LIVE · cybersecurity feed
Live wire
ransomware

Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence

Ukrainian lawyer and Conti malware developer Oleksii Lytvynenko was sentenced to four years in U.S. prison for ransomware attacks. Oleksii Oleksiyovych Lytvynenko had, by most accounts, a fairly ordinary legal career in Ukraine before he switched to writing malware. A US federal court sentenced the 44-year-old to four years in prison this week for conspiracy […]

zeroday.news ·

A Ukrainian national involved in the Conti ransomware operation, Oleksii Oleksiyovych Lytvynenko, has been sentenced to four years in a U.S. federal prison for conspiracy to commit wire fraud. The 44-year-old, formerly residing in Cork, Ireland, pleaded guilty to the charge on June 10, 2026.

Lytvynenko's role in Conti, a ransomware variant that impacted over 1,000 organizations globally, was multifaceted. He was involved in both developing malware tools and directly participating in attacks on victim networks. Specifically, he was tasked with coding a "loader," a type of malicious software designed to facilitate the deployment of other malware on compromised systems.

According to court documents, Lytvynenko conspired with others to deploy Conti ransomware to extort victims and steal their data. From 2020 to 2022, Conti was used to attack computers and networks in 47 U.S. states, 31 foreign countries, the District of Columbia, and Puerto Rico. The FBI estimates that by January 2022, victim payouts associated with Conti ransomware had exceeded $150 million.

Investigators found evidence of Lytvynenko's direct involvement, including stolen data from eight U.S. victims and four overseas organizations recovered from his online accounts. Prosecutors linked his actions to attacks on at least 12 companies, indicating an active role beyond just malware development.

Lytvynenko admitted to joining the Conti group around September 2021 and acknowledged possessing stolen data from multiple victims in the U.S. and abroad.

The Conti operation reportedly ceased in 2022 following a public declaration of support for Russia's invasion of Ukraine, which led to the leak of its internal chat logs and source code. However, Lytvynenko's ransomware activities continued beyond this shutdown.

When Irish police arrested him at his home in County Cork in July 2023, his laptop was reportedly found open, running Cobalt Strike, with an active Rocket.Chat session connected over Tor, suggesting ongoing involvement in cybercrime. Forensic evidence from this arrest further demonstrated his continued ransomware activity.

Lytvynenko was extradited from Ireland to the U.S. in October 2025, more than two years after his arrest. While the charge of conspiracy to commit wire fraud carries a statutory maximum sentence of 20 years, Lytvynenko received a four-year sentence.

Assistant Director Brent Daniels of the U.S. Secret Service’s Office of Field Operations emphasized the significant harm caused by Conti ransomware, which targeted victims across numerous states and countries, disrupting critical operations. Daniels stated that the sentence represents a measure of justice for victims and underscores the Secret Service's commitment to pursuing ransomware actors globally.

This sentencing is part of a broader U.S. effort to combat ransomware. Other recent cases include a 16-year sentence for a Ransom Cartel creator and an 8.5-year sentence for a Karakurt negotiator. In September 2023, four other Conti conspirators were indicted in Tennessee.

ransomwaremalware
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice

patch

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and s