Ukrainian national pleads guilty to role in Conti ransomware operation

Ukrainian national pleads guilty to role in Conti ransomware operation — Cybersecurity | Versia.media

A Ukrainian national who was extradited from Ireland to the United States last year has entered a guilty plea to conspiracy charges linked to the Conti ransomware operation.

The U.S. Department of Justice announced on Thursday that 44-year-old Oleksii Oleksiyovych Lytvynenko pleaded guilty to conspiracy to commit wire fraud for his involvement in Conti ransomware attacks carried out between 2021 and 2022.

According to prosecutors, Lytvynenko and his co-conspirators deployed Conti ransomware on victim networks within the United States and abroad, stealing data and encrypting devices to demand Bitcoin ransom payments.

Per the DOJ, Lytvynenko admitted to joining the Conti conspiracy around September 2021 and to possessing data stolen from eight U.S. victims and four international victims.

He also acknowledged joining a team overseen by another Conti conspirator, where he contributed to coding a "loader," a type of malware used to load software necessary for executing attacks.

The Conti ransomware operation ranked among the most prolific cybercrime groups active at the time, targeting hospitals, businesses, schools, and government entities globally.

Court documents indicate that Conti targeted more than 1,000 victims worldwide and amassed over $150 million in ransom payments.

The guilty plea comes after Lytvynenko's extradition from Ireland to the United States, following his arrest in July 2023. Lytvynenko now faces a maximum prison sentence of 20 years.

The Conti ransomware group originated from the Ryuk cybercrime syndicate and was tightly linked to the TrickBot malware network.

The group gained notoriety for large-scale attacks on healthcare organizations, governments, and enterprises before ceasing operations in 2022, following the leak of its internal chats and heightened law enforcement pressure.

Security researchers believe former Conti members later branched off into other ransomware groups, including BlackCat, Black Basta, ZEON, Hive, Quantum, BlackByte, Karakurt, and the Silent Ransom Group.

In September 2023, the U.S. and the United Kingdom also imposed sanctions and filed charges against nine Russian nationals associated with the TrickBot and Conti ransomware cybercrime operations for attacks affecting more than 900 victims worldwide.

Test every layer before attackers do

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Related Articles:

Karakurt extortion gang ‘cold case’ negotiator gets 8.5 years in prison

Trigona ransomware attacks use custom exfiltration tool to steal data

Pharma giant Novo Nordisk discloses breach of clinical trials data

Oracle mitigates PeopleSoft zero-day exploited in data theft attacks

Authorities dismantle 'AudiA6' ransomware crypto-laundering service

← Cybersecurity