Phobos ransomware admin pleads guilty to wire fraud conspiracy
好的,我现在需要帮用户总结一篇文章的内容,控制在100个字以内。用户的要求很明确,不需要特定的开头,直接写文章描述即可。 首先,我通读了整篇文章。文章主要讲的是一个俄罗斯人Evgenii Ptitsyn因参与Phobos勒索软件活动而认罪。Phobos是一个勒索软件即服务(RaaS)的长期运行项目,与Crysis勒索软件家族有关。Ptitsyn负责管理Phobos的销售、分发和日常运营,通过暗网网站和犯罪论坛推广。该团伙从全球1000多个实体中获得了超过3900万美元的赎金。 接下来,我需要提取关键信息:认罪的俄罗斯人、Phobos勒索软件、涉及金额、受害者数量以及Ptitsyn的角色。同时,文章还提到Operation Aether国际行动打击了该团伙。 现在,我要把这些信息浓缩到100字以内。确保涵盖认罪、Phobos的影响、金额、受害者类型以及Ptitsyn的角色和判决情况。 最后,组织语言,使其简洁明了。避免使用复杂的句子结构,确保信息准确且符合字数限制。 </think> 一名俄罗斯男子承认参与Phobos勒索软件活动,该组织通过暗网销售加密工具,在全球攻击学校、医院等机构并索要赎金。该男子被指控管理勒索软件的分发和运营,并从中获利超过3900万美元。他面临最高20年监禁。 2026-3-5 08:47:51 Author: www.bleepingcomputer.com(查看原文) 阅读量:3 收藏

Phobos

A Russian national pleaded guilty to a wire fraud conspiracy charge related to his role in administering the Phobos ransomware operation, which breached hundreds of victims worldwide.

Phobos is a long-running ransomware-as-a-service (RaaS) operation linked to the Crysis ransomware family. Phobos has been widely distributed through many affiliates, accounting for roughly 11% of all submissions to the ID Ransomware service between May 2024 and November 2024.

The U.S. Department of Justice says the ransomware gang has collected ransom payments worth more than $39 million million from over 1,000 public and private entities worldwide.

43-year-old Evgenii Ptitsyn was extradited from South Korea in November 2024 and was charged in the United Statesfor overseeing the sale, distribution, and day-to-day operation of Phobos ransomware.

According to court documents, Ptitsyn and his accomplices began running the cybercrime operation no later than November 2020, selling access to the Phobos ransomware to criminal affiliates through a darknet website and advertising on criminal forums under the "derxan" and "zimmermanx" handles.

The affiliates broke into targets' networks (including schools, hospitals, and government agencies), often using stolen credentials, exfiltrated files, and encrypted sensitive data before demanding payment. They also threatened victims who refused to pay the ransoms via email and phone calls with leaking their stolen data online and sending it to customers.

Affiliates paid a per-deployment fee to Ptitsyn in exchange for a decryption key, and Ptitsyn collected a cut of ransom payments made by victims. From December 2021 to April 2024, all decryption key fees were transferred from an affiliate cryptocurrency wallet to a single Phobos admin cryptocurrency wallet under Ptitsyn's control.

"After a successful Phobos ransomware attack, affiliates paid approximately $300 to the Phobos administrators for a decryption key to regain access to the encrypted files," the indictment reads. "Each deployment of Phobos ransomware was assigned a unique alphanumeric string in order to match it to the corresponding decryption key, and each affiliate was directed to pay the decryption key fee to a cryptocurrency wallet unique to that affiliate."

Ptitsyn has been scheduled for sentencing on July 15 and is now facing up to 20 years following his guilty plea to wire fraud conspiracy.

Operation Aether targeting Phobos ransomware

Earlier this year, Polish police detained a 47-year-old man suspected of ties to the Phobos ransomware, seizing computers and mobile phones containing stolen credentials, credit card numbers, and server access data, as part of "Operation Aether," an Europol-coordinated international effort targeting the Phobos ransomware gang.

Over the years, Operation Aether went after Phobos-linked individuals at multiple levels of the operation, including backend infrastructure operators and ransomware affiliates involved in network intrusions and data encryption.

Other key results of this operation include a massive disruption in February 2025, when police detained two suspected affiliates and seized 27 servers, and the arrest of another affiliate in Italy in 2023.

"As a result of this operation, law enforcement was also able to warn more than 400 companies worldwide of ongoing or imminent ransomware attacks," Europol noted in February 2025. "This complex international operation, supported by Europol and Eurojust, involved law enforcement agencies from 14 countries."

tines

Red Report 2026: Why Ransomware Encryption Dropped 38%

Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.


文章来源: https://www.bleepingcomputer.com/news/security/phobos-ransomware-admin-pleads-guilty-to-wire-fraud-conspiracy/
如有侵权请联系:admin#unsafe.sh