The ProtectedTier 1 · The Spine · No. 1

Stern

Vitaly Nikolaevich Kovalev

One man sits at the hinge of the two largest pillars of the modern ransomware world. He is wanted on three continents, sanctioned by two governments, and named at last by a third. He has never spent a night in a cell, and the fortune he built is visible on the blockchain and untouched. This is why.

By Reno July 2026 12 min read Open Research
VISIBLE. UNTOUCHABLE. ARRANGED. THE MONEY IN HIS OWN NAME IN THE FAMILY controls (no wallet on record) blood THE FORTUNE hundreds of millions UNFROZEN VITALY KOVALEV personal holdings NONE director of one shell company, liquidated 2020 Z. B. KOVALEVA (mother) SOFTWARE FILM / TV ARTS RETAIL R & D REAL ESTATE SPORT HOLDS EVERYTHING CANNOT BE SEIZED HOLDS NOTHING The money is arranged before you read a word. The architecture of the money: visible, untouchable, arranged · End Krysha analysis

Every family tree in this project runs back to a handful of men who learned the trade together when the crime was still wire fraud. Vitaly Nikolaevich Kovalev is the one through whom the most passes. If Evgeniy Bogachev is the common ancestor, Kovalev is the heir who turned the inheritance into an enterprise. He took the Business Club's methods and built the machine that became TrickBot, Ryuk, and Conti: the syndicate that Western intelligence tracks as Wizard Spider. He ran it under one name, whispered inside the organization long before any government said it aloud. Stern. Confirmed reporting

The name held its secret for years. Investigators and vendors knew Stern was the boss. They did not know who Stern was. That gap closed in May 2025, when Germany's Bundeskriminalamt did what no agency had done before and put a face and a legal name to the handle. The rest of this file is the story of the man behind it, of the money that no one can freeze, and of the roof that has kept both out of reach the entire time. Confirmed reporting

The room he came from

Kovalev did not appear with TrickBot. He arrives in the record more than a decade earlier, as an organizer of the plumbing that turns stolen bank credentials into cash. A U.S. federal grand jury in the District of New Jersey indicted him in 2012 for conspiracy to commit bank fraud and eight counts of bank fraud, tied to intrusions into U.S. bank accounts in 2009 and 2010, with an estimated loss around 950,000 dollars. That indictment sat under seal for eleven years. It was not unsealed until February 2023, by which point the small-time mule organizer had become the CEO of the most productive ransomware operation on earth. Confirmed reporting

The bridge between the two is the Business Club era. Threat-intelligence analysis places Kovalev, under the handle Bentley, among the principal members of GameOver Zeus, the peer-to-peer banking botnet that the FBI-led Operation Tovar dismantled in June 2014. Tovar took the infrastructure and left the people. The talent and the tradecraft flowed onward, first into the Dyre banking trojan, which U.S. Treasury describes as the direct predecessor of TrickBot, and then into TrickBot itself, which researchers first identified in 2016. Credible reporting

The pattern set in that first room never changed. A hard separation between the people who write the malware and the people who move the money. A core built on trusted relationships rather than anonymous forums. A home base beyond Western reach. Kovalev would scale that architecture a hundredfold. Analyst inference

November 2015: the raid that made Stern

By 2015 the crew faced the problem every successful cybercrime operation eventually meets: what to do with the money, and how to look legitimate while doing it. Their answer sat on the twenty-fifth floor of a Moscow tower. 25th Floor was a working film production company and, at the same time, a laundering vehicle for the proceeds of Dyre, the banking trojan that was Stern's operation before TrickBot existed. Confirmed

It even had a film in development: the journalist Geoff White reports that 25th Floor flew in a screenwriter to write a picture called Botnet, a thinly fictionalized life of the gang's leader, then known as Benny. Credible reporting

In November 2015, Russian authorities raided the offices. Reuters and Kaspersky tied the search directly to the Dyre operation. People were questioned and, tellingly, no one is known to have been charged. Dyre went quiet within weeks. Confirmed reporting

This is the hinge of the whole story, and it is worth slowing down for. The raid did not end the operation. It reorganized it. Within months the same crew's tooling re-emerged as TrickBot, the platform that would carry the group to Ryuk and then to Conti. The man at the center shed his old skins along the way. The Business Club's Bentley, the underground's Ben and Benny, the names of the Dyre years, recede here, and Stern appears. The leader who walked out of the 25th Floor raid was not the same operator who walked in. Analyst inference

Kovalev did not come out of 2015 diminished. He came out protected, and he came out as Stern.

