Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Russian Ransomware Operator Pleads Guilty in US

Evgenii Ptitsyn was extradited to the United States from South Korea in November 2024.

Hacker arrested

A 43-year-old Russian national has pleaded guilty in a US court to charges stemming from his role in the Phobos ransomware operation.

The man, Evgenii Ptitsyn, was arrested in South Korea in June 2024 and extradited to the United States in November of the same year.

The US Justice Department announced on Wednesday that Ptitsyn has now pleaded guilty to wire fraud conspiracy, for which he faces up to 20 years in prison. Sentencing is scheduled for July 15. 

According to authorities, Ptitsyn was involved in the Phobos scheme since at least November 2020, helping with the sale, distribution, and operation of the ransomware. 

Ptitsyn appears to have been part of the administration team, which offered malware and infrastructure that affiliates could use to target victims and obtain ransom payments. 

The Phobos operation emerged in 2019 and targeted more than 1,000 organizations worldwide, with cybercriminals believed to have obtained over $16 million in ransom payments.

Advertisement. Scroll to continue reading.

Authorities in the United States and Europe have taken significant action against the Phobos operation in recent years, announcing infrastructure takedowns and arrests.

The most recent arrest was announced last month. Police in Poland apprehended a 47-year-old man who appears to be suspected of being a Phobos affiliate. 

Related: LeakBase Cybercrime Forum Shut Down, Suspects Arrested

Related: Tycoon 2FA Phishing Platform Dismantled in Global Takedown

Related: Ukrainian Nefilim Ransomware Affiliate Extradited to US

Related: US Charges 31 More Defendants in Massive ATM Hacking Probe

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Rapid7 announced that Wael Mohamed will assume the role of Chief Executive Officer, replacing current Chief Executive Officer Corey Thomas, who will become Executive Chairman of the Board.

Anurag Jain has been appointed Senior Vice President of Engineering at CodeHunter.

CTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.