INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Phobos Ransomware admin faces up to 20 years

| 2026-03-05 19:12 CRITICAL LOW
Executive Summary AI-generated
The Phobos ransomware operation, which targeted over 1,000 public and private entities in the United States and worldwide, extorting more than $16 million in ransom payments. Russian national Evgenii Ptitsyn pleaded guilty to wire fraud conspiracy for his role in the scheme, facing up to 20 years in prison after helping sell and operate the ransomware platform used by affiliates to attack victims.
Technical Mitigations AI-generated
* Use of secure communication channels: The use of encrypted messaging and secure communication channels, such as Signal or WhatsApp, can help protect against Phobos ransomware attacks by ensuring that sensitive information is not intercepted or accessed by unauthorized parties. * Implementing robust security measures: Organizations should implement robust security measures, such as firewalls, intrusion detection systems, and antivirus software, to detect and prevent Phobos ransomware attacks. Regularly updating software and patches can also help protect against known vulnerabilities. * Using secure payment processing: Payment processors and online marketplaces should use secure payment processing methods, such as tokenization or encryption of sensitive information, to minimize the risk of Phobos ransomware attacks on customers' financial data. * Implementing incident response plans: Organizations should have incident response plans in place to quickly respond to Phobos ransomware attacks. This includes having a clear understanding of how to contain and mitigate the attack, as well as having necessary resources and personnel available to do so. * Regularly updating software and systems: Regularly updating software and systems can help prevent exploitation of known vulnerabilities that could be used by Phobos ransomware attackers. It is also essential to have a clear understanding of how to patch vulnerabilities quickly in the event of an attack.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation AetherOperation Aether
Target & Sectors
NORTH_AMERICA NORTH_AMERICA governmentgovernment
Incident Timeline
November 2020
Evgenii Ptitsyn and others used a ransomware-as-a-service model to extort victims by selling decryption keys for Phobos Ransomware on darknet forums.
tactic Ransomware
organisation affiliates
May 2024
Phobos ransomware was used to target users between May 2024 and November 2024.
tactic Ransomware
general_metric 11 %
November 2024
Evgenii Ptitsyn was charged in the United States with overseeing Phobos ransomware, which had been widely distributed through many affiliates.
tactic Ransomware
target_region Korea, Republic of
target_region United States
organisation Evgenii Ptitsyn
general_metric 11 %
February 2025
The 47-year-old man was arrested in Poland suspected of involvement in the Phobos ransomware operation and linked to Europol's Operation Aether, which targeted the group.
attribution Italy
infrastructure 27 servers
tactic Ransomware
organisation Europol
general_metric 400 companies
target_region Russian Federation
organisation the U.S. Justice Department
organisation Operation Aether
organisation the Central Bureau for Combating Cybercrime
organisation IP
organisation the District Prosecutor’s Office
organisation SecurityAffairs
December 2021 to April 2024
Ransomware affiliates transferred decryption key fees from unique wallets to a single wallet controlled by Phobos admin.
tactic Ransomware
2026-03-05
Evgenii Ptitsyn pleaded guilty in the US to wire fraud conspiracy for his role in administering Phobos ransomware.
organisation Phobos
organisation The U.S. Department of Justice
financial $39 Stolen / Extorted Funds
data_breach 2020 November
organisation affiliates
financial $300 affiliates
organisation DoJ
financial $16 States
organisation Europol
organisation IP
organisation the District Prosecutor’s Office
organisation Central Bureau of Cybercrime Control
organisation CBZC
organisation The Red Report 2026
July 15
Phobos ransomware affiliates are facing up to 20 years in prison after being sentenced for their roles in a wire fraud conspiracy.
tactic Ransomware
2046-02-28
Evgenii Ptitsyn pleaded guilty in the U.S. for his role in Phobos ransomware operation and faces up to 20 years in prison.
target_region Russian Federation
organisation Ransomware
organisation Evgenii Ptitsyn
general_metric 43 guilty plea Russian national Evgenii Ptitsyn
Tactical Metrics
Metrics
infrastructure
27
Servers
Metrics
financial
39,000,000
Stolen / Extorted Funds
Metrics
data_breach
2,020
November
Metrics
financial
300
Affiliates
Metrics
financial
16,000,000
States
Intelligence Sources
BleepingComputer 2026-03-05
Security Affairs 2026-03-05