructure and assets, and levied sanctions against Wang and his co-conspirators. The 911 S5 Botnet infected computers in nearly 200 countries and facilitated a whole host of computer-enabled crimes, including financial frauds, identity theft, and child exploitation. This operation demonstrates the FBI’s commitment to working shoulder-to-shoulder with our partners to protect American businesses and the American people, and we will work tirelessly to unmask and arrest the cybercriminals who profit from this illegal activity.
Christopher Wray, Director, Federal Bureau of Investigation (FBI)
As alleged in the indictment, Wang created malware that compromised millions of residential computers around the world and then sold access to the infected computers to cybercriminals. These criminals used the hijacked computers to conceal their identities and commit a host of crimes, from fraud to cyberstalking. Cybercriminals should take note. Today’s announcement sends a clear message that the Criminal Division and its law enforcement partners are firm in their resolve to disrupt the most technologically sophisticated criminal tools and hold wrongdoers to account.
Nicole M. Argentieri, Principal Deputy Assistant Attorney General, head of the Justice Department’s Criminal Division, U.S. Department of Justice, Criminal Division
YunHe Wang created and administered a residential proxy service—a botnet known as 911 S5—that affected millions of computers all over the world. He will now be held accountable. Proxy services like 911 S5 are pervasive threats that shield criminals behind the compromised IP addresses of residential computers worldwide. Successfully tackling a problem of this scale is only possible with strong collaboration and exceptional investigative work between our law enforcement partners at home and abroad, and we stand ready to hold accountable anyone—no matter where they are located—who exploits our telecommunications infrastructure for their own criminal purpose.
Damien M. Diggs, U.S. Attorney for the Eastern District of Texas, U.S. Attorney's Office, Eastern District of Texas
The disruption, seizure, and arrest of the perpetrator(s) responsible for the 911 S5 cybercriminal enterprise demonstrates the forward leaning posture of the Department of Defense Office of Inspector General Defense Criminal Investigative Service (DCIS) Cyber Field Office. This investigation showcases the critical import of identifying and pursuing emerging threats and technologies targeting our warfighters, and the industrial base that supports them. Today’s announcement illustrates the magnitude of cooperation within federal law enforcement and our foreign partners pursuing criminals in the rapidly evolving cybercrime arena.
Kelly P. Mayo, Director, DCIS, Department of Defense Office of Inspector General, Defense Criminal Investigative Service (DCIS)
The conduct alleged here reads like it’s ripped from a screenplay: A scheme to sell access to millions of malware-infected computers worldwide, enabling criminals over the world to steal billions of dollars, transmit bomb threats, and exchange child exploitation materials—then using the scheme’s nearly $100 million in profits to buy luxury cars, watches, and real estate. What they don’t show in the movies though is the painstaking work it takes by domestic and international law enforcement, working closely with industry partners, to take down such a brazen scheme and make an arrest like this happen.
Matthew S. Axelrod, Assistant Secretary for Export Enforcement, Bureau of Industry and Security (BIS), U.S. Department of Commerce, Bureau of Industry and Security (BIS)

Investigating agencies

United States Department of JusticeFederal Bureau of InvestigationDefense Criminal Investigative Service, Department of Defense Office of Inspector GeneralBureau of Industry and Security, U.S. Department of CommerceCriminal Division, Computer Crime and Intellectual Property SectionU.S. Attorney's Office for the Eastern District of TexasOffice of Foreign Assets Control, Treasury DepartmentJustice Department's Office of International AffairsMoney Laundering and Asset Recovery SectionSingapore Police ForceAttorney-General's Chambers of SingaporeRoyal Thai PoliceOffice of the Attorney General and the Anti-Money Laundering Office of the Kingdom of Thailand

Case details

Prosecuting office
Eastern District of Texas
Asset Forfeiture And SeizureBotnet OperationChild ExploitationCryptocurrencyCyber Attacks And Fraud Against Military E-CommerceExport Control ViolationsFinancial SanctionsHarassment And Bomb ThreatsInternational CooperationLarge-Scale Financial FraudMalware DistributionMoney LaunderingPandemic Relief Program FraudPublic-Private Partnership

Primary source

Every fact above is drawn from the Department of Justice's own announcement — a public-domain government record.

Read the original DOJ release →

This is a research and reference page compiled from public DOJ announcements, not legal advice. Details reflect the government's statements as of its release date and may not capture later developments such as appeals, dismissals, or overturned convictions. Defendants are presumed innocent unless and until proven guilty.