What changed was not only the branding. This project assesses the 2015 raid as the moment the Russian security state, assessed to be the FSB, stopped being a hazard to the crew and became its roof. An operation raided by its own government does not usually resurface, unbothered, under a new name, and go on to extort billions from the West. This one did. The most economical explanation for a crew that is searched, released, and then left alone to scale is not luck. It is arrangement. The state got involved, and the involvement changed the operation without weakening the man. Analyst inference

The name even outlived the raid. In the Russian corporate registry, film companies under the same "25th Floor" name trace to Kovalev's mother, all since liquidated. The brand was burned once and kept reappearing on the family's paperwork. Confirmed registrations

Building the machine

By the late 2010s Kovalev sat at the top of a structure that looked less like a gang than a company. German federal law enforcement, U.S. Treasury OFAC, and the U.K. National Crime Agency all assess him as the founder and supreme leader of the Wizard Spider organization: the umbrella over the TrickBot platform, the Ryuk ransomware operation, and later the Conti syndicate. The BKA's own assessment is blunt about the scale. At times, it found, the TrickBot group ran to more than a hundred members, operating in an organized, hierarchical, project-and-profit-oriented manner. Confirmed reporting

The links between the pieces are not guesswork. TrickBot and Ryuk are tied by shared wallet addresses and blockchain forensics. TrickBot and Conti are tied by source code, leaked chats, blockchain tracing, and a joint CISA and FBI advisory. This is one of the best-corroborated lineage claims in the entire ecosystem, resting on several independent bodies of evidence at once. Confirmed reporting

Under Kovalev, Conti became a formal ransomware-as-a-service operation with an internal chart resembling a technology startup: salaried coders and managers paid in Bitcoin once or twice a month, negotiators on commission, affiliates recruited by invitation on forums such as XSS and Exploit. Affiliates deploying Conti typically kept around 70 percent of a ransom, with 30 percent flowing to the core. The tradecraft was industrial: double extortion, a darknet leak site called Conti News, victim-specific negotiation portals on Tor, and a deliberate campaign against healthcare during the COVID-19 pandemic. Confirmed reporting

Stern the boss

The proof of who ran it came from inside. In February 2022, after Conti publicly pledged support for Russia's invasion of Ukraine, a Ukrainian researcher published more than 100,000 of the group's internal Jabber and Rocket.Chat messages. The ContiLeaks laid the org chart bare. Analysis of the dump described Stern as the Big Boss, the leader developing the high-level vision, managing people and projects directly and indirectly. Members needed Stern's explicit approval before launching attacks or hiring lawyers for arrested colleagues. The leaks did not just confirm that Stern led Conti. They confirmed that the whole structure bent around a single point of command, and that the point was him. Confirmed reporting

What the leaks did not do was give Stern a name. Across the underground he surfaced as Ben, Bergen, and Alex Konor. OFAC would later list Bentley as an official alias; the DOJ indictment carried Bergen. But a wall of handles is not an identity, and for three more years the wall held. Confirmed reporting

Fig. 1 · The face behind the handle
CandidVitaly Kovalev
SurveillanceVitaly Kovalev
PortraitVitaly Kovalev
SurveillanceVitaly Kovalev
Vitaly Nikolaevich Kovalev. Images drawn from open-source and leaked materials collected during the unmasking of the Stern persona.

The money: visible and untouchable

Most fugitives hide their money. Stern's is the opposite problem: it is on the blockchain, in plain sight, it is enormous, and nothing has been done about it.

Start with the wallet. A single Bitcoin wallet controlled by Stern, made up of hundreds of addresses, received well over 13,000 bitcoin across its life. At the valuations of the Conti years that is a fortune in the hundreds of millions of dollars; at later prices it runs higher still. The coins moved, mixed, and cashed out through the same laundering rails the group used for ransom proceeds, but the origin point is not in doubt. Confirmed

German investigators have put the scale of the fortune as high as a billion euros, an estimate now repeated in Russian coverage as well. Credible reporting

Now set that against the sanctions record. OFAC designated Kovalev in February 2023 and attaches no wallet address to him at all. Nothing traceable to Stern has been frozen or seized. The single most important fact about his money is the gap between how visible it is and how untouched it remains. An analyst can watch the fortune. No government has laid a hand on it. Confirmed

An analyst can watch the fortune. No government has laid a hand on it.

The pattern repeats above ground, where his name is conspicuously absent. In the Russian corporate registry Kovalev owns nothing. He appears as the director of exactly one company, a Moscow software shell called NineSoft that reported zero revenue and was liquidated in 2020. That is the whole of his legal business footprint. Confirmed

The assets sit one name over, with his mother. Zhannetta Borisovna Kovaleva, born 1960, is the registered owner of a portfolio that spans software (NineSoft, which she owned outright while her son nominally ran it), beverage retail (a Volgograd company called Rada), film and television production companies in Moscow, a performing-arts firm, an equestrian-sport association, a scientific-research company (InnovVita, registered in 2024 and co-founded with a Russian state medical university), and a real-estate rental business she runs as a sole proprietor. Confirmed

The spread across unrelated sectors, held by a retiree while her sanctioned son holds nothing, reads as the signature of assets parked under a family member. Analyst inference

Three layers, one design. A crypto fortune the West can see and cannot freeze. A personal register swept clean. A legitimate-facing portfolio held by his mother. The money is not missing. It is arranged. Analyst inference

Fig. 2 · Where the name appears, and where it does not
LayerIn whose nameStatus
Crypto proceedsStern (wallet, 13,000+ BTC received)Visible on-chain; never frozen or seized
OFAC listingVitaly KovalevSanctioned 2023; no wallet address attributed
Personal companiesVitaly KovalevNone owned; director of one shell (NineSoft), liquidated 2020
Business portfolioZhannetta B. Kovaleva (mother)Software, retail, film/TV, arts, sport, R&D, real estate
The register-clean subject and the asset-holding parent: the structure of insulation. Sources: Russian corporate registry (EGRUL); OFAC SDN listing.

