Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Hacker groups and malware
- Conti
- Reported by
- 1 outlet
CYBER-CRIME
Swapping legal work for malware development ended in extradition and a guilty plea
A Ukrainian lawyer who wound up coding malware for the Conti ransomware gang has been sentenced to four years in a US prison.
Oleksii Oleksiyovych Lytvynenko, 44, pleaded guilty in June to conspiracy to commit wire fraud over his role in Conti, the Russia-linked ransomware operation associated with more than 1,000 victims and at least $150 million in ransom payments.
Lytvynenko took an unusual route into the ransomware business. The Ukrainian national, who later lived in Cork, Ireland, trained as a lawyer before joining Conti as an intruder and developer.
According to his plea agreement [PDF], Lytvynenko operated under the handle "henry" and joined a team run by another Conti conspirator known as "silver" or "buza." He was recruited to help with coding and directed to work on a malware loader – software designed to get other malicious code running on a victim's machine.
Prosecutors said his Google account showed he had also been doing some homework. Investigators found books and videos about malware and hacking alongside Conti malware, ransom notes, and stolen victim data. Prosecutors said he also used Google and ZoomInfo to research potential targets.
Lytvynenko wasn't confined to writing code, according to the filing. Evidence from his online accounts showed that he possessed data stolen from eight US victims and four overseas, with the eight American victims reporting more than $1.5 million in losses.
Court documents identify several Bitcoin transfers tied to his Conti work, including 0.4 BTC worth $25,042 that prosecutors traced back to one of his victims. He has been ordered to forfeit the same amount.
Conti disbanded in 2022 after its internal chats and source code were leaked following the gang's public support for Russia's invasion of Ukraine. Lytvynenko apparently didn't take that as his cue to find another line of work.
When Gardaí turned up at his County Cork home in July 2023, they said they found his laptop open, Cobalt Strike running and a Rocket.Chat session connected over Tor. Prosecutors said evidence recovered from the machine showed that his involvement in ransomware activity had continued after Conti disbanded.
Lytvynenko was extradited from Ireland to the US in October 2025.
The Justice Department says Conti attacked organizations across 47 US states, the District of Columbia, Puerto Rico, and 31 foreign countries between 2020 and 2022. By January 2022, the FBI estimated that victim payouts associated with Conti exceeded $150 million.
Lytvynenko will now have four years to contemplate a career change. ®
Reproduced in full under licence from The Register. © The Register.
Coverage
One outlet has carried this so far.
2026-09-11 12:15 UTC
Related stories
- Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
The Hacker News · 2026-09-16
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
The Hacker News · 2026-09-16
- N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
The Hacker News · 2026-09-16
- NCSC and Allies Warn of Iranian Spyware Campaign
Infosecurity Magazine · 2026-09-16
- Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News · 2026-09-16