The two subjects before this one were both answering for an organisation. Alex C spoke for RTM Team and would not be drawn a step past that, and the Bashe crew answered me collectively, in one voice, having told me up front what they wanted out of the coverage. Either way what reached me was a position that had been settled somewhere before I asked. This time there was nobody standing behind the answers except the man giving them. He replied over Tox, in his own rough English, and spent most of the opening round explaining why he believes the law chasing him is more unjust than what he does with a keyboard. The later questions, and the round I want to build out of these answers, have not gone to him yet.
He calls himself sourcec0de. He is, by his own account, a Russian ransomware operator, thirty years old, under investigation by at least three United States agencies, and being treated for bone cancer. He answered the first eleven of my questions, acknowledged that everything he does is a crime, and then made an argument about why he does it anyway. I have published the argument with the record attached, because the argument is the point.
What I have not done is verify him. I cannot confirm that the person answering me on Tox is the person behind the alias in the reporting I cite below, that he carried out the attacks he describes, or that a single one of his operational claims is true. Read it as testimony from inside a criminal business, given by a man with every reason to manage how he comes across. I am not standing behind any of it.
Who sourcec0de is, on the public record
The alias is not new. In September 2011, Brian Krebs reported that administrative access to MySQL.com had been offered for sale in the underground for about $3,000, and that the seller used the handle sourcec0de. He pointed me at that report himself. It is the only part of his story that exists in public independent of him, and it only goes so far. It puts the alias in the MySQL.com episode. It does not put the man on my Tox behind the alias. He says he is. I cannot prove it.
By his telling, MySQL.com was an early job. He describes exploiting the site, taking the servers, and selling the access to someone who burned it on a browser-exploit kit, after which Krebs tied the episode to his post. He says he then worked under a second alias, g3tty, on a well-known exploit forum, hacked several Russian darknet markets, and specialised in Western shops and payment processors, selling card data and holding the proceeds in cryptocurrency early. His account of the arc is his own:
then got into ransomware somewhe in 2021, back then I already had connections with FSB and one guy from it suggested ransomware. Back in the day all I knew about ransomware was “that it is consumer ransomware, targeting folks for 200$ payouts”. Boy was I wrong. I got into corporate administration along the way, I hacked so many targets via proxyshell and other RCEs, like fortinet, etc. Entire cities, airports, billion-revenue corporations.
The claim that an FSB contact steered him into ransomware is the sort of thing that cannot be checked and should not be repeated as fact. I include it because he volunteered it, and because the relationship between Russian security services and Russian ransomware crews is a live question that this kind of testimony feeds without settling. Treat it as what he wanted me to hear.
He says the attention became mutual. He claims he learned, through notifications to his own email, that his data had been subpoenaed by the FBI, the Secret Service and DCIS. DCIS is the Defense Criminal Investigative Service, the criminal investigative arm of the US Department of Defense Inspector General, which would be an unusual agency to see on a fraud case and a less unusual one to see if a suspect had, as he puts it, “hack critical American infrastructure and encrypted it.” He offered his illness in the same breath:
so here I am, sick with cancer and still working to afford my treatment and/or leave money to my son. I’m 30 y.o (bone cancer targetting young folks unfortunately)
I have no way to confirm the diagnosis, the investigation, or the son. They are offered as mitigation, and a reader is entitled to weigh them as such while remembering that everything after the diagnosis is still a description of harm done to other people.
How the contact was made
I reached him the way I reach everyone in this series, over Tox, using contact details mined from three years of offline copies of cybercrime forums. I introduced myself, gave him a way to verify my Tox ID, and pointed him at two decades of published work so he could decide whether I was worth answering. He replied within a day, asked how I had found his Tox address, and said he had already thought about talking to Western press, Wired or BleepingComputer, for a book he says he is writing about the ransomware ecosystem. He had no offers on the table, he said, so he was open to mine.
He set a single condition before anything else. He would not name anyone he works with.
I will never reveal sensitive info about my friends or other people in this sphere, don’t ever ask or we won’t work. this is the only request from me
He made one request about himself, too. He gave me his first name and, privately, his surname, and asked that only the first name and the alias appear in print. His reasoning is worth quoting in full, because he told me I could, and because it is the clearest thing he said about how he thinks the machinery around him works:
its known to American special services investigating me, but public interview with my name and openly discussing crimes will kinda destroy “plausible deniability” Russian special forces have to not obey international arrest warrants. So there is that, my kind request is to use my nickname and my first name, but not last name.
I have honoured it. He is Yuriy and sourcec0de in this piece, and the surname stays out. I would have withheld it in any case, because I have no way of checking it against anything. He also mentioned, more than once, that he was between rounds of chemotherapy and would not always be online, which is worth keeping in mind against the pace of a staged interview like this one.
One note on language. He took my questions in English and answered in English, and the answers below are his, grammar and spelling included. I have trimmed for length where a single answer ran into unrelated territory, and marked where I did, but I have not reworded him. Leaving the mistakes in is deliberate. It is how you can tell this came back from one man over Tox and not from a crew settling on a line.
Establishing contact
Who am I speaking to?
▮ sourcec0deYuriy [surname withheld at his request]. My kind request is to use my nickname and my first name, but not last name, which I only shared to you privately. More known under the alias sourcec0de. Then I was doing some hacking here and there, under the alias g3tty on exploit forum.
Are you familiar with my research and achievements throughout the years?
▮ sourcec0deNo i am not aware of your work, I will familiarize myself with it out of respect and honest curiousity. Even though I believe the interview can be done without this.
The interview, so far
He answered the first eleven of my questions, nine of them substantive. The first one he took was how he started, and his answer reaches back to a school computer room.
How did you get started in the cybercrime ecosystem?
// Free tool
How does your own site score?
Run the same forty passive checks against your own domain — TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in about fifteen seconds.
No signup. Nothing installed. We only request what your site already serves publicly.
I started as a kid (11-12 years old), the main motivation was combo of three factors: a.) my own personality (desire for control and power), b.) my physical attributes (small height, weight, which makes me look unassuming), and c.) my background: poor family, single mother working as a school teacher.
my first hack was in IT classes in school: I put a traffic sniffer for routers. Back in the day VK social network was booming. So i hacked everyone from my school who authorized in vk from IT classes, been reading their messages, understanding psychology of older kids and learning people through their private messages.
How would you describe yourself? A vendor of a service, an active threat actor, or a ransomware operator?
▮ sourcec0deI am an active threat actor doing the work usually performed by the entire teams: I use CVEs to gain initial access, then I move laterally through the corporate network, analyze the network topology, escalate privileges, gain backups / virtualization access, then encrypting the network. I also personally requested development of private tools helping in the work.
How did you get involved with computers?
▮ sourcec0demy knowledge was mostly self-procured. I was studying from online courses that I couldn’t afford originally (so I downloaded their pirated version), I studied web tech and languages such as php/python, sql, linux administration and scripting. All the while actively hacking sites as a kid.
How far-reaching is what you are currently doing?
▮ sourcec0deI am currently doing the same thing since I got into ransomware, taking RCEs, scanning and encrypting the networks. Sometimes though I receive outsourced accesses from acquaintances who need my expertise in encrypting the network.
What are your current projects and future plans?
▮ sourcec0deI am also writing a book about myself and my “exploits”. I also was given couple of students to teach. One is already almost fully autonomous, after a month of severe everyday training he needed only a week of my intensive program to hack into prison and encrypt it, albeit in obscure country Aruba.
with my help my associates also curate couple other projects, like creating “HACK AI”, using models and our own hardware to weaponize artificial intelligence models for hacking purposes: creating exploits for “hard to exploit CVEs”, bypassing AV/EDR restrictions, scanning networks.
Are you a pure opportunist, a businessman, or do you hold an ideological justification?
▮ sourcec0deI have no delusions of grandeur about my position in the world: I do harm, there is no doubt. But I do it professionally, and yes, I do have not exactly justifications, but extenuating circumstances. All these circumstances, however, do not rob me of realization that all my crimes, nor rob me from responsibility of attacking western corporations, citizens and entire countries.
However, I do need to mention ideological distaste towards unjust legal system, the fact that financial crime is treated with condescension and mercy but cyber crimes sometimes prosecuted with intention to put for a lifetime the perpetrators. if they keep putting away young guys for this for a lifetime, I will never stop.
How do you compartmentalise your operator life from your real-world life?
▮ sourcec0deI don’t do that. All my acquaintances of significance know what I do, its not really treated as a big deal. cyber crime is treated like regular work in Russia. Most people who are not IT-savvy wouldn’t know the difference between cyber crime and cyber security gig. So before I was officially in FBI investigation, I was just saying I am cyber security researcher.
What is the biggest misconception the public has about people in the ecosystem?
▮ sourcec0deassuming it takes some cosmic world-class talent to be a hacker, or some naive perception of activity, like viewing it as magical stuff. I do not like my answer on this question, so I will either think more on it or maybe you can rephrase.
Have you ever been scammed or ripped off by other actors?
▮ sourcec0deNo, I haven’t been scammed or ripped off. But I have seen it happening with people whose talents I respected and who weren’t “lame”, so this thing happening with people a lot. I am really controlling and mistrusting individual, that’s why I never have been betrayed. [answer continues into personal matters, omitted]
I do harm, there is no doubt. But I do it professionally.
After the conversation
What checks out, and what does not
One thing corroborates, weakly. The sourcec0de alias really does appear in Krebs’s 2011 MySQL.com reporting, so the name has a documented history in a genuine incident. Everything else rests on his word. The FSB tip, the attacks on cities and airports, the students, the offensive-AI project, the subpoenas: none of it is verifiable from where I sit, and some of it is exactly the kind of claim an operator inflates to raise his own standing. DCIS is a real agency and it would make sense on a critical-infrastructure case, so at least that detail hangs together with the rest of what he told me. I still cannot show that any of it happened.
The argument he wants to make
His central claim is not technical, it is about justice, and he made it before I had asked a single question. He put it like this: that a repeat drug offender who commits a killing might serve fifteen or twenty years, while a young man with no record can face forty years or life for a run of ransomware attacks against businesses. He compared it to the way counterfeiting was once punished as a crime against the state, and argued that a single crypto payment, moved between wallets, can be stacked into dozens of money-laundering counts. He said he had considered starting a legal-awareness project for cybercrime defendants. Defence lawyers and academics with no stake in any of this make versions of the same argument.
It also collapses under his own testimony. His case rests on the premise that ransomware is a financial crime and should be sentenced like one, no worse than fraud. But he draws the line himself: attacks on hospitals, airports and critical infrastructure, he told me, carry the risk of loss of life and should be treated differently. Then, in the same conversation, he claims to have hit airports and entire cities, to have encrypted “critical American infrastructure,” and to have trained a student whose graduation exercise was encrypting a prison. By his own standard, those are not the financial crimes he wants leniency for. There is a real argument buried in what he says about how these cases get sentenced. He is the wrong man to be making it.
The child at the keyboard
The origin story is the part I keep returning to. He traces it to being eleven or twelve, small for his age, poor, wanting control, and finding it in a school IT room by capturing his classmates’ VK logins and reading their private messages, in his words, “understanding psychology of older kids and learning people through their private messages.” He says he went on to do the same to acquaintances for years.
It is an admission of surveillance of other children, and he offers it as the moment he found his talent rather than as anything to regret. The same word, control, runs through the rest of the interview: he describes controlling networks, controlling the people he trains, and, in the portion I left out, controlling the people closest to him. I have interviewed enough people in this ecosystem to say that the tooling is usually the least interesting thing about any of them. What he is good at, on his own description, is sitting quietly inside something he does not own, a corporate network or a classmate’s inbox, for as long as it takes to become worth money.
The offensive-AI claim
The one forward-looking thing he said is that associates are building what he calls HACK AI, using models and their own hardware to develop exploits for hard-to-exploit vulnerabilities, evade endpoint defences and automate the dull parts of intrusion. I cannot confirm it exists, and I have heard men in this scene call a group chat a research lab before. But the direction is the one every defender is already watching, and it is worth recording that an operator at this level now frames model-assisted offence as a project worth naming rather than a novelty. We have written separately about where AI meets this side of the industry, and this is a data point for that file, no more.
Where the interview stands
This interview runs in rounds, and this is the first of them. The remaining questions from the main set, on corporate security failures, where the industry is heading, what leaving this work looks like, and what he would say directly to the organisations he targets, have not yet been put to him, and neither has the third round I intend to build from the answers above. I have published the opening round now rather than holding it, because what he has already said stands on its own. When the later questions go to him and answers come back, they will run here, and I will say plainly what changed.
On giving him the platform
He engaged with this as an interview: he accepted the request, set his one condition, answered at length, asked me what was working and what was not, and told me explicitly that I could quote his reasoning about his name. He did not give me a separate, tidy yes to publication, and I would rather be able to point at one, so I am telling you that instead of implying it. I have treated his participation as consent to run the opening round under his alias while withholding what he asked me to withhold. If he later objects, I will say so here.
There is a fair objection to running any of this: it hands a wanted operator a platform and lets him perform grievance for an audience. I have weighed that against the alternative, which is that the public and the people who defend networks against men like him hear only the indictment and never the reasoning. He is already in the public record. Letting him explain, in his own flawed English, how he justifies attacking a hospital’s neighbours while asking to be sentenced like a fraudster, tells you more about how this industry sustains itself than a press release ever would. His victims did not get to choose whether to take part. He did, and he chose to talk. I have spent twenty years saying you cannot defend against this ecosystem while refusing to listen to the people inside it, and I am not going to start refusing now.
Notes and sources
- The alias in public reporting: Brian Krebs, “MySQL.com Sold for $3k, Serves Malware,” KrebsOnSecurity, 26 September 2011.
- DCIS is the Defense Criminal Investigative Service, the criminal investigative arm of the US Department of Defense Office of Inspector General.
- Earlier interviews in this series: the Bashe hack team on why it wants the coverage, and a representative of RTM Locker on the RaaS market.
- Related reading on Ransomnews: what double extortion actually is, tracking actors across rebrands, and the wider threat-group catalogue.
- Quotations are reproduced from the Tox correspondence with light trims for length, marked where made, and no rewording. Operational descriptions are kept at the level the subject volunteered and deliberately not expanded. The subject’s surname is withheld at his request; his identity claims, including the link to the 2011 alias, are his own and unverified.
This interview is part of the Ransomnews cybercrime desk’s work on the people behind the attacks. It is testimony, not endorsement, and every criminal claim in it is the subject’s own.
The Ransomnews Monthly
One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.
Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.
