Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
The Danchev Interviews

sourcec0de interview: a ransomware operator on why he won’t stop

Dancho DanchevBy Dancho DanchevSeptember 17, 2026Updated:September 17, 2026No Comments17 Mins Read33 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Interview card headed sourcec0de, an active ransomware operator in the opening round of a long interview, with a Tox chat motif showing answered exchanges in green and questions still to be put to him as dim outlines
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

The two subjects before this one were both answering for an organisation. Alex C spoke for RTM Team and would not be drawn a step past that, and the Bashe crew answered me collectively, in one voice, having told me up front what they wanted out of the coverage. Either way what reached me was a position that had been settled somewhere before I asked. This time there was nobody standing behind the answers except the man giving them. He replied over Tox, in his own rough English, and spent most of the opening round explaining why he believes the law chasing him is more unjust than what he does with a keyboard. The later questions, and the round I want to build out of these answers, have not gone to him yet.

He calls himself sourcec0de. He is, by his own account, a Russian ransomware operator, thirty years old, under investigation by at least three United States agencies, and being treated for bone cancer. He answered the first eleven of my questions, acknowledged that everything he does is a crime, and then made an argument about why he does it anyway. I have published the argument with the record attached, because the argument is the point.

What I have not done is verify him. I cannot confirm that the person answering me on Tox is the person behind the alias in the reporting I cite below, that he carried out the attacks he describes, or that a single one of his operational claims is true. Read it as testimony from inside a criminal business, given by a man with every reason to manage how he comes across. I am not standing behind any of it.

Who sourcec0de is, on the public record

The alias is not new. In September 2011, Brian Krebs reported that administrative access to MySQL.com had been offered for sale in the underground for about $3,000, and that the seller used the handle sourcec0de. He pointed me at that report himself. It is the only part of his story that exists in public independent of him, and it only goes so far. It puts the alias in the MySQL.com episode. It does not put the man on my Tox behind the alias. He says he is. I cannot prove it.

By his telling, MySQL.com was an early job. He describes exploiting the site, taking the servers, and selling the access to someone who burned it on a browser-exploit kit, after which Krebs tied the episode to his post. He says he then worked under a second alias, g3tty, on a well-known exploit forum, hacked several Russian darknet markets, and specialised in Western shops and payment processors, selling card data and holding the proceeds in cryptocurrency early. His account of the arc is his own:

then got into ransomware somewhe in 2021, back then I already had connections with FSB and one guy from it suggested ransomware. Back in the day all I knew about ransomware was “that it is consumer ransomware, targeting folks for 200$ payouts”. Boy was I wrong. I got into corporate administration along the way, I hacked so many targets via proxyshell and other RCEs, like fortinet, etc. Entire cities, airports, billion-revenue corporations.

The claim that an FSB contact steered him into ransomware is the sort of thing that cannot be checked and should not be repeated as fact. I include it because he volunteered it, and because the relationship between Russian security services and Russian ransomware crews is a live question that this kind of testimony feeds without settling. Treat it as what he wanted me to hear.

He says the attention became mutual. He claims he learned, through notifications to his own email, that his data had been subpoenaed by the FBI, the Secret Service and DCIS. DCIS is the Defense Criminal Investigative Service, the criminal investigative arm of the US Department of Defense Inspector General, which would be an unusual agency to see on a fraud case and a less unusual one to see if a suspect had, as he puts it, “hack critical American infrastructure and encrypted it.” He offered his illness in the same breath:

so here I am, sick with cancer and still working to afford my treatment and/or leave money to my son. I’m 30 y.o (bone cancer targetting young folks unfortunately)

I have no way to confirm the diagnosis, the investigation, or the son. They are offered as mitigation, and a reader is entitled to weigh them as such while remembering that everything after the diagnosis is still a description of harm done to other people.

How the contact was made

I reached him the way I reach everyone in this series, over Tox, using contact details mined from three years of offline copies of cybercrime forums. I introduced myself, gave him a way to verify my Tox ID, and pointed him at two decades of published work so he could decide whether I was worth answering. He replied within a day, asked how I had found his Tox address, and said he had already thought about talking to Western press, Wired or BleepingComputer, for a book he says he is writing about the ransomware ecosystem. He had no offers on the table, he said, so he was open to mine.

