Ukrainian lawyer and Conti malware developer Oleksii Lytvynenko was sentenced to four years in U.S. prison for ransomware attacks.
Oleksii Oleksiyovych Lytvynenko had, by most accounts, a fairly ordinary legal career in Ukraine before he switched to writing malware. A US federal court sentenced the 44-year-old to four years in prison this week for conspiracy to commit wire fraud, the Justice Department announced, tied to his role in Conti, the ransomware operation blamed for infecting over 1,000 organizations worldwide.
“Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national, was sentenced today to four years in prison for conspiracy to commit wire fraud in connection with a conspiracy to deploy Conti, a ransomware variant that infected the computers of more than 1,000 victims worldwide.” reads the announcement by DoJ. “According to court documents, Lytvynenko, formerly of Cork, Ireland, conspired with others to deploy Conti ransomware to extort victims and steal their data. From 2020 until 2022, Conti was used to attack computers and networks in 47 states, 31 foreign countries, the District of Columbia, and Puerto Rico. The FBI estimates that, as of January 2022, there had been victim payouts associated with Conti ransomware exceeding $150,000,000.”
Conti’s numbers put it in a different league from most ransomware groups that end up in a US courtroom. Between 2020 and 2022, the group attacked networks across 47 US states, 31 foreign countries, Washington DC, and Puerto Rico, and the FBI estimates victim payouts topped $150 million before the operation shut down.
Lytvynenko stood out because he handled both sides of Conti’s operations. He broke into victim networks and developed tools for attacks. He built a loader that helped deploy malware on compromised systems. Investigators found stolen data from eight US victims and four overseas organizations in his accounts. Prosecutors linked his actions to attacks on at least 12 companies, showing he played an active role rather than working on the sidelines.
Specifically, he was assigned to code a “loader,” the kind of malware that opens the door for other malicious software to run once a machine is already compromised. Evidence recovered from his own online accounts showed he personally held stolen data from eight US victims and four more overseas, and prosecutors say his direct actions affected at least a dozen companies during his time with the group. That’s not someone on the periphery of the operation; that’s someone touching both the tools and the actual victims.
The most striking detail in this case is what happened after Conti supposedly stopped existing. The gang shut down its operation in 2022 after its internal chat logs and source code leaked publicly, following the group’s public declaration of support for Russia’s invasion of Ukraine, a leak that exposed the entire operation to researchers and law enforcement simultaneously. Lytvynenko apparently didn’t take that as a signal to find a different line of work.
When Irish police showed up at his home in County Cork in July 2023, they reportedly found his laptop still open, running Cobalt Strike, with an active Rocket. Chat session connected over Tor, the kind of setup that doesn’t belong to someone who’s quietly stepped away from cybercrime. Forensic evidence from that arrest demonstrated his ransomware activity had continued well past Conti’s collapse. He was extradited from Ireland to the US in October 2025, more than two years after that raid.
Lytvynenko admitted to joining the group around September 2021. He acknowledged holding stolen data from multiple victims in the U.S. and abroad.
Oleksii Lytvynenko pleaded guilty to conspiracy to commit wire fraud for his role in the Conti ransomware operation. In September 2023, four other Conti conspirators were indicted in Tennessee.
“Lytvynenko pleaded guilty to wire fraud conspiracy on June 10. Evidence recovered from Lytvynenko’s online accounts showed he possessed data stolen from eight U.S. victims and four overseas victims. Lytvynenko further admitted to joining a team run by a Conti conspirator during which time Lytvynenko was directed to work on coding a “loader,” which is typically a type of malware, or malicious software, that is used to load programs necessary to execute other malicious attacks.” DoJ continues. “Forensic artifacts recovered at the time of his arrest in July 2023 in County Cork, Ireland, further demonstrated ongoing involvement in ransomware activity.”
Lytvynenko pleaded guilty in June to a single count of wire fraud conspiracy, a charge that carried a statutory maximum of 20 years, making the four-year sentence a fraction of what he legally could have received.
“Conti ransomware caused extraordinary harm, targeting victims across nearly every state and dozens of countries and disrupting critical operations for organizations across multiple industries,” said Assistant Director Brent Daniels of the U.S. Secret Service’s Office of Field Operations. “Today’s sentence is a measure of justice for the victims whose data, operations, and livelihoods were put at risk. It underscores the Secret Service’s commitment to pursuing ransomware actors and their networks wherever they operate and protecting the American people.”
The sentence adds to a broader US crackdown on ransomware. The Ransom Cartel creator recently received 16 years, while a Karakurt negotiator got 8.5 years. Lytvynenko’s four-year sentence may look lighter, but it still shows that US courts are pursuing ransomware criminals who operate from abroad.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Conti ransomware)
Source: SecurityAffairs
Source Link: https://securityaffairs.com/198931/cyber-crime/conti-hacker-who-built-malware-and-attacked-victims-gets-four-year-sentence.html