news.mlab.sh
Back to the feed
threat-intel

Ukrainian hacker gets four years in US prison over Conti ransomware attacks

High
Summary

A Ukrainian hacker, Oleksii Lytvynenko, was sentenced to four years in prison for his role in the Conti ransomware operation, which targeted over 1,000 victims globally. He was involved in developing malicious tools and storing stolen data, even after Conti itself ceased operations. This case highlights the ongoing threat posed by ransomware groups and the involvement of individuals with ties to Eastern Europe.

A Ukrainian national, Oleksii Lytvynenko, was sentenced to four years in a U.S. prison for his involvement in the Conti ransomware operation. The U.S. Justice Department stated that Lytvynenko worked as both a hacker and developer for Conti, personally targeting at least a dozen companies and contributing to the creation of malicious tools used by the group. Investigators discovered that Lytvynenko stored data stolen from eight U.S. victims and four others overseas, found within his online accounts.

Between 2020 and 2022, Conti hackers launched attacks against organizations across 47 U.S. states and 31 countries, including Washington, D.C., and Puerto Rico. The FBI estimates that victims paid the group over $150 million in ransoms by January 2022. Lytvynenko’s role extended beyond simply executing attacks; he was involved in building and maintaining the malware “loader” used to install and launch other malicious programs on compromised systems.

Following the collapse of Conti in 2022, due to an apparent leak by a Ukrainian insider, Lytvynenko remained involved in ransomware operations, as evidenced by forensic evidence recovered during his arrest. He spent several years in an Irish jail while fighting extradition before being transferred to the U.S.

Four other alleged Conti members were charged in a separate indictment unsealed in September 2023. Before its shutdown, Conti was one of the world’s most prolific ransomware operations, believed to operate from Russia and other Eastern European countries. The group gained significant attention following Russia’s invasion of Ukraine, with an insider providing valuable information about the group’s activities.

Read the full article at The Record