Developer who worked for LockBit and Conti ransomware gangs arrested in Ukraine

Developer who worked for LockBit and Conti ransomware gangs arrested in Ukraine

Ukraine’s police have arrested a Kyiv resident who allegedly developed software for the notorious LockBit and Conti ransomware operations.

In an operation led by the Office of the Prosecutor General, cyber police operatives and investigators from the Main Investigative Department of the National Police identified a 28-year-old native of Kharkiv region. This individual had been collaborating with the Russian hacker group for a reward paid in cryptocurrencies, the police said.

According to the press release, the suspect developed so-called “cryptors” - specialized software designed to disguise computer viruses as safe files, hiding them from the most popular antivirus programs. These cryptors were used in the Conti ransomware attacks targeting computer networks of enterprises in the Netherlands and Belgium.

Through their investigation, cyber police linked the suspect to the Russian hacker groups “LockBit” and “Conti,” both known for disabling industrial enterprises by encrypting computer networks to extort ransoms.

The LockBit ransomware operation was disrupted in February 2024 as result of a global police effort codenamed ‘Operation Cronos,’ involving law enforcement authorities from 11 countries. In May, the US, UK, Australian authorities and Europol doxxed the administrator of the notorious LockBit ransomware operation, identified as Dmitry Yuryevich Khoroshev (aka 'LockBitSupp' and ‘putincrab’).

As for Conti, the ransomware group shut down operations in 2022 following the exposure of its internal chats and ransomware encryptor source code.

During the raids in Kyiv and the Kharkiv region, the police seized computer equipment, mobile phones, and handwritten notes.

The investigation is ongoing, and the issue of charging the suspect under Part 5 of Article 361 (Unauthorized Interference with the Operation of Information (Automated), Electronic Communication, Information and Communication Systems, Electronic Communication Networks) of the Criminal Code of Ukraine is being considered. The sanction under this article provides for up to 15 years of imprisonment. Additional legal qualifications may also be applied.


Back to the list

Latest Posts

Cyber Security Week in Review: July 4, 2025

Cyber Security Week in Review: July 4, 2025

In brief: Google patches Chrome 0Day, the US is on the hunt for North Korean IT workers, and more.
4 July 2025
AI chatbots fall for phishing scams

AI chatbots fall for phishing scams

The models provided the correct URL only 66% of the time; nearly 30% of responses pointed users to dead or suspended domains.
3 July 2025
Chinese hackers exploited Ivanti flaws in attacks against French government

Chinese hackers exploited Ivanti flaws in attacks against French government

ANSSI believes that the Houken campaign is operated by ‘UNC5174’, an entity believed to act as an initial access broker for China’s Ministry of State Security.
2 July 2025