Polish cybercrime Police arrest man linked to Phobos ransomware operation
好的,我现在需要帮用户总结这篇文章的内容,控制在100字以内。首先,我得通读全文,抓住关键信息。 文章主要讲波兰警方逮捕了一名47岁的男子,他涉嫌参与Phobos勒索软件活动。他们从他的设备中找到了登录信息、密码、信用卡数据和服务器IP地址,这些数据可以用来发动网络攻击,包括勒索软件。此外,他还使用加密通讯与Phobos犯罪集团联系。波兰当局是在Operation Aether行动中逮捕他的,这个行动由欧洲刑警组织协调,针对Phobos的运营商、附属机构和基础设施。 接下来,我需要把这些要点浓缩成一句话。重点包括:波兰警方逮捕一名男子,涉及Phobos勒索软件,发现非法数据,并与该集团联系。同时提到这是Operation Aether的一部分。 现在我要确保语言简洁明了,不超过100字。可能的结构是:波兰警方逮捕一名男子,涉嫌参与Phobos勒索软件活动,并发现其设备中的非法数据及与犯罪集团的联系。 最后检查字数是否符合要求,并确保信息准确无误。 </think> 波兰警方逮捕一名47岁男子,怀疑其参与Phobos勒索软件活动,并在其设备中发现大量非法数据。该男子涉嫌与Phobos犯罪集团联系,并被指控开发和分发用于非法访问计算机系统的工具。此次逮捕是欧洲刑警组织协调的Operation Aether行动的一部分。 2026-2-17 15:16:11 Author: securityaffairs.com(查看原文) 阅读量:1 收藏

Polish cybercrime Police arrest man linked to Phobos ransomware operation

Pierluigi Paganini February 17, 2026

Officers from Poland’s Central Bureau of Cybercrime Control (CBZC) police arrested a 47-year-old man linked to the Phobos ransomware operation.

Polish authorities arrested a 47-year-old man suspected of involvement in cybercrime and linked him to the Phobos ransomware operation. Police said they discovered evidence of illegal activities on his seized devices.

“Officers from the Central Bureau for Combating Cybercrime detained a 47-year-old man suspected of creating, acquiring, and sharing computer programs used to unlawfully obtain information stored in computer systems.” reads the press release published by Poland’s Central Bureau of Cybercrime Control (CBZC) police. “Officers secured files on the man’s computer containing digital data, such as logins, passwords, credit card numbers, and server IP addresses. This data could have been used to launch various attacks, including ransomware. Furthermore, the 47-year-old used encrypted messaging to contact the Phobos criminal group, known for its ransomware attacks.”

In a joint operation by cybercrime units in Katowice and Kielce, Polish authorities arrested the man in the Małopolska region over suspected links to the Phobos group. Investigators seized computers and mobile phones containing logins, passwords, credit card data, and server IP addresses that could be used to breach electronic systems and launch ransomware attacks.

Evidence also showed he used encrypted messaging to communicate with members of the criminal network. He has been charged with creating and distributing tools for unlawful access to computer systems, an offense punishable by up to five years in prison. The case is overseen by the District Prosecutor’s Office in Gliwice. The arrest was part of Operation Aether, coordinated by Europol, which has targeted Phobos operators, affiliates, and infrastructure worldwide.

Phobos is an organized cybercrime group operating a ransomware-as-a-service (RaaS) model, providing its malware to affiliates who carry out attacks and share the profits. The group has targeted more than 1,000 victims worldwide, including U.S. public schools, healthcare providers, nonprofit organizations, government bodies, and private firms, even a contractor linked to the U.S. Department of Defense. According to the U.S. Department of Justice, ransom demands tied to Phobos exceeded $16 million. While the average demand was around $54,000, amounts varied widely. Exact earnings remain uncertain due to cryptocurrency payments and darknet activity.

In November 2024, Russian Phobos ransomware operator Evgenii Ptitsyn, suspected of playing a key role in the ransomware operations, was extradited from South Korea to the US to face cybercrime charges.

The Russian national was allegedly involved in the development, sale, distribution, and operations of the ransomware.

Evgenii Ptitsyn and others allegedly ran an international hacking scheme since November 2020, deploying Phobos ransomware to extort victims. Ptitsyn reportedly sold the ransomware on darknet forums under aliases like “derxan” and “zimmermanx,” enabling other criminals to encrypt data and demand ransom.

Ptitsyn and his conspirators used a ransomware-as-a-service (RaaS) model to distribute their malware to a network of affiliates. Affiliates paid fees to administrators like Ptitsyn for decryption keys, with payments routed via unique cryptocurrency wallets from 2021–2024.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, ransomware)




文章来源: https://securityaffairs.com/188128/cyber-crime/polish-cybercrime-police-arrest-man-linked-to-phobos-ransomware-operation.html
如有侵权请联系:admin#unsafe.sh