0.4 BTC — worth $25,042 — was one of several crypto transfers prosecutors tied to the work of a man who had trained as a lawyer before turning to ransomware development. That transfer was traced to a victim and has been ordered forfeited as part of a U.S. case that ended with a four‑year prison sentence.
Oleksii Oleksiyovych Lytvynenko — from lawyer to "henry"
Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national who later lived in Cork, Ireland, pleaded guilty in June to conspiracy to commit wire fraud for his role in the Conti ransomware operation. According to his plea agreement, he operated under the handle "henry" and was recruited into a team run by another Conti conspirator known as "silver" or "buza." Prosecutors say Lytvynenko trained as a lawyer before joining Conti as both an intruder and a developer, and that he was directed to work on a malware loader — the component that gets additional malicious code running on a victim's machine.
Technical footprint: loaders, Cobalt Strike and encrypted chat
Evidence in the case outlines a technical profile that moved beyond simple scripting. When Gardaí arrived at Lytvynenko’s County Cork home in July 2023, they reported finding his laptop open with Cobalt Strike running and a Rocket.Chat session connected over Tor. Prosecutors also point to his online accounts, where investigators found Conti malware, ransom notes and stolen victim data alongside books and videos about malware and hacking. The plea filing further says Lytvynenko used online tools — specifically Google and ZoomInfo — to research potential targets.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildFinancial traces and victim harm: 0.4 BTC, $1.5M in reported U.S. losses
Court documents identify several Bitcoin transfers tied to Lytvynenko’s Conti work. One transfer of 0.4 BTC, valued at $25,042, was traced back to one of his victims and has been ordered forfeited. Investigators found that he possessed data stolen from eight U.S. victims and four overseas victims; the eight American victims reported more than $1.5 million in losses. Prosecutors also tied other Bitcoin movement to his activity as part of the broader Conti operation.
Conti's scale, public unraveling, and continued activity
The Conti operation is described in court filings and government statements as a large, Russia‑linked ransomware group associated with more than 1,000 victims and at least $150 million in ransom payments. The Justice Department says Conti attacked organizations across 47 U.S. states, the District of Columbia, Puerto Rico, and 31 foreign countries between 2020 and 2022. By January 2022 the FBI had estimated victim payouts associated with Conti exceeded $150 million. Conti disbanded in 2022 after internal chats and source code were leaked following the gang's public support for Russia's invasion of Ukraine; prosecutors say Lytvynenko’s involvement in ransomware activity continued after that disbandment.
Extradition and sentence: cross‑border enforcement in action
Lytvynenko was arrested in Ireland in July 2023 and later extradited from Ireland to the United States in October 2025. He pleaded guilty in June and has been sentenced to four years in a U.S. prison, and ordered to forfeit the funds tied to the traced Bitcoin transfer.
What this means for technologists, affected enterprises, and law enforcement
- Technologists and security teams: The case underscores the operational role of loaders and dual‑use tools — investigators found Cobalt Strike running on an active device and a Rocket.Chat session over Tor. Defensive teams will note that malware development, readily searchable resources on malware, and commodity tools can coexist on a single operator’s machine.
- Affected enterprises and procurement leaders: Prosecutors linked stolen data from multiple victims to a single operator and documented more than $1.5 million in reported losses for just eight U.S. victims. Organizations should expect continued focus on data theft and extortion as measurable sources of loss.
- Law enforcement and international partners: The sequence — an Irish search in July 2023, extradition in October 2025, guilty plea in June, and a U.S. sentence — shows multi‑year, cross‑border cooperation culminating in forensic tracing of crypto transfers and asset forfeiture.
Oleksii Lytvynenko’s four‑year sentence closes one chapter in the long, geographically dispersed Conti story, but the record assembled in court filings — usernames, chat aliases, traces of loaders and coin movements — also illustrates how individual operators can be linked to large‑scale campaigns. Whether that forensic paper trail proves to be a deterrent or simply one more lesson learned by others remains a question the documents do not answer.




