Conti ransomware: Lytvynenko sentenced to 48 months, most of it already served in Irish custody
By Sethu Satheesh · 13 Sept 2026 · 21 min read
Threat Actor: Conti ransomware group · Target: Businesses, nonprofits and government entities in the US and 31 countries; three Middle District of Tennessee victims named in the indictment
Source: www.justice.gov
Executive Summary
On 10 September 2026 Chief Judge William L. Campbell Jr. of the US District Court for the Middle District of Tennessee sentenced Oleksii Oleksiyovych Lytvynenko, a 44-year-old Ukrainian national, to 48 months' imprisonment for conspiracy to commit wire fraud as a member of the Conti ransomware operation. Lytvynenko had pleaded guilty on 10 June 2026 to Count Two of a two-count indictment returned under seal in May 2023; Count One, conspiracy to violate the Computer Fraud and Abuse Act, was dismissed on the government's motion at sentencing. He was ordered to forfeit $25,042 and to pay restitution in an amount still to be determined.
The headline number understates how little custody remains. The judgment as entered on the docket reads "Imprisonment for 48 months (with credit from time served in Ireland since July 2023), no supervision to follow." Lytvynenko was arrested by An Garda Síochána in County Cork on 6 July 2023 and remained in custody through two rounds of Irish extradition litigation and his transfer to the United States. By sentencing day that was 1,162 days, about 38 months. Roughly ten months of the 48 remained on the day the sentence was pronounced, before any Bureau of Prisons good-conduct credit. Under paragraph 28 of his plea agreement he has consented to removal from the United States when the sentence ends, which is why no supervised release follows.
The plea agreement's factual basis is more specific than the press coverage. Lytvynenko, using the handle "henry", joined the team of a co-conspirator known as "silver" (also "buza") and was "directed to work on coding a 'loader'". He is not described as writing the Conti encryptor. His Google account tied him to data stolen from eight US victims and four overseas victims, with the eight US victims reporting losses of at least $1,511,634.96; he used the account to search zoominfo.com for prospective targets and to store ransom notes, malware samples including Conti, and hacking manuals, and used Mega.NZ to hold stolen victim data. When Gardaí seized his laptop it was running Cobalt Strike and a Rocket.Chat instance reached over Tor, contained RDP artefacts consistent with lateral movement on victim networks, and held Google searches for Mimikatz. The court-accepted record therefore supports "intruder and loader coder", which is what the Department of Justice's own release says ("both an intruder and a developer"), while the "Conti ransomware developer" framing in several headlines goes further than the admitted facts.
This is the first sentence handed down in the Middle District of Tennessee's Conti prosecution, which also charged four Russian nationals in a separate indictment unsealed in September 2023, none of whom is in custody. It follows the May 2026 sentencing in the Southern District of Ohio of Deniss Zolotarjovs, a negotiator for the organisation that former Conti leaders ran afterwards under the Karakurt, Royal, TommyLeaks, SchoolBoys and Akira brands, to 102 months. The Conti operation itself, per the FBI figures the department cites, attacked more than 1,000 victims in 47 states, the District of Columbia, Puerto Rico and 31 countries, with victim payouts exceeding $150 million as of January 2022.
Verification of Claims
-
Claim: Lytvynenko was sentenced to four years in prison on 10 September 2026. → Verified → Docket entry 56, United States v. Lytvynenko, 3:23-cr-00088 (M.D. Tenn.): "JUDGMENT on Sentencing held on 9/10/2026 … Imprisonment for 48 months … Signed by Chief Judge William L. Campbell, Jr on 9/10/2026" [3]. DOJ Office of Public Affairs release dated 10 September 2026 [1].
-
Claim: The sentence credits time served in Irish custody since July 2023, leaving roughly ten months. → Verified (credit); the residual figure is our arithmetic → The judgment text states "with credit from time served in Ireland since July 2023" [3]. Arrest date 6 July 2023 is in the plea agreement's factual basis [4]. 6 July 2023 to 10 September 2026 is 1,162 days (38.2 months); 48 minus 38.2 leaves about 9.8 months. The Bureau of Prisons performs the final computation under 18 U.S.C. § 3585(b) and applies good-conduct credit separately; the residual could be shorter. No press report we reviewed mentions the credit.
