Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
enforcement-actionransomware-group-operationcybercrime-service-ecosysteminitial-access-method

Guilty Plea of Yanluowang Ransomware Initial Access Broker

Updated 3mo agoFirst seen Nov 10, 20255 sources

Aleksei Olegovich Volkov, a Russian national, pleaded guilty in the United States to charges related to his role as an initial access broker (IAB) for the Yanluowang ransomware group. Volkov provided access to at least seven U.S. organizations between July 2021 and November 2022, enabling the deployment of ransomware that resulted in ransom demands ranging from $300,000 to $15 million. He received a percentage of the ransom payments, including $94,259 from a $500,000 ransom and $162,220 from a $1 million ransom, and was ordered to pay nearly $9.2 million in restitution to affected organizations. Volkov's activities were uncovered through digital forensics, including chat logs, cryptocurrency records, and social media accounts, and he was extradited to the U.S. after being apprehended in Rome.

The indictment and plea agreement detail Volkov's collaboration with co-conspirators, his use of aliases such as "chubaka.kor," and his involvement in negotiating ransom payments and providing network credentials to the Yanluowang group. The attacks affected a range of U.S. businesses, including engineering firms, banks, and telecommunications providers, with some victims able to restore from backups and avoid ransom payments. Volkov faces up to 53 years in prison for charges including access device fraud, aggravated identity theft, and conspiracy to commit money laundering and computer fraud.

Share:
Guilty Plea of Yanluowang Ransomware Initial Access Broker
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Nov 10, 20257mo ago

Volkov pleads guilty in U.S. ransomware access-broker case

On or before November 10, 2025, Volkov pleaded guilty in the United States to multiple charges tied to acting as an initial access broker for Yanluowang ransomware attacks. Court filings said he profited from ransom payments, and he was ordered to pay more than $9.1 million in restitution to six victims; sentencing had not yet been set.

Jan 1, 20242y ago

Volkov extradited to the United States

After his arrest in Italy, Volkov was extradited to the U.S. in 2024 to face prosecution over his alleged role in facilitating Yanluowang ransomware intrusions. U.S. investigators had tied him to the operation using iCloud data, crypto exchange records, social media accounts, and recovered server evidence.

Volkov arrested in Italy

Italian authorities arrested Volkov in January 2024 in connection with his alleged role as an initial access broker supporting Yanluowang ransomware attacks. The arrest preceded his transfer to the United States to face fraud, identity, and money-laundering-related charges.

Jul 1, 20215y ago

Volkov brokers access for Yanluowang attacks on U.S. companies

From July 2021 through November 2022, Aleksey Olegovich Volkov allegedly breached corporate networks and sold stolen employee credentials and other access to the Yanluowang ransomware group. Prosecutors say this enabled attacks on at least seven or eight U.S. organizations, with ransom demands ranging from $300,000 to $15 million.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

18 LINKEDOpen in app
Threat actors
2 linked
Affected products
2 linked
IcloudVisual Studio Code
Organizations
10 linked
AppleCisco SystemsBoxXThe RegisterAsahi Group HoldingsProtonSonicwallGoogleMassachusetts Institute of Technology Sloan School of Management
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.