A Latvian national extradited to the United States has been sentenced to 8.5 years in prison for his role as a “cold case” negotiator in the notorious Russian Karakurt ransomware group.
35-year-old Deniss Zolotarjovs from Moscow, Russia, was arrested in Georgia in December 2023 and pleaded guilty in July 2025 to conspiracy to commit wire fraud and money laundering charges filed against him in August 2024 after being transferred to U.S. custody.
According to court documents, Zolotarjovs (also known online as “Sforza_cesarini”) was a key member of the Karakurt extortion operation, which was led by former Conti ransomware gang leaders. The group specialized in compromising company systems, stealing sensitive data, and demanding ransom payments from victims under threat of public data leaks or sales to other cybercriminals.
The FBI linked Zolotarjovs to at least six extortion cases against American organizations between August 2021 and November 2023. His specific role involved negotiating so-called “cold case extortions” – situations where initial communication with victims had ceased without ransom payment being made.
Zolotarjovs played a crucial role in convincing victims to reconsider their refusal to pay ransom demands. He conducted extensive research on targeted companies and analyzed stolen personal and health information to increase psychological pressure on victims.
He was also associated with attacks by various other ransomware groups including Conti, Royal, TommyLeaks, SchoolBoys Ransomware, and Akira.
According to Department of Justice estimates, attacks on just 13 of the more than 54 companies targeted by Zolotarjovs resulted in over $56 million in losses, including approximately $2.8 million in confirmed ransom payments. The government believes true losses could be in the hundreds of millions of dollars due to widespread underreporting of ransomware incidents.
Zolotarjovs represents the first Karakurt member to face charges and sentencing in the United States, potentially paving the way for prosecution of additional group members, some of whom are former Russian law enforcement officers.
His connections allegedly allowed the group to access Russian government databases and law enforcement connections to intimidate personal detractors and identify potential new recruits. Corruption within the organization reportedly enabled leaders to avoid Russian taxes and regularly pay bribes to exempt draft-age men from compulsory military service in Russia.
In related developments, two former Sygnia and DigitalMint employees were also sentenced to four years in prison each for targeting U.S. companies in BlackCat (ALPHV) ransomware attacks.


