A Ukrainian man has been handed a four-year prison term by US courts for participating in Conti, the notorious ransomware outfit that struck more than 1,000 targets worldwide and ceased operations in 2022. Oleksii Lytvynenko, aged 44, served Conti in dual roles—as both an attacker and a coder—directly assaulting at least a dozen firms and contributing to the development of malware tools deployed by the syndicate, according to the US Justice Department announcement on Thursday.
Lytvynenko, formerly based in Cork, Ireland, entered a guilty plea in June. Investigators uncovered stolen information from eight American victims and four international targets stored in his digital accounts.
Throughout the 2020–2022 period, Conti operatives launched assaults on entities spanning 47 American states, 31 nations, Washington, D.C., and Puerto Rico. The FBI assessed that organisations had transferred more than $150 million in ransom payments to the group by early 2022.
For years, the Conti ransomware group executed a sustained and sophisticated campaign that victimized hundreds of organizations across the United States and abroad, including critical infrastructure entities
A. Tysen Duva, assistant attorney general for the DOJ criminal division
Court filings indicate that Lytvynenko retained stolen victim data and worked on developing a malware "loader"—software engineered to deploy or activate additional harmful code on infiltrated systems.
Forensic analysis conducted following his detention revealed that Lytvynenko continued participating in ransomware schemes even after Conti's own shutdown, according to court materials.
Irish law enforcement apprehended Lytvynenko at his Cork residence in July 2023 following a US request. He remained in Irish custody for several years while contesting his extradition before ultimately being transferred to American jurisdiction.
A separate indictment charging four additional suspected Conti members was made public in September 2023.
Conti ranked among the world's most active ransomware syndicates prior to its demise. Security analysts widely believed the operation was based in Russia and Eastern European territories. The group drew significant scrutiny after its leadership openly endorsed Moscow's position following Russia's full-scale military campaign against Ukraine beginning in February 2022.
Shortly thereafter, someone with apparent insider access—believed to be Ukrainian—released extensive internal communications and records from Conti, revealing information regarding the group's personnel and methods.
In 2024, Ukrainian law enforcement detained another individual suspected of involvement with Conti in Kyiv.
Source: The Record



