Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationenforcement-actioncybercrime-service-ecosystemhealthcare-sector-threat

Phobos Ransomware Administrator Evgenii Ptitsyn Pleads Guilty in U.S. Case

Updated 3mo agoFirst seen Mar 5, 20264 sources

U.S. prosecutors said Evgenii Ptitsyn, a 43-year-old Russian national described as an administrator/leader behind the Phobos ransomware operation, pleaded guilty to wire fraud conspiracy tied to a global ransomware-and-extortion scheme. Court filings and DOJ statements cited in reporting say Phobos and its affiliates victimized more than 1,000 organizations worldwide and extorted over $39 million, with victims including U.S. healthcare providers, hospitals, educational institutions, and other essential services. Ptitsyn was arrested in South Korea and later extradited to the United States; he faces a maximum of 20 years in prison.

Authorities described Phobos as an affiliate-driven operation in which administrators developed and distributed the ransomware, coordinated sales via a darknet site, and advertised services on criminal forums/messaging platforms, while affiliates typically gained access to victim networks—often using stolen credentials—to steal and encrypt data and then demand payment for decryption. Reporting also described a fee/revenue model in which affiliates paid administrators for unique decryption keys and administrators took a cut of proceeds; Ptitsyn agreed to forfeit $1.77 million and pay at least $39.3 million in restitution. Additional context in coverage linked Phobos to related activity (including the 8Base strain) and noted prior law-enforcement actions against other alleged members, as well as the release of a free Phobos decryption tool by Japanese authorities.

Share:
Phobos Ransomware Administrator Evgenii Ptitsyn Pleads Guilty in U.S. Case
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Jul 15, 2026just now

Sentencing scheduled for July 15

Following the guilty plea, the court scheduled Ptitsyn's sentencing for July 15, where he faces a maximum sentence of 20 years in prison.

Mar 4, 20264mo ago

Plea deal includes forfeiture and restitution terms

Under the plea agreement, prosecutors dropped several charges, while Ptitsyn agreed to forfeit about $1.77 million and pay at least $39.3 million in restitution.

Ptitsyn pleads guilty to wire fraud conspiracy

In U.S. federal court, Ptitsyn pleaded guilty to wire fraud conspiracy for his role in administering the Phobos ransomware scheme. Prosecutors said the operation used affiliates, stolen credentials, darknet infrastructure, and cryptocurrency payments to extort victims.

Nov 1, 20242y ago

Ptitsyn extradited from South Korea to the U.S.

After his arrest, Ptitsyn was extradited from South Korea to the United States in November 2024, according to most reports, to face federal charges related to Phobos.

May 1, 20242y ago

South Korea arrests Evgenii Ptitsyn

Ptitsyn was arrested in South Korea in May 2024 as part of the international law-enforcement case targeting the Phobos ransomware operation.

Jan 1, 20233y ago

California school system pays $300,000 ransom

One disclosed victim example was a California public school system that paid a $300,000 ransom in 2023 following a Phobos attack.

Jan 1, 20224y ago

Phobos extorts over 1,000 victims worldwide

Authorities said Phobos and its affiliates went on to compromise more than 1,000 organizations globally, including many U.S. healthcare, education, and essential-service entities, collecting more than $39 million in ransