Cybercrime

Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court

Ardit Kutleshi created and operated Rydox, which allowed miscreants to trade PII and cybercrime tools and services.

Hacker pleads guilty

A Kosovar national pleaded guilty in a US court to charges related to the creation and administration of the Rydox cybercrime marketplace.

The individual, Ardit Kutleshi, 28, was arrested in December 2024 along with two other suspects, Jetmir Kutleshi and Shpend Sokoli. He was extradited to the US last year.

Rydox was disrupted in December 2024, when the US obtained judicial authorization to seize www.Rydox.cc, the domain that hosted the marketplace. The Rydox servers were also seized, along with roughly $225,000 in cryptocurrency.

According to court documents, Rydox allowed cybercriminals to trade stolen personally identifiable information (PII), stolen payment card data, account credentials, and cybercrime tools.

At least 321,372 cybercrime products were allegedly offered on Rydox, including stolen information such as names, addresses, credentials, credit cards, and Social Security numbers, along with phishing kits, stealer logs, and spamming tools.

Rydox was estimated to have had approximately 18,000 users when taken down.

Advertisement. Scroll to continue reading.

More than 7,600 transactions were made through the marketplace between 2016 and 2024, and its operators received at least $232,000 in revenue.

Kutleshi pleaded guilty to identity theft and money laundering conspiracy charges and is scheduled for sentencing on February 9, 2027.

He faces two years of mandatory prison for the aggravated identity theft and up to 20 years in prison for money laundering.

Related: US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks

Related: AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft

Related: In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

Related: NightmareStresser DDoS Service Disrupted in International Operation

Related Content

Cybercrime

The cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets.

Cybercrime

Active since at least 2022, NightmareStresser was one of the longest-running DDoS-for-hire services in the world.

Cybercrime

The defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash.

Data Breaches

The private equity firm appears to have been targeted as part of a campaign focusing on major financial companies.

Malware & Threats

Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands.

Cybercrime

Hundreds of C&C servers were disrupted in an operation involving law enforcement and several cybersecurity companies.

Cybercrime

Nathan Austad has been ordered to pay roughly $1.8 million in forfeiture and restitution, and the sentence also includes 3 years of supervised release. 

Malware & Threats

Mistic is used by Woodgnat, an initial access broker working with Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version