Formation of a foreign criminal organization, computer intrusion, and large-scale extortion. 🕸️ The Trickbot & Wizard Spider Connection
According to investigations by the German Federal Criminal Police Office (BKA) , the group's activities have resulted in financial losses totaling hundreds of millions of euros. Kovalskii’s alleged technical contributions were vital to the group’s ability to deploy devastating ransomware families like , Conti , and Diavol . Updated Legal Status and "Operation Endgame"
The criminal organization Kovalskii is associated with has reportedly caused extensive global damage.
Confirmed sightings or verification of his physical location. aleksei valerevich kovalskii updated
The operation successfully dismantled thousands of server nodes worldwide, froze illicit crypto addresses, and seized internal command-and-control logs. These newly acquired data logs gave investigators an inside look into the identities of developers behind the keyboards. As a direct consequence, the BKA and INTERPOL updated their active wanted registries to include definitive identification details for Kovalskii and his immediate operational ring. Current Charges and Legal Standing
The Hunt for "Neo": Aleksei Valerevich Kovalskii Updated , an elite cybercriminal operating under the notorious digital aliases "neo" and "wild" , remains a central target of global law enforcement following a massive international crackdown on ransomware syndicates . Born on August 16, 1991, in Krasnoyarsk, Russia, Kovalskii evolved from a localized hacker into a prominent operative within the "Trickbot" group (also tracked globally as "Wizard Spider" ), a hyper-organized cyber syndicate responsible for extorting hundreds of millions of dollars from victims worldwide.
Tracking any movements outside of Russia that could lead to his apprehension. Updated Legal Status and "Operation Endgame" The criminal
Analyze how restrict cybercriminal networks.
Initial search results and news reports from the same period identified a different name in connection to the leadership of the Trickbot group: . German authorities accused Kovalev, also known by the alias “Stern,” of being the founder of the Trickbot gang.
The syndicate deployed a devastating array of malware designed to breach systems, siphon intelligence, and paralyze operations. Trickbot's weapon pipeline includes: These newly acquired data logs gave investigators an
. Published data confirms he is a Russian national sought by law enforcement agencies, with Germany actively involved in the international arrest warrant tracking. As global cross-border law enforcement collaboration tightens, tracking systems have recently processed updated profiles regarding his personal data and legal status.
Kovalskii is targeted for his participation in a foreign criminal organization and for providing "essential contribution" to global cyberattacks. The investigations are led by the German Federal Criminal Police Office (BKA) and the Frankfurt General Prosecutor's Office (ZIT), specializing in combating cybercrime.
As of mid-2026, the international law enforcement landscape remains heavily focused on dismantling organized ransomware and malware operations, with —also known as or —remaining a key target in the ongoing crackdown on high-level cybercriminals. As part of the multi-jurisdictional “Operation Endgame,” European and international authorities continue to pursue Kovalskii for his alleged critical role in developing and maintaining tools used in global cyberattacks.