Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationenforcement-actionloader-delivery-mechanismunderground-data-leak

Conti Developer Pleads Guilty for Role in Global Ransomware Campaign

Updated 7d agoFirst seen Jun 12, 20267 sources

Ukrainian national Oleksii Oleksiyovych Lytvynenko pleaded guilty in U.S. federal court to conspiracy to commit wire fraud for his role in the Conti ransomware operation, one of the most prolific cybercrime campaigns tracked by U.S. authorities. Prosecutors said Lytvynenko joined Conti by September 2021, helped develop a malware loader used to gain initial access to victim networks, and possessed data stolen from 12 victims, including eight in the United States. He was arrested in Ireland in July 2023, extradited to the United States in October 2025, and now faces up to 20 years in prison, with sentencing scheduled for September 2026.

The Justice Department said Conti targeted more than 1,000 victims across 47 U.S. states, Puerto Rico, Washington, D.C., and about 31 countries, extorting more than $150 million in ransom payments. In one part of the case, prosecutors said Lytvynenko and co-conspirators collected about $634,000 in Bitcoin from two Tennessee victims and leaked stolen data from another Tennessee organization after a $3 million ransom demand was rejected. The plea comes as U.S. authorities continue pursuing other alleged Conti members; earlier indictments also tied the group’s breakup to successor operations including Black Basta, Quantum, Royal, and BlackSuit.

Share:
Conti Developer Pleads Guilty for Role in Global Ransomware Campaign
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Sep 10, 2026just now

Sentencing scheduled for Lytvynenko

The court scheduled Lytvynenko's sentencing for September 10, 2026, following his guilty plea in the Conti case.

Conti Ransomware Guilty Plea After Ransomware Attacks
Jun 12, 202610d ago

Lytvynenko pleads guilty in U.S. federal court

Lytvynenko pleaded guilty to conspiracy to commit wire fraud for his role in Conti ransomware attacks, admitting involvement in the criminal operation and facing up to 20 years in prison.

Conti ransomware group member pleads guilty, faces up to 20 years in prison | CyberScoop

Lytvynenko extradited from Ireland to the United States

After his arrest in Ireland, Lytvynenko was extradited to the United States in October 2025 to face federal charges tied to Conti ransomware operations.

Conti ransomware group member pleads guilty, faces up to 20 years in prison | CyberScoop

Lytvynenko arrested in Ireland

Lytvynenko was arrested in Ireland in July 2023 in connection with his alleged role in Conti ransomware attacks.

Conti ransomware group member pleads guilty, faces up to 20 years in prison | CyberScoop

U.S. unseals indictment against four additional Conti conspirators

Authorities said an indictment against four additional alleged Conti conspirators was unsealed in September 2023, expanding the public U.S. case against the ransomware network.

Conti Ransomware Guilty Plea After Ransomware Attacks

Conti ransomware campaign operates globally

According to the Justice Department description cited in the references, Conti conducted ransomware operations from 2020 to 2022, targeting organizations across 47 U.S. states and 31 foreign countries and extorting at least $150 million.

Conti Ransomware Guilty Plea After Ransomware Attacks
May 1, 20224y ago

Conti shuts down after internal leaks

The Conti ransomware operation shut down in May 2022 after the group backed the Russian government, a move that triggered internal leaks. The article presents this as the end of Conti's active run following its 2020–2022 campaign.

Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges - SecurityWeek
Sep 1, 20215y ago

Oleksii Lytvynenko joins the Conti conspiracy

Authorities said Oleksii Oleksiyovych Lytvynenko had joined Conti by at least September 2021 and helped develop a malware loader used to enable initial intrusions in some attacks.

Conti Ransomware Guilty Plea After Ransomware Attacks
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

25 LINKEDOpen in app
Organizations
3 linked
SecurityWeekSecurityOnline.infoSecurity Affairs
Breaches
1 linked
GOVERNMENTOFCOSTARICA-2026-06
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.