-
Claim: The four-year term was within a range the parties had agreed and that bound the court. → Verified → Plea agreement ¶11–15: the agreement is made under Fed. R. Crim. P. 11(c)(1)(C); the stipulated final offense level is 22 and the "Recommended Guidelines Range" is 41 to 51 months, and "if the Court accepts this plea agreement, it will be obligated to follow the parties' stipulated offense level and impose an agreed-upon sentence of between 41 and 51 months" [4]. Forty-eight months sits inside that range.
-
Claim: Lytvynenko was a "Conti ransomware developer". → Assessed, Not Confirmed → The factual basis says he "was directed to work on coding a 'loader'" on "silver"'s team and describes loaders generically as malware "used to load programs necessary to execute other malicious attacks" [4]. It does not say he wrote or maintained the Conti encryptor. DOJ's release calls him "both an intruder and a developer" [1], which is consistent with loader work. "Conti ransomware developer" in headlines [7][8] is a compression the record does not quite support.
-
Claim: He personally harmed at least 12 companies. → Verified as to the count; "companies" is loose → Plea agreement: his Google account "connected the defendant to data stolen by Conti conspirators from eight U.S. victims and four overseas victims" [4]. Twelve victims. The indictment's Victim 1 was a government entity, and the plea agreement's victims are not all identified as businesses, so "companies" [1][6] may be imprecise.
-
Claim: Lytvynenko trained as a lawyer. → Verified → The Irish Court of Appeal judgment [2025] IECA 212 describes the appellant as a Ukrainian national lawyer who had been granted temporary protection in Ireland after the Russian invasion [10]; The Register cites the same judgment [6].
-
Claim: He was extradited from Ireland in October 2025. → Verified → Court of Appeal dismissed his appeal on 28 October 2025 [10]; the M.D. Tenn. docket records "Warrant Returned Executed on 10/30/2025" and an initial appearance and arraignment by video before Magistrate Judge Alistair Newbern the same day, plea of not guilty, detention hearing waived [3]; DOJ release of 30 October 2025 [11].
-
Claim: Conti extorted more than $150 million from victims. → Verified as an FBI estimate with a date attached → DOJ: "The FBI estimates that, as of January 2022, there had been victim payouts associated with Conti ransomware exceeding $150,000,000" [1]. The figure is an estimate frozen at January 2022; Conti continued operating until roughly June 2022 [4], so the lifetime total is higher and unstated.
-
Claim: Conti infected more than 1,000 victims worldwide. → Verified as DOJ's figure; the indictment said "more than nine hundred" → The May 2023 indictment alleged the conspirators "have claimed attacks on more than nine hundred victims worldwide" [5]; DOJ's 2025 and 2026 releases say "over 1,000" [1][11]. Both are counts of claimed attacks, not confirmed intrusions.
-
Claim: Lytvynenko was ordered to forfeit $25,042. → Verified → Plea agreement ¶19: consent to a forfeiture money judgment of $25,042, representing 0.4 BTC deposited to his Binance account on or about 29 October 2021 "which originated from one of the defendant's victims" [4]; Forfeiture Order, docket 52, 3 September 2026, incorporated in the judgment [3].
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| 2020 (no later than) | Conti conspirators | Conti ransomware developed; at least three versions released thereafter | [4][5] |
| 28 Jul 2020 | Conti conspirators | Victim 1, a Middle District of Tennessee government entity, encrypted including its sheriff's department; EMS and a local police department hit by lateral movement; ~$174,000 ransom paid | [5] |
| Dec 2020 | Conti conspirators | Begin publishing stolen data of non-paying victims on a Tor site | [4][5] |
| 29 Jul – 18 Oct 2021 | Lytvynenko | Four BTC payments (0.025, 0.021, 0.031, 0.015 BTC) received from addresses associated with Conti conspirators | [4] |
| 9 Sep 2021 | Conti conspirators | Victim 2, a Middle District of Tennessee business, encrypted; $950,000 demanded, ~$460,000 paid | [5] |
| Sep 2021 (no later than) | Lytvynenko | Joins the Conti conspiracy; as "henry" works on "silver"'s coding team on a loader | [4] |
| 29 Oct 2021 | Lytvynenko | 0.4 BTC (~$25,042) from a victim deposited to his Binance account | [4] |
| 29 Jan 2022 | Conti conspirators | Victim 3, a Middle District of Tennessee business, encrypted; $3,000,000 demanded, refused; audit and 401(k) files published | [5] |
| Jan 2022 | FBI | Estimates Conti victim payouts exceed $150 million | [1] |
| Jun 2022 | Conti conspirators | Conspiracy period alleged in the indictment ends | [4][5] |
| 22 May 2023 | Grand jury, M.D. Tenn. | Two-count sealed indictment returned | [5] |
| 8 Jun 2023 | US Embassy, Dublin | Extradition request communicated to Ireland | [9] |
| 6 Jul 2023 | An Garda Síochána | Lytvynenko arrested in County Cork; laptop running Cobalt Strike and Tor-hosted Rocket.Chat seized | [4] |
| 7 Sep 2023 | DOJ | Separate M.D. Tenn. indictment of four Russian nationals for Conti unsealed | [12] |
| 20 Feb 2025 | High Court of Ireland (Keane J) | Objections to extradition dismissed; committed to await surrender, [2025] IEHC 100 | [9] |
| 28 Oct 2025 | Court of Appeal of Ireland (Burns J) | Appeal dismissed, [2025] IECA 212 | [10] |
| 30 Oct 2025 | US Marshals / M.D. Tenn. | Warrant executed on US soil; case unsealed; initial appearance and arraignment by video, not guilty plea, detention ordered | [3][11] |
| 4 May 2026 | DOJ | Zolotarjovs, negotiator for the successor organisation, sentenced to 102 months in S.D. Ohio | [13] |
| 10 Jun 2026 | Lytvynenko / Campbell C.J. | Status conference converted to plea hearing; guilty plea to Count Two under a Rule 11(c)(1)(C) agreement with a 41–51 month range | [3][4][2] |
| 3 Sep 2026 | Campbell C.J. | Forfeiture order entered (docket 52) | [3] |
| 10 Sep 2026 | Campbell C.J. | Sentence: 48 months with credit for Irish custody since July 2023, no supervision, $100 assessment, restitution to be determined; Count One dismissed | [1][3] |
Operation Anatomy
The anatomy below is the Conti operation as the court record describes it, with Lytvynenko's admitted role marked where the plea agreement places him.
Target selection
Conti conspirators "identified potential victims and searched for vulnerabilities in victims' networks". Lytvynenko's contribution at this stage was research: he used his Google account to query zoominfo.com, a commercial business-contact database, for information about potential victims [4].
Initial access, persistence, lateral movement
Once a foothold existed the conspirators "sought to obtain persistent remote access to the networks, move laterally … and escalate privileges", presenting themselves to victim systems as the legitimate holders of administrative credentials. The wire-fraud theory of the case rests on that misrepresentation [4]. Lytvynenko's laptop held "multiple remote desktop protocol artifacts which indicated lateral movement on victim networks" and Google searches for Mimikatz, the credential-dumping tool [4]. The Cobalt Strike instance running at the moment of arrest, together with the Rocket.Chat session, "revealed the defendant's involvement in multiple intrusions of third-party corporate and municipal computer networks, including computer networks in the United States" [4].
Tooling
A dedicated role in the conspiracy was "crypting" Conti so that it evaded antivirus detection; another was developing the ransomware itself [4][5]. Lytvynenko's admitted development work was a loader, on the team of "silver"/"buza" [4]. Conti's Tor-hosted Rocket.Chat server is the same internal chat infrastructure whose logs were leaked in February 2022 after the group declared support for Russia's invasion of Ukraine; that leak is not part of the court record and is mentioned here only as context.
Exfiltration and encryption
Conspirators "stole victim data and deployed Conti ransomware, by transmitting it to the victims' computer(s)". Lytvynenko stored stolen data on Google Drive and on Mega.NZ [4]. The ransom note told victims to "google it" if they did not know Conti and directed them to a Tor site for "further instructions" [4][5].
Extortion and payment
Victims uploaded their note to the Tor site to open a negotiation channel. From December 2020, victims who did not engage quickly had portions of their data published, with more threatened [4]. The indictment reproduces one exchange: a Middle District of Tennessee victim wrote that it had been "begging everyone for help"; the conspirator replied, "Stop telling tales, you're a bad negotiator. You have a choice to pay or be published." That victim paid about $460,000 [5]. Ransoms were divided among conspirators; Lytvynenko's traced share was 0.4 BTC from a victim plus four smaller transfers from Conti-associated addresses, all landing at a Binance account in his own name [4].
Loading diagram...
Accused
Oleksii Oleksiyovych Lytvynenko, a/k/a Alexsey Alexseevich Litvinenko, 44, Ukrainian national, resident of County Cork, Ireland, at the time of arrest. Handle: "henry". Trained as a lawyer, per the Irish Court of Appeal [10]. He and family members held temporary protection in Ireland under the International Protection Act 2015 following Russia's invasion of Ukraine [9][10].
Status: Convicted on his guilty plea to Count Two (18 U.S.C. § 1349, conspiracy to commit wire fraud). Count One (18 U.S.C. § 371, conspiracy to violate 18 U.S.C. § 1030(a)(2)(C), (a)(5)(A) and (a)(7)(C)) dismissed on the government's motion after sentencing [3][4].
Admitted role: Joined no later than September 2021; victim research; storage of stolen data and malware; coding a loader on "silver"'s team; the seized laptop evidenced live intrusion activity in July 2023, a year after the indictment's conspiracy period ends [4].
Co-conspirators referenced in the record: "silver" a/k/a "buza", team lead for coding, not charged in this case [4]. In the separate M.D. Tenn. indictment unsealed 7 September 2023, Maksim Galochkin, Maksim Rudenskiy, Mikhail Tsarev and Andrey Zhuykov are charged with Conti conspiracy offences; they are presumed innocent and none has appeared in a US court [12].
Attribution confidence: Not applicable in the intelligence sense; the facts above are admissions in a plea agreement accepted by the court.
Organisational context: Conti was operated by the group tracked as Wizard Spider/Trickbot in vendor reporting. After Conti's 2022 shutdown, per DOJ's May 2026 Zolotarjovs release, former Conti leaders ran an organisation that used the Conti, Karakurt, Royal, TommyLeaks, SchoolBoys and Akira brands, stole data from more than 54 companies between June 2021 and August 2023, and operated for a time from an office on Lakhtinskaya Street in St Petersburg [13].
MITRE ATT&CK techniques evidenced in the court record (IDs checked on attack.mitre.org, 13 September 2026):
| ID | Technique | Basis |
|---|---|---|
| T1591 | Gather Victim Org Information | zoominfo.com searches [4] |
| T1078 | Valid Accounts | misrepresentation as holders of administrative credentials [4] |
| T1003.001 | OS Credential Dumping: LSASS Memory | Mimikatz searches on seized laptop [4] |
| T1021.001 | Remote Services: Remote Desktop Protocol | RDP artefacts indicating lateral movement [4] |
| T1027.002 | Obfuscated Files or Information: Software Packing | "crypting" role [4][5] |
| T1105 | Ingress Tool Transfer | loader role [4] |
| T1567.002 | Exfiltration to Cloud Storage | Google Drive and Mega.NZ [4] |
| T1090.003 | Proxy: Multi-hop Proxy | Tor for negotiation portal and Rocket.Chat [4] |
| T1486 | Data Encrypted for Impact | Conti deployment [4][5] |
| T1657 | Financial Theft | ransom extortion [4][5] |
| S0154 | Cobalt Strike | running at arrest [4] |
| S0002 | Mimikatz | searches on laptop [4] |
| S0575 | Conti | the ransomware |
OpSec failures: A Gmail/Google Drive account linking him to twelve victims' data; a Binance account in his own name receiving ransom proceeds; a laptop open and running Cobalt Strike and Rocket.Chat at the moment of arrest, three years after the conspiracy began and a year after it nominally ended.
Technical Indicators
# Court record indicators only. No network IoCs are disclosed in the
# indictment, plea agreement or judgment; do not treat the items below
# as detection content.
cryptocurrency:
- address: 1413UKpEBZ9XTojkv37n9pyikS8AJXTvCW
chain: BTC
role: defendant's receiving address, linked to a Binance account in his name
source: plea agreement, Doc. 43, para 7
- note: >
Four sending addresses "associated with Conti conspirators" appear in
the plea agreement but are OCR-damaged in the public copy
(bc1q... prefixes); consult the PDF before relying on them.
services_used:
- zoominfo[.]com # victim research
- drive.google[.]com # stolen data and malware storage
- mega[.]nz # stolen data storage
tooling_observed_at_arrest:
- Cobalt Strike
- Rocket.Chat over Tor
- RDP client artefacts
- Mimikatz (searches, not binary)
network_iocs: none disclosedLegal and Regulatory Response
Charges. Indictment 3:23-cr-00088, returned under seal 22 May 2023, two counts: § 371 conspiracy to commit CFAA offences, and § 1349 conspiracy to commit wire fraud. Forfeiture allegations under §§ 981(a)(1)(C), 982(a)(2)(B) and 1030(i) [5].
Extradition. Request communicated 8 June 2023; arrest 6 July 2023. The High Court (Keane J) rejected objections based on family life and bodily integrity, risk of inhuman or degrading treatment in US custody or by refoulement to Ukraine, and an abuse-of-process argument about interception and retention of his correspondence in custody, finding the thresholds unmet or the evidence insufficient: Attorney General v Lytvynenko [2025] IEHC 100, 20 February 2025 [9]. The Court of Appeal (Burns J) dismissed the appeal on 28 October 2025, holding that lost-evidence and disclosure complaints belong in the requesting state's courts, that interference with family life did not reach "the level of exceptionality that extradition should not occur", and accepting US assurances that he could seek relief from removal to Ukraine on a credible-fear or torture basis: [2025] IECA 212 [10]. He was in the United States two days later [3].
Plea. Rule 11(c)(1)(C) agreement filed 10 June 2026: base offense level 7 (§ 2B1.1(a)(1)); +16 for loss over $1.5 million; +2 for ten or more victims; +2 for a substantial part of the scheme committed from outside the United States; −2 zero-point offender; −3 acceptance of responsibility; final level 22, Criminal History Category I anticipated, range 41–51 months, binding on the court if accepted. Appeal waived for any sentence within or below the range. Consent to removal on completion of sentence [4].
Sentence. 48 months, credit for Irish custody since July 2023, no supervised release, $100 special assessment, forfeiture money judgment of $25,042, restitution to be determined [3]. Investigating agencies: FBI San Diego, Nashville and El Paso; US Secret Service; HSI New York. Prosecutors: Trial Attorney Sonia V. Jimenez (CCIPS) and AUSA Taylor J. Phillips [1].
Related prosecutions. M.D. Tenn. indictment of Galochkin, Rudenskiy, Tsarev and Zhuykov, unsealed 7 September 2023, alongside Trickbot indictments in N.D. Ohio and a Scripps Health-related Conti indictment in S.D. Cal.; those defendants remain at large [12]. S.D. Ohio: Zolotarjovs sentenced 4 May 2026 to 102 months [13].
Impact Assessment
- Victims tied to the defendant: Confirmed, 12 (8 US, 4 overseas), by data in his Google account [4].
- Losses reported by those US victims: Confirmed, at least $1,511,634.96 [4].
- Defendant's traced proceeds: Confirmed, $25,042 (0.4 BTC) plus 0.092 BTC across four smaller transfers, the latter not valued in the record [4].
- Middle District of Tennessee victims in the indictment: Confirmed, three; ~$174,000 and ~$460,000 paid by Victims 1 and 2; Victim 3 refused a $3,000,000 demand and had audit and 401(k) files published [5].
- Conti victims overall: Reported, "over 1,000" (DOJ 2025–2026) against "more than nine hundred" (indictment 2023), both counts of claimed attacks [1][5].
- Conti payouts overall: Estimated, more than $150 million as of January 2022 (FBI) [1].
- Restitution: Unknown, to be determined after judgment [3].
- Remaining custody: Estimated, about ten months from 10 September 2026 before good-conduct credit; final computation by the Bureau of Prisons [3].
Lessons and Defensive Recommendations
For SOC and IR teams
- The intrusion chain admitted here is the standard 2020–2022 ransomware playbook: credential misuse presented as legitimate admin access, RDP for lateral movement, Cobalt Strike beacons, Mimikatz for credentials. Detection content for T1021.001 and T1003.001, and Cobalt Strike beacon signatures, remain relevant because the successor brands listed in the Zolotarjovs record (Royal, Akira and others) inherited the same operators.
- Exfiltration to consumer cloud storage (Google Drive, Mega) preceded encryption. Egress monitoring for Mega and personal Google accounts from servers is a cheap, high-signal control.
For legal and leadership
- "Four years" is the sentence; the custody remaining was closer to ten months on the day of sentencing. When briefing boards on deterrence, cite the docket, not the headline.
- The extortion transcript in the indictment ("You have a choice to pay or be published") is court-authenticated evidence of Conti's negotiation posture. It is useful in tabletop exercises precisely because it is not vendor-reconstructed.
- Restitution in this case is still to be determined. Victims of Conti in the Middle District of Tennessee, or whose data was among the twelve sets tied to the defendant, should confirm with the US Attorney's Office victim-witness unit that they are on the restitution list.
For platforms and exchanges
- A ransom payment moved from a victim to a Binance account held in the defendant's real name within the same operation. Exchange KYC records were evidently decisive in the forfeiture calculation; the case is a reference point for what "traceable proceeds" looks like when an affiliate skips the mixing step.
For researchers
- The Register's "trained as a lawyer" detail traces to the Irish Court of Appeal judgment, not to US filings. When a biographical fact appears only in one jurisdiction's record, cite that record.
Sources
- Ukrainian National Sentenced to Four Years in Prison for Wire Fraud Conspiracy in Connection with Conti Ransomware — US Department of Justice, Office of Public Affairs, 10 September 2026
- Ukrainian National Pleads Guilty to Wire Fraud Conspiracy in Connection with Conti Ransomware — US Department of Justice, Office of Public Affairs, June 2026
- United States v. Lytvynenko, 3:23-cr-00088, docket — CourtListener/RECAP, M.D. Tenn., entries 6–13 (30 October 2025), 41–44 (10 June 2026), 52 (3 September 2026), 56 (10 September 2026)
- Plea Agreement, Doc. 43, United States v. Lytvynenko — M.D. Tenn., filed 10 June 2026, 18 pp.
- Indictment, Doc. 3, United States v. Lytvynenko — M.D. Tenn., filed under seal 22 May 2023, 10 pp.
- Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars — The Register, 11 September 2026
- Conti ransomware crew member sentenced to four years in prison — CyberScoop, September 2026
- Ukrainian hacker gets four years in US prison over Conti ransomware attacks — The Record, September 2026
- High Court: Man committed to prison pending his extradition to USA to stand trial for ransomware conspiracy charges — Irish Legal News, on Attorney General v Lytvynenko [2025] IEHC 100 (Keane J, 20 February 2025)
- Court of Appeal: Man fails in appeal against his extradition to USA to stand trial for ransomware conspiracy charges — Irish Legal News, on Attorney General v Lytvynenko [2025] IECA 212 (Burns J, 28 October 2025)
- Ukrainian National Extradited from Ireland in Connection with Conti Ransomware — US Department of Justice, Office of Public Affairs, 30 October 2025
- Multiple Foreign Nationals Charged in Connection with Trickbot Malware and Conti Ransomware Conspiracies — US Department of Justice, Office of Public Affairs, 7 September 2023
- Member of Prolific Russian Ransomware Group Sentenced to Prison — US Department of Justice, Office of Public Affairs, 4 May 2026
Related Research
Three men who worked in incident response ran BlackCat attacks. One of them was simultaneously negotiating on behalf of ransomware victims — and passing the attackers his own clients' insurance limits.
LockBit, BlackSuit and Play didn't run their own servers. They rented them from a company in St Petersburg that answered no abuse reports and no takedown requests, and billed like any other host.
The BlackSuit ransomware group (a rebrand of Royal Ransomware) compromised CDK Global, the dominant Dealer Management System provider for North American auto dealerships, causing a weeks-long outage affecting ~15,000 dealerships' ability to sell, finance, service, and manage vehicles — one of the most disruptive ransomware incidents against a critical software supplier in 2024.