Ukrainian national Oleksii Oleksiyovych Lytvynenko received a four-year U.S. prison sentence after pleading guilty to conspiring to commit wire fraud through the Conti ransomware operation. Lytvynenko joined Conti in September 2021, developed malware, and possessed data stolen from 12 victims, including eight U.S. organizations. Prosecutors said he and his co-conspirators extorted about $634,000 in Bitcoin from two Tennessee victims; one intrusion disrupted a sheriff’s department, emergency medical services, and a police department.
The sentence follows broader U.S. prosecutions targeting the interconnected Trickbot and Conti ecosystems. Justice Department indictments allege that operators used Trickbot—an infostealer that infected millions of systems worldwide—to obtain access for Conti ransomware attacks against hospitals, schools, businesses, local governments, and public-safety agencies. Conti compromised more than 900 organizations globally before it disbanded in 2022, with former personnel subsequently linked to successor operations including Zeon, Black Basta, and the Quantum/Royal/BlackSuit lineage.

TTPs, infrastructure, and targeting history in one profile.
15 events from the most recent confirmed update back to the earliest known activity.
The United States extradited Lytvynenko from Ireland to face charges related to his alleged Conti ransomware activity.
Ukrainian authorities arrested another suspected member of the Conti ransomware operation in Kyiv.
The Quantum ransomware lineage, which had previously rebranded as Royal, rebranded as BlackSuit after former Conti members moved into successor groups.
The Justice Department unsealed three federal indictments charging Russian nationals over alleged Trickbot and Conti roles. The Conti case charged Galochkin, Maksim Rudenskiy, Mikhail Tsarev, and Andrey Zhuykov for an alleged conspiracy operating through June 2022.
Irish authorities arrested Lytvynenko while he was living in Ireland under temporary protective status; he was reportedly near an open laptop running Cobalt Strike at the time.
Trickbot developer Alla Witte pleaded guilty to conspiracy to commit computer fraud and was sentenced to 32 months in prison.
Conti disbanded after attacking more than 1,000 organizations globally, including critical-infrastructure providers and the Costa Rican government.
Trickbot, which allegedly infected millions of computers and was used as an initial-access vector for ransomware including Conti, was taken down.
A leak exposed chats between Conti members, although the group subsequently resumed operations using new infrastructure and targets.
Oleksii Oleksiyovych Lytvynenko admitted that he joined the Conti cybercrime group and developed malware for the operation.
Maksim Galochkin was later charged over a Conti ransomware attack on Scripps Health that allegedly impaired medical examination, diagnosis, treatment, and care.
The Middle District of Tennessee indictment alleges that Conti conspirators conducted ransomware operations against hundreds of victims, including hospital systems and governments, from 2020 through June 2022.
According to the Northern District of Ohio indictment, the defendants began conspiring to use Trickbot malware to steal money and sensitive information from victims worldwide.
A U.S. court sentenced Lytvynenko to four years in prison for participating in the Conti ransomware conspiracy. Prosecutors said he and co-conspirators extorted about $634,000 in Bitcoin from two Tennessee victims.
Lytvynenko pleaded guilty to conspiracy to commit wire fraud for his participation in the Conti ransomware conspiracy.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
12 references tracked. Mallory keeps watching after this page renders.
hipaajournal.com
Open sourcecysecurity.news
Open sourcesecurityaffairs.com
Open sourcemalware.news
Open sourcesecurityweek.com
Open sourcecyberscoop.com
Open sourcejustice.gov
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.