Cybercrime

Ukrainian Malware Operator Pleads Guilty in US Court

Ukrainian national Mark Sokolovsky has pleaded guilty in a US court to operating the malware named Raccoon Infostealer.

Ukrainian national Mark Sokolovsky has pleaded guilty in a US court to operating the malware named Raccoon Infostealer.

The US Justice Department announced on Monday that a Ukrainian national has pleaded guilty over his role in the operation of a piece of malware named Raccoon Infostealer.

The individual is 28-year-old Mark Sokolovsky. He was arrested in March 2022 in the Netherlands and extradited to the US in February 2024 to face computer hacking, fraud, identity theft and money laundering charges.

When they arrested Sokolovsky, authorities also dismantled the infrastructure used at the time by Raccoon Stealer, but the malware was later resurrected

The Justice Department said Sokolovsky pleaded guilty in a Texas court to one count of conspiracy to commit computer intrusions. As part of the plea agreement, the Ukrainian cybercriminal will forfeit nearly $24,000 and pay more than $910,000 in restitution. 

Raccoon Infostealer emerged in 2018 and Sokolovsky is said to be one of its “key administrators”.

The malware, offered through a malware-as-a-service model, enabled users to steal data from infected devices, including login credentials and financial information, which could be used for financial crimes or be sold to other cybercriminals.

Advertisement. Scroll to continue reading.

Raccoon Infostealer was leased to malicious actors for $200 per month and it infected millions of computers around the world.

The FBI has set up a website where users can check whether their email address shows up in the data stolen by Raccoon Infostealer.

Related: More LockBit Hackers Arrested, Unmasked as Law Enforcement Seizes Servers

Related: Russian TrickBot Malware Developer Sentenced to Prison in US

Related: Russian Sentenced to Prison in US for Selling Stolen Information

Related: Ukrainian Sentenced to Prison in US for Role in Zeus, IcedID Malware Operations

Related Content

Cybercrime

Connor Riley Moucka was extradited to the United States in July 2025 after he was arrested in Canada. 

Malware & Threats

The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.

Malware & Threats

The malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems.

Artificial Intelligence

SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot.

Malware & Threats

Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop.

Malware & Threats

The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533.

Malware & Threats

The new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency. 

Endpoint Security

Bitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint security products.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version