According to court documents, Lytvynenko operated under the handle 'henry' and worked on a team led by another Conti conspirator known as 'silver' or 'buza.' His primary task was writing a malware loader — software designed to deploy malicious code on victims' machines. Prosecutors said his Google account contained evidence of research into hacking techniques, alongside Conti malware, ransom notes, and stolen victim data. He also used Google and ZoomInfo to identify potential targets.
Lytvynenko's involvement extended beyond coding. Investigators found that he possessed data stolen from eight US victims and four overseas, with the eight American victims reporting combined losses exceeding $1.5 million. Bitcoin transfers tied to his work included 0.4 BTC (worth $25,042 at the time of transfer), which prosecutors traced back to one victim. He has been ordered to forfeit that amount.
Conti disbanded in 2022 after internal chats and source code were leaked following the gang's public support for Russia's invasion of Ukraine. Lytvynenko, however, did not cease his activities. When Irish police (Gardaí) raided his County Cork home in July 2023, they found his laptop open, Cobalt Strike running, and a Rocket.Chat session connected over Tor. Prosecutors said evidence from the machine showed he remained active in ransomware operations after Conti's collapse.
The Justice Department says Conti attacked organizations across 47 US states, the District of Columbia, Puerto Rico, and 31 foreign countries between 2020 and 2022. By January 2022, the FBI estimated that victim payouts associated with Conti exceeded $150 million. Lytvynenko's sentence was handed down in a US federal court, and he will now serve four years in prison.