Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Ukrainian Nefilim Ransomware Affiliate Pleads Guilty in US

Artem Stryzhak pleaded guilty to conspiracy to commit computer fraud after he was extradited earlier this year.

Hacker arrested

A 35-year-old Ukrainian national pleaded guilty in a US court on Friday to charges related to Nefilim ransomware attacks.

The suspect, Artem Aleksandrovych Stryzhak, was arrested in Spain in 2024 and extradited to the United States in late April 2025.

Stryzhak has pleaded guilty to conspiracy to commit fraud related to computers. He is scheduled to be sentenced in May 2026 and faces up to 10 years in prison.

According to authorities, the Ukrainian national was a Nefilim ransomware affiliate. The ransomware operation’s administrators provided him with malware and other resources needed to launch cyberattacks against major companies worldwide in exchange for 20% of the money he received from victims.

[ Read: Inside the Journey of Russian Hacker on FBI’s Most Wanted List ]

Court documents show Stryzhak became a Nefilim affiliate around June 2021, and suggest he was involved in other criminal activities.

Advertisement. Scroll to continue reading.

The man was encouraged by others to target companies in countries such as the United States, Canada, and Australia, with an annual revenue exceeding $200 million. 

The cybercriminals stole valuable data from victims’ systems and then deployed file-encrypting malware, demanding a ransom payment to decrypt the files and prevent stolen data from being made public. 

One of Stryzhak’s co-conspirators, Volodymyr Tymoshchuk, is still at large with an $11 million reward on his head. 

Tymoshchuk has been accused of being an administrator of the Nefilim ransomware and is also believed to have participated in hundreds of attacks involving LockerGoga and MegaCortex ransomware. 

Related: Ransomware Payments Surpassed $4.5 Billion: US Treasury

Related: Ransomware Attack Disrupts Local Emergency Alert System Across US

Related: 700,000 Records Compromised in Askul Ransomware Attack

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Barry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer.

John DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox.

Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.