Guilty Plea of Yanluowang Ransomware Initial Access Broker
Aleksei Olegovich Volkov, a Russian national, pleaded guilty in the United States to charges related to his role as an initial access broker (IAB) for the Yanluowang ransomware group. Volkov provided access to at least seven U.S. organizations between July 2021 and November 2022, enabling the deployment of ransomware that resulted in ransom demands ranging from $300,000 to $15 million. He received a percentage of the ransom payments, including $94,259 from a $500,000 ransom and $162,220 from a $1 million ransom, and was ordered to pay nearly $9.2 million in restitution to affected organizations. Volkov's activities were uncovered through digital forensics, including chat logs, cryptocurrency records, and social media accounts, and he was extradited to the U.S. after being apprehended in Rome.
The indictment and plea agreement detail Volkov's collaboration with co-conspirators, his use of aliases such as "chubaka.kor," and his involvement in negotiating ransom payments and providing network credentials to the Yanluowang group. The attacks affected a range of U.S. businesses, including engineering firms, banks, and telecommunications providers, with some victims able to restore from backups and avoid ransom payments. Volkov faces up to 53 years in prison for charges including access device fraud, aggravated identity theft, and conspiracy to commit money laundering and computer fraud.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
4 events from the most recent confirmed update back to the earliest known activity.
Volkov pleads guilty in U.S. ransomware access-broker case
On or before November 10, 2025, Volkov pleaded guilty in the United States to multiple charges tied to acting as an initial access broker for Yanluowang ransomware attacks. Court filings said he profited from ransom payments, and he was ordered to pay more than $9.1 million in restitution to six victims; sentencing had not yet been set.
Volkov extradited to the United States
After his arrest in Italy, Volkov was extradited to the U.S. in 2024 to face prosecution over his alleged role in facilitating Yanluowang ransomware intrusions. U.S. investigators had tied him to the operation using iCloud data, crypto exchange records, social media accounts, and recovered server evidence.
Volkov arrested in Italy
Italian authorities arrested Volkov in January 2024 in connection with his alleged role as an initial access broker supporting Yanluowang ransomware attacks. The arrest preceded his transfer to the United States to face fraud, identity, and money-laundering-related charges.
Volkov brokers access for Yanluowang attacks on U.S. companies
From July 2021 through November 2022, Aleksey Olegovich Volkov allegedly breached corporate networks and sold stolen employee credentials and other access to the Yanluowang ransomware group. Prosecutors say this enabled attacks on at least seven or eight U.S. organizations, with ransom demands ranging from $300,000 to $15 million.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
5 references tracked. Mallory keeps watching after this page renders.
Russian hacker admits helping Yanluowang ransomware infect companies
bitdefender.com
Open sourceRussian broker pleads guilty to profiting from Yanluowang ransomware attacks
go.theregister.com
Open sourceYanluowang initial access broker pleaded guilty to ransomware attacks
bleepingcomputer.com
Open sourceYanluowang initial access broker to plead guilty to ransomware attacks
bleepingcomputer.com
Open sourceYanluowang ransomware gang’s IAB admits guilt
scworld.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.

