Cybercrime

Russian Ransomware Operator Pleads Guilty in US

Evgenii Ptitsyn was extradited to the United States from South Korea in November 2024.

Hacker arrested

A 43-year-old Russian national has pleaded guilty in a US court to charges stemming from his role in the Phobos ransomware operation.

The man, Evgenii Ptitsyn, was arrested in South Korea in June 2024 and extradited to the United States in November of the same year.

The US Justice Department announced on Wednesday that Ptitsyn has now pleaded guilty to wire fraud conspiracy, for which he faces up to 20 years in prison. Sentencing is scheduled for July 15. 

According to authorities, Ptitsyn was involved in the Phobos scheme since at least November 2020, helping with the sale, distribution, and operation of the ransomware. 

Ptitsyn appears to have been part of the administration team, which offered malware and infrastructure that affiliates could use to target victims and obtain ransom payments. 

The Phobos operation emerged in 2019 and targeted more than 1,000 organizations worldwide, with cybercriminals believed to have obtained over $16 million in ransom payments.

Advertisement. Scroll to continue reading.

Authorities in the United States and Europe have taken significant action against the Phobos operation in recent years, announcing infrastructure takedowns and arrests.

The most recent arrest was announced last month. Police in Poland apprehended a 47-year-old man who appears to be suspected of being a Phobos affiliate. 

Related: LeakBase Cybercrime Forum Shut Down, Suspects Arrested

Related: Tycoon 2FA Phishing Platform Dismantled in Global Takedown

Related: Ukrainian Nefilim Ransomware Affiliate Extradited to US

Related: US Charges 31 More Defendants in Massive ATM Hacking Probe

Related Content

Cybercrime

The defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash.

Data Breaches

The company has notified the SEC that hackers accessed patient, employee, provider, business, and financial information.

Data Breaches

FulcrumSec says it stole over 80 GB of data from Manchester Airports Group and plans to leak it online.

Data Breaches

The Rhysida ransomware group has claimed the exfiltration of over 5TB of data, including personal information and credentials.

Ransomware

The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ.

Cybercrime

The pro-Russian hacker group Server Killers claimed responsibility for the attack.

IoT Security

Operation CameraSwarm targeted Dahua cameras across multiple countries, focusing on Russian and CIS telecom netblocks.

Artificial Intelligence

Atalanta's Argo product is now being used to prove the resilience of Viasat’s satellite communications network.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version