Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationenforcement-actioncybercrime-service-ecosystemcredential-access-method

Poland Arrests Suspected Phobos Ransomware Affiliate in Europol Operation Aether

Updated 3mo agoFirst seen Feb 17, 20268 sources

Polish law enforcement arrested a 47-year-old man in the Małopolska/Lesser Poland region on suspicion of involvement with the Phobos ransomware operation as part of Europol-coordinated Operation Aether targeting Phobos-linked infrastructure and affiliates. During a search of the suspect’s residence, Poland’s Central Bureau/Central Office for Combating Cybercrime (CBZC) seized devices and data investigators said could enable unauthorized access and ransomware activity, including stolen credentials, passwords, credit card numbers, and server IP/access data.

Authorities said technical analysis indicated the seized materials could be used to breach electronic security and support “various attacks, including ransomware,” and alleged the suspect used encrypted messaging to communicate with the Phobos criminal group. Reporting also noted the seizure of a laptop and multiple smartphones, and that the suspect was charged with offenses related to creating/acquiring/sharing tools or data used to unlawfully obtain information and facilitate unauthorized system access; if convicted, he faces up to five years in prison. Operation Aether reporting additionally linked the enforcement activity to efforts against 8Base, described as a ransomware group believed to be connected to Phobos.

Share:
Poland Arrests Suspected Phobos Ransomware Affiliate in Europol Operation Aether
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Feb 17, 20264mo ago

Investigators seize devices and cybercrime data in the Poland raid

During the raid, police seized a laptop or computer, multiple smartphones, payment cards, and other items, and reported finding stolen credentials, passwords, credit card numbers, server IP addresses, and related access data. Investigators said the materials could facilitate unauthorized access and ransomware attacks.

Polish police arrest and charge alleged Phobos affiliate

Poland's Central Bureau of Cybercrime Control arrested a 47-year-old man in the Małopolska region on suspicion of involvement with the Phobos ransomware operation. Authorities said he used encrypted messaging to communicate with the group and charged him with creating, obtaining, and sharing tools used for illegal access to IT systems.

Feb 1, 20251y ago

Europol-led Operation Aether identifies a Polish Phobos suspect

A Europol-led multinational operation conducted in February 2025, referred to in reporting as Operation Aether, identified a suspect in Poland allegedly tied to the Phobos ransomware ecosystem. The operation targeted Phobos operators, affiliates, and infrastructure internationally.

Nov 1, 20242y ago

Alleged Phobos administrator Evgenii Ptitsyn is extradited to the US

In November 2024, alleged Phobos developer and administrator Evgenii Ptitsyn was extradited from South Korea to the United States to face cybercrime charges tied to Phobos development and operations. Reporting says Phobos-linked activity declined after his extradition.

Feb 1, 20242y ago

US authorities warn Phobos is hitting critical infrastructure

In February 2024, U.S. authorities warned that Phobos ransomware was affecting U.S. state, local, tribal, and territorial governments and other critical infrastructure organizations. The warning highlighted the growing operational impact of the ransomware-as-a-service group.

Jun 1, 20233y ago

8Base ransomware activity increases as a Phobos-linked spinoff

The 8Base ransomware group, described as linked to the Phobos ecosystem, increased its activity in summer 2023 and claimed several high-profile victims. Later reporting connected 8Base to broader law-enforcement actions targeting Phobos infrastructure and affiliates.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

12 LINKEDOpen in app
Threat actors
2 linked
Malware
3 linked
Organizations
7 linked
BleepingComputerCoinbaseMeta PlatformsXMastodonSecurity AffairsCanada Goose
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.