Oleksii Oleksiyovych Lytvynenko, 44, was handed down a four-year prison term for participating in Conti ransomware campaigns spanning 2021 to 2022. The Ukrainian national was apprehended by Irish authorities (An Garda Síochána) in July 2023 following a U.S. request and subsequently extradited.
Working alongside other Conti members, Lytvynenko helped execute attacks that deployed malicious code across victim infrastructure in the U.S. and other nations. The operation involved stealing sensitive information and locking systems to demand Bitcoin payments from targets.
According to the Department of Justice, "From 2020 until 2022, Conti was used to attack computers and networks in 47 states, 31 foreign countries, the District of Columbia, and Puerto Rico. The FBI estimates that, as of January 2022, there had been victim payouts associated with Conti ransomware exceeding $150,000,000."
Assistant Attorney General A. Tysen Duva stated that "Lytvynenko joined that conspiracy as both an intruder and a developer — personally harming at least 12 companies, storing stolen data from victims, and helping build the malicious tools Conti used to extort and threaten communities."
Lytvynenko entered a guilty plea to conspiracy to commit wire fraud in June 2026 and had faced up to 20 years in prison. He acknowledged joining the Conti operation in September 2021 and managing stolen information from eight American companies and four international victims. Between 2020 and June 2022, he participated in sending extortion demands as part of the gang's dual-layer extortion scheme.
As part of his role, Lytvynenko also collaborated with another Conti member on developing a "loader"—a form of malware designed to deliver the software infrastructure needed to launch attacks.
Conti ransomware gang
The Conti operation originated from the Ryuk group in 2020 and maintained connections to the TrickBot malware network, establishing itself as a major threat to healthcare providers, public agencies, and large corporations through high-impact intrusions.
The organization expanded into a broader criminal enterprise managing several malware platforms, including BazarBackdoor and TrickBot, before ceasing operations in 2022 amid intensified law enforcement action and the disclosure of private communications.
Following its dissolution, Conti's infrastructure and personnel dispersed into successor groups such as BlackCat, Black Basta, ZEON, Hive, Quantum, BlackByte, Karakurt, and the Silent Ransom Group.
In February 2023, seven individuals linked to TrickBot and Conti faced sanctions following a major data breach that exposed personal details and private communications from both organizations, referred to as ContiLeaks and TrickLeaks.
During September 2023, the United States and United Kingdom jointly imposed sanctions and criminal charges against nine Russian nationals tied to Conti and TrickBot for conducting attacks affecting over 900 organizations globally. In May 2025, Germany's Federal Criminal Police Office (Bundeskriminalamt or BKA) publicly identified the leader of both the TrickBot and Conti networks as Vitaly Nikolaevich Kovalev, a 36-year-old Russian operating under the moniker "Stern."
Court filings indicate that the Conti organization victimized more than 1,000 entities worldwide and accumulated over $150 million in ransom proceeds during its operational period.
Source: BleepingComputer