He set a single condition before anything else. He would not name anyone he works with.

I will never reveal sensitive info about my friends or other people in this sphere, don’t ever ask or we won’t work. this is the only request from me

He made one request about himself, too. He gave me his first name and, privately, his surname, and asked that only the first name and the alias appear in print. His reasoning is worth quoting in full, because he told me I could, and because it is the clearest thing he said about how he thinks the machinery around him works:

its known to American special services investigating me, but public interview with my name and openly discussing crimes will kinda destroy “plausible deniability” Russian special forces have to not obey international arrest warrants. So there is that, my kind request is to use my nickname and my first name, but not last name.

I have honoured it. He is Yuriy and sourcec0de in this piece, and the surname stays out. I would have withheld it in any case, because I have no way of checking it against anything. He also mentioned, more than once, that he was between rounds of chemotherapy and would not always be online, which is worth keeping in mind against the pace of a staged interview like this one.

One note on language. He took my questions in English and answered in English, and the answers below are his, grammar and spelling included. I have trimmed for length where a single answer ran into unrelated territory, and marked where I did, but I have not reworded him. Leaving the mistakes in is deliberate. It is how you can tell this came back from one man over Tox and not from a crew settling on a line.

Establishing contact

Tox session · openingquestions sent 17 August 2026
Dancho Danchev

Who am I speaking to?

▮  sourcec0de

Yuriy [surname withheld at his request]. My kind request is to use my nickname and my first name, but not last name, which I only shared to you privately. More known under the alias sourcec0de. Then I was doing some hacking here and there, under the alias g3tty on exploit forum.

Dancho Danchev

Are you familiar with my research and achievements throughout the years?

▮  sourcec0de

No i am not aware of your work, I will familiarize myself with it out of respect and honest curiousity. Even though I believe the interview can be done without this.

answered 20 August, from the road to a chemotherapy clinic

The interview, so far

He answered the first eleven of my questions, nine of them substantive. The first one he took was how he started, and his answer reaches back to a school computer room.

Tox session · the interviewsame questions, sent 17 August 2026
Dancho Danchev

How did you get started in the cybercrime ecosystem?

// Free tool

How does your own site score?

Run the same forty passive checks against your own domain — TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

▮  sourcec0de

I started as a kid (11-12 years old), the main motivation was combo of three factors: a.) my own personality (desire for control and power), b.) my physical attributes (small height, weight, which makes me look unassuming), and c.) my background: poor family, single mother working as a school teacher.

my first hack was in IT classes in school: I put a traffic sniffer for routers. Back in the day VK social network was booming. So i hacked everyone from my school who authorized in vk from IT classes, been reading their messages, understanding psychology of older kids and learning people through their private messages.

Dancho Danchev

How would you describe yourself? A vendor of a service, an active threat actor, or a ransomware operator?

▮  sourcec0de

I am an active threat actor doing the work usually performed by the entire teams: I use CVEs to gain initial access, then I move laterally through the corporate network, analyze the network topology, escalate privileges, gain backups / virtualization access, then encrypting the network. I also personally requested development of private tools helping in the work.

Dancho Danchev

How did you get involved with computers?

▮  sourcec0de

my knowledge was mostly self-procured. I was studying from online courses that I couldn’t afford originally (so I downloaded their pirated version), I studied web tech and languages such as php/python, sql, linux administration and scripting. All the while actively hacking sites as a kid.

Dancho Danchev

How far-reaching is what you are currently doing?

▮  sourcec0de

I am currently doing the same thing since I got into ransomware, taking RCEs, scanning and encrypting the networks. Sometimes though I receive outsourced accesses from acquaintances who need my expertise in encrypting the network.

Dancho Danchev

What are your current projects and future plans?

▮  sourcec0de

I am also writing a book about myself and my “exploits”. I also was given couple of students to teach. One is already almost fully autonomous, after a month of severe everyday training he needed only a week of my intensive program to hack into prison and encrypt it, albeit in obscure country Aruba.

with my help my associates also curate couple other projects, like creating “HACK AI”, using models and our own hardware to weaponize artificial intelligence models for hacking purposes: creating exploits for “hard to exploit CVEs”, bypassing AV/EDR restrictions, scanning networks.

Dancho Danchev

Are you a pure opportunist, a businessman, or do you hold an ideological justification?

▮  sourcec0de

I have no delusions of grandeur about my position in the world: I do harm, there is no doubt. But I do it professionally, and yes, I do have not exactly justifications, but extenuating circumstances. All these circumstances, however, do not rob me of realization that all my crimes, nor rob me from responsibility of attacking western corporations, citizens and entire countries.

However, I do need to mention ideological distaste towards unjust legal system, the fact that financial crime is treated with condescension and mercy but cyber crimes sometimes prosecuted with intention to put for a lifetime the perpetrators. if they keep putting away young guys for this for a lifetime, I will never stop.

Dancho Danchev

How do you compartmentalise your operator life from your real-world life?

▮  sourcec0de

I don’t do that. All my acquaintances of significance know what I do, its not really treated as a big deal. cyber crime is treated like regular work in Russia. Most people who are not IT-savvy wouldn’t know the difference between cyber crime and cyber security gig. So before I was officially in FBI investigation, I was just saying I am cyber security researcher.

Dancho Danchev

What is the biggest misconception the public has about people in the ecosystem?

▮  sourcec0de

assuming it takes some cosmic world-class talent to be a hacker, or some naive perception of activity, like viewing it as magical stuff. I do not like my answer on this question, so I will either think more on it or maybe you can rephrase.

Dancho Danchev

Have you ever been scammed or ripped off by other actors?

▮  sourcec0de

No, I haven’t been scammed or ripped off. But I have seen it happening with people whose talents I respected and who weren’t “lame”, so this thing happening with people a lot. I am really controlling and mistrusting individual, that’s why I never have been betrayed. [answer continues into personal matters, omitted]

the opening two questions and the first nine of the main set; the later questions have not yet been put to him
“

I do harm, there is no doubt. But I do it professionally.

▮  sourcec0de

After the conversation

What checks out, and what does not

One thing corroborates, weakly. The sourcec0de alias really does appear in Krebs’s 2011 MySQL.com reporting, so the name has a documented history in a genuine incident. Everything else rests on his word. The FSB tip, the attacks on cities and airports, the students, the offensive-AI project, the subpoenas: none of it is verifiable from where I sit, and some of it is exactly the kind of claim an operator inflates to raise his own standing. DCIS is a real agency and it would make sense on a critical-infrastructure case, so at least that detail hangs together with the rest of what he told me. I still cannot show that any of it happened.

The argument he wants to make

His central claim is not technical, it is about justice, and he made it before I had asked a single question. He put it like this: that a repeat drug offender who commits a killing might serve fifteen or twenty years, while a young man with no record can face forty years or life for a run of ransomware attacks against businesses. He compared it to the way counterfeiting was once punished as a crime against the state, and argued that a single crypto payment, moved between wallets, can be stacked into dozens of money-laundering counts. He said he had considered starting a legal-awareness project for cybercrime defendants. Defence lawyers and academics with no stake in any of this make versions of the same argument.

It also collapses under his own testimony. His case rests on the premise that ransomware is a financial crime and should be sentenced like one, no worse than fraud. But he draws the line himself: attacks on hospitals, airports and critical infrastructure, he told me, carry the risk of loss of life and should be treated differently. Then, in the same conversation, he claims to have hit airports and entire cities, to have encrypted “critical American infrastructure,” and to have trained a student whose graduation exercise was encrypting a prison. By his own standard, those are not the financial crimes he wants leniency for. There is a real argument buried in what he says about how these cases get sentenced. He is the wrong man to be making it.

The child at the keyboard

The origin story is the part I keep returning to. He traces it to being eleven or twelve, small for his age, poor, wanting control, and finding it in a school IT room by capturing his classmates’ VK logins and reading their private messages, in his words, “understanding psychology of older kids and learning people through their private messages.” He says he went on to do the same to acquaintances for years.

It is an admission of surveillance of other children, and he offers it as the moment he found his talent rather than as anything to regret. The same word, control, runs through the rest of the interview: he describes controlling networks, controlling the people he trains, and, in the portion I left out, controlling the people closest to him. I have interviewed enough people in this ecosystem to say that the tooling is usually the least interesting thing about any of them. What he is good at, on his own description, is sitting quietly inside something he does not own, a corporate network or a classmate’s inbox, for as long as it takes to become worth money.

The offensive-AI claim

The one forward-looking thing he said is that associates are building what he calls HACK AI, using models and their own hardware to develop exploits for hard-to-exploit vulnerabilities, evade endpoint defences and automate the dull parts of intrusion. I cannot confirm it exists, and I have heard men in this scene call a group chat a research lab before. But the direction is the one every defender is already watching, and it is worth recording that an operator at this level now frames model-assisted offence as a project worth naming rather than a novelty. We have written separately about where AI meets this side of the industry, and this is a data point for that file, no more.

Where the interview stands

This interview runs in rounds, and this is the first of them. The remaining questions from the main set, on corporate security failures, where the industry is heading, what leaving this work looks like, and what he would say directly to the organisations he targets, have not yet been put to him, and neither has the third round I intend to build from the answers above. I have published the opening round now rather than holding it, because what he has already said stands on its own. When the later questions go to him and answers come back, they will run here, and I will say plainly what changed.

On giving him the platform

He engaged with this as an interview: he accepted the request, set his one condition, answered at length, asked me what was working and what was not, and told me explicitly that I could quote his reasoning about his name. He did not give me a separate, tidy yes to publication, and I would rather be able to point at one, so I am telling you that instead of implying it. I have treated his participation as consent to run the opening round under his alias while withholding what he asked me to withhold. If he later objects, I will say so here.

There is a fair objection to running any of this: it hands a wanted operator a platform and lets him perform grievance for an audience. I have weighed that against the alternative, which is that the public and the people who defend networks against men like him hear only the indictment and never the reasoning. He is already in the public record. Letting him explain, in his own flawed English, how he justifies attacking a hospital’s neighbours while asking to be sentenced like a fraudster, tells you more about how this industry sustains itself than a press release ever would. His victims did not get to choose whether to take part. He did, and he chose to talk. I have spent twenty years saying you cannot defend against this ecosystem while refusing to listen to the people inside it, and I am not going to start refusing now.

Notes and sources

  • The alias in public reporting: Brian Krebs, “MySQL.com Sold for $3k, Serves Malware,” KrebsOnSecurity, 26 September 2011.
  • DCIS is the Defense Criminal Investigative Service, the criminal investigative arm of the US Department of Defense Office of Inspector General.
  • Earlier interviews in this series: the Bashe hack team on why it wants the coverage, and a representative of RTM Locker on the RaaS market.
  • Related reading on Ransomnews: what double extortion actually is, tracking actors across rebrands, and the wider threat-group catalogue.
  • Quotations are reproduced from the Tox correspondence with light trims for length, marked where made, and no rewording. Operational descriptions are kept at the level the subject volunteered and deliberately not expanded. The subject’s surname is withheld at his request; his identity claims, including the link to the 2011 alias, are his own and unverified.

This interview is part of the Ransomnews cybercrime desk’s work on the people behind the attacks. It is testimony, not endorsement, and every criminal claim in it is the subject’s own.

The Ransomnews Monthly

One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous Article36,769 exposed AI endpoints, only 2% ask for a login
Next Article Exploit.in: inside a Russian hacker forum, 2005 to 2008
Dancho Danchev
  • LinkedIn

Dancho Danchev is a Bulgarian threat intelligence researcher who has spent more than two decades tracking cybercrime, malware campaigns, and the infrastructure behind the criminal underground. His research covers botnets, including Koobface, exploit kits, blackhat SEO, scareware, and large-scale domain abuse, with a focus on OSINT work that maps campaigns back to the operators running them. He has published through ZDNet Zero Day, Webroot, GroupSense, and WhoisXML API, and has run his own cybercrime research blog since the early 2000s.

Related Posts

Bashe interview: a ransomware group on why it wants the coverage

August 27, 2026

RTM Locker interview: a ransomware actor on the RaaS market

August 21, 2026

Comments are closed.

// The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

// Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

// Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

// Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,604 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.