Fake FSB Officer Tried to Shake Down the Conti Ransomware Gang
A Moscow man allegedly posed as an FSB officer and demanded money from one of the most dangerous ransomware crews in history. He is now in jail.
Russia's Investigative Committee is prosecuting Moscow resident Ruslan Satuchin, who investigators say impersonated an FSB officer and demanded a large sum of money from members of the Conti ransomware gang. RBC broke the story, citing two sources familiar with the case files.
The scheme, as investigators describe it, was simple. In September 2022 Satuchin contacted one of Conti's members and introduced himself as an FSB officer. For a price, he promised the hackers protection: no surveillance operations and no criminal charges. The case against him and "unidentified persons" landed three years later, in September 2025, under Part 4 of Article 159 of the Russian Criminal Code, fraud on an especially large scale.
Police detained Satuchin in Moscow in October 2025. RBC's sources point out a curious detail: he knew about the criminal case and the ongoing probe, yet made no attempt to run and kept living at his registered address. A court sent him to pre-trial detention the next day, then extended the arrest by two more months in December. Investigators argued that the witnesses know the defendant personally, so he could pressure them if released. His lawyers asked for house arrest instead, citing his family and stable social ties. Satuchin denies the charges and remains in a Moscow detention center.
The gang he picked
Conti, the crew Satuchin allegedly tried to squeeze, was no ordinary ransomware operation. It ran on the RaaS (Ransomware-as-a-Service) model and had ties to the Russian-speaking Wizard Spider group. Researchers at Group-IB called it a "criminal IT company": in-house HR, R&D and OSINT departments, regular salaries and a performance bonus system.
Conti first surfaced in February 2020. Over the next two years it hit 859 organizations worldwide, from multinational corporations to government agencies. Its loudest strike came in May 2022, when an attack on Costa Rica's government systems pushed the country into a national state of emergency. The US responded with a reward of up to 15 million dollars for information on Conti's leaders and members.
The hackers styled themselves as "patriots" and claimed they never touched Russian companies. That stance ended up destroying them. In February 2022 Conti's leadership publicly backed the Russian government, the group split, and its internal chats leaked online. A Ukrainian member of the gang, or a security researcher with access to its infrastructure, is believed to have published them. The ransomware's source code, its control panels and the BazarBackdoor API followed. Conti soon dissolved, and its former members scattered across other crews.
Written by
Read next
Microsoft Patches a Record 570 Flaws, Two Zero-Days Already Under Attack
On Tuesday, July 14, Microsoft shipped the largest set of fixes in Patch Tuesday history, closing 570 vulnerabilities at once. Attackers are already exploiting two of them in the wild, and a third was publicly disclosed before the patch landed. The most serious of the exploited bugs is CVE-2026-56164 in Microsoft SharePoint Server. A missing authentication check in a critical function lets an unauthenticated attacker escalate privileges across the network, with no password at all. Researchers a
Crypto Theft Fell to $972M in H1 2026, but North Korea's Share Climbed to Two-Thirds
In the first half of 2026, attackers stole about $972 million from the cryptocurrency industry across 207 incidents, according to a mid-year report from analytics firm TRM Labs. The figure is down by more than half from the same period in 2025, when losses were put at $2.3 billion. Despite the overall decline, the share tied to North Korea has actually grown. Analysts attribute roughly $643 million, about 66% of the half-year total, to the Lazarus Group and its TraderTraitor subunit. Almost all
The EU and UK Hit Russia With Their First Joint Cyber Sanctions
The sanctions target FSB Centre 16, the arm of Russian intelligence behind one of the world's most durable hacking operations, over a decade of attacks on Europe including an attempt to black out Poland in winter.
$643M in Six Months: How Lazarus Operates and Where the Evidence Runs Out
In the first half of 2026, analysts at TRM Labs attributed roughly $643 million to groups linked to North Korea, about 66% of everything stolen from the cryptocurrency industry, out of some $972 million lost across 207 incidents. Almost all of it came from two April attacks on DeFi protocols: the roughly $292 million breach of KelpDAO and the $285 million hit on Drift Protocol. A year earlier the shape was similar but the scale was not. Chainalysis put 2024 losses to DPRK-linked hackers at $1.34
Microsoft Patches a Record 570 Flaws, Two Zero-Days Already Under Attack
On Tuesday, July 14, Microsoft shipped the largest set of fixes in Patch Tuesday history, closing 570 vulnerabilities at once. Attackers are already exploiting two of them in the wild, and a third was publicly disclosed before the patch landed. The most serious of the exploited bugs is CVE-2026-56164 in Microsoft SharePoint Server. A missing authentication check in a critical function lets an unauthenticated attacker escalate privileges across the network, with no password at all. Researchers a
LegacyHive: Unpatched Windows Zero-Day PoC Dropped Hours After Patch Tuesday
Within hours of July's Patch Tuesday, a researcher going by Nightmare Eclipse (also seen as Chaotic Eclipse) published a proof-of-concept exploit for a new Windows vulnerability dubbed LegacyHive. No patch existed at the time of release, and the exploit works on the latest build of the system, assembled with July's updates already applied. The vulnerability lives in the Windows User Profile Service (ProfSvc) and its registry hive loading mechanism. When a user signs in, Windows mounts the UsrCl