Fraud Management & Cybercrime
,
Ransomware
Lytvynenko Admitted Developing Malware and Stealing Data for Conti
A Ukrainian man involved in the Conti ransomware group has been sentenced to four years in prison by a U.S. federal judge Thursday.
See Also: The Unstructured Data Blindspot: Why Your Most Valuable Assets Are Your Least Protected
The ruling came after Oleksii Oleksiyovych Lytvynenko, 44, pleaded guilty in June to wire fraud conspiracy in connection with the prolific cybercriminal operation, a felony punishable by up to 20 years in prison. Under the plea agreement, prosecutors dismissed a separate computer fraud conspiracy charge.
Lytvynenko admitted to developing malware and stealing victim data for Conti. The gang had extorted over $150 million in ransom payments from more than 1,000 victims by January 2022, the FBI estimated. Conti disbanded in spring 2022 following internal acrimony over Russia’s invasion of Ukraine after its leadership declared support for the Kremlin – a stand that also crashed its extortion revenue amid corporate concerns over violating international sanctions (see: Conti’s Legacy: What’s Become of Ransomware’s Most Wanted?).
“Lytvynenko joined that conspiracy as both an intruder and a developer – personally harming at least 12 companies, storing stolen data from victims, and helping build the malicious tools Conti used to extort and threaten communities,” said Assistant Attorney General A. Tysen Duva of the Department of Justice criminal division.
“Even after the Conti conspiracy ended, he continued engaging in active ransomware operations until his arrest. Cybercriminals who build, deploy, or profit from malware like Conti – no matter where they operate – will face justice and meaningful consequences in U.S. courts,” Duva said in a statement.
From 2020 to 2022, cybercriminals used the malware known as Conti and its numerous variants to attack businesses and governments in the United States and more than 30 other countries, prosecutors said. They hacked into victims’ computers and networks, stole data, locked systems and demanded ransoms for decryption.
Many versions of Conti’s ransom note said “if you don’t [know Conti] – just ‘google it.'” Victims were directed to upload the note to the group’s darkweb negotiation site and send money to the attacker’s cryptocurrency address.
U.S. victims included a government entity and two businesses in the Middle District of Tennessee, where Lytvynenko was prosecuted and sentenced. He joined Conti around September 2021 and was responsible for eight U.S. victims, who reported at least $1.5 million in losses, and four victims abroad, prosecutors said in his plea deal.
A grand jury indicted Lytvynenko in May 2023. The U.S. made an extradition request to Ireland in June 2023, and Lytvynenko was arrested in the Irish city of Cork in July that year.
Investigators seized Lytvynenko’s laptop and found Conti ransom notes sent to those victims, malware including Conti and instructional materials on malware and hacking stored in his Google Drive. More data stolen from the Conti victims was stored on New Zealand online file-hosting service Mega.NZ.
Lytvynenko also used his Google account to search zoominfo.com for information about potential victims, prosecutors said.
Under the moniker “henry,” Lytvynenko joined another Conti operator’s team to help develop a malicious loader. He received five bitcoin payments in his Binance account for the work, worth about $30,000 at the transaction time between July and October 2021.
Lytvynenko argued in a handwritten letter in Russian received by the court on April 21 that the computer and wire fraud allegations against him were too vague because prosecutors had not specified his role in the attacks against the three Tennessee victims or how much of their financial losses could be linked to him.
Describing himself as a “minimal participant”, Lytvynenko also argued that prosecutors had not shown he personally received proceeds from the ransomware attacks and said some victims did not pay a ransom.
He additionally asked the court to help him establish refugee status and legalize his stay in the U.S. since he didn’t have the money or physical freedom to pursue the application himself. Previously, he had received temporary protection in Ireland following Russia’s invasion of Ukraine.
On June 10, Lytvynenko entered a plea agreement with the government to plead guilty to wire fraud in exchange for dismissal of the computer fraud charge and to receive a recommended sentence of 41 to 51 months.
Four other Conti operators, all of them Russian nationals – Maksim Galochkin, Maksim Rudenskiy, Mikhail Mikhailovich Tsarev and Andrey Yuryevich Zhuykov – were also charged by the same federal court in September 2023 with one count of computer fraud and one count of wire fraud conspiracy.
The FBI’s San Diego, Nashville and El Paso Field Offices and the U.S. Secret Service are investigating the case.