The roof

This is what puts Kovalev in this section rather than a prison, and the money is its clearest proof. The tradecraft was Western-facing and the profits were enormous, and yet the machine ran for years from inside Russia with no domestic consequence, because the machine was useful and its operator stayed home.

The U.S. Treasury said as much, on the record, in February 2023: current members of the TrickBot group are associated with Russian intelligence services, and the group's 2020 preparations aligned them to Russian state objectives, including targeting of the U.S. government and U.S. companies. That is the strongest public U.S. statement of a state nexus for this cluster. Note its limits as carefully as its force. Treasury did not name which service, and it did not claim direct operational control. Confirmed reporting

The honest characterization is state-tolerated rather than state-directed: what Recorded Future calls controlled impunity. The supporting evidence is circumstantial but consistent. No documented Conti or Wizard Spider attacks on Russian or CIS-based victims. Kovalev living openly in Russia despite warrants on three continents, his fortune visible and unfrozen. Targeting that aligns with state interests without needing to be commanded. There is no public evidence of formal tasking, intelligence-sharing agreements, or deliverables changing hands, and this file does not assert any. The roof does not require a contract. It requires only that the West cannot reach the metal, the man, or the money. Analyst inference

There is a quieter tell as well. Russia's own media covers the case as the story of a clever criminal entrepreneur, a man with companies and a crypto fortune, and never once mentions the protection. The roof is most visible in the places it is never named. Analyst inference

The reckoning that isn't

On paper, the case against Kovalev is overwhelming. He carries U.S. OFAC sanctions under the CYBER2 program, designated February 9, 2023. He carries U.K. sanctions under the Cyber (Sanctions) (EU Exit) Regulations 2020, imposed the same week, making any ransom payment to him a sanctions violation. He carries the unsealed 2012 New Jersey indictment. And in May 2025, Germany added an arrest warrant, naming him as the ringleader of a transnational criminal organization and the founder of TrickBot and Wizard Spider, alongside an Interpol Red Notice. Confirmed reporting

None of it has cost him his freedom or his money. No arrest has been made. He is assessed to be inside Russia, and extradition is not feasible under current conditions. The Interpol notice constrains his international travel and complicates any laundering that has to touch international financial infrastructure, but it does not reach him at home. The pattern that Operation Tovar taught the ecosystem in 2014 holds for its most successful graduate: infrastructure can be seized, protected people cannot, as long as they stay home and stay useful. Confirmed reporting

Consolidated designations and warrants (excerpt)
Subject: Vitaly Nikolaevich KOVALEV, aliases “Stern”, “Bentley”, “Bergen”, “Ben”
Role: founder and leader, Wizard Spider (TrickBot / Conti / Ryuk)
Indictment: D.N.J., filed 2012, unsealed Feb 9, 2023
Designations: OFAC CYBER2, Feb 9, 2023; UK Cyber Sanctions, Feb 2023
Germany: BKA arrest warrant and Interpol Red Notice, May 2025
Status: at large, Russian Federation
Compiled from OFAC, US DOJ, UK NCA, and German BKA public records. Reproduced for analysis.

What we do not know

A file this size should be honest about its holes. Kovalev's current operational role is unconfirmed: whether he is an active leader, a financial backer, an advisor, or effectively retired in any successor operation is not established by any official source. The specific service behind the state nexus, whether FSB, SVR, or GRU, is unnamed in public reporting. And while the origin of his crypto fortune is settled, the current disposition of those funds, how much remains liquid and where, is not something open reporting can fully trace. Analyst inference

The clean version is the one that matters for this project. Stern built the most efficient ransomware enterprise the West has yet seen, extracted a fortune now measured on-chain, arranged it so that his own name touches none of it, and was named, indicted, and sanctioned by three governments without losing a day of freedom or a coin of the proceeds. He is protected. That is the whole point.

Sourcing & confidence

This file draws on US Treasury OFAC and US DOJ (District of New Jersey) records, the UK NCA sanctions announcement, the German BKA Operation Endgame arrest warrant and Interpol Red Notice (May 2025), the CISA and FBI advisory AA21-265A on Conti, analysis of the 2022 ContiLeaks, blockchain tracing of the group's proceeds, and Russian corporate-registry (EGRUL) records for the companies named. Confidence labels follow standard analytic practice.

Confirmed · official record, or multiple independent sources.
Credible · single strong source or consistent vendor reporting, not yet officially confirmed.
Analyst inference · the project's own assessment, drawn from the evidence above.

KovalevSternWizard SpiderTrickBotContiRyukOperation EndgameThe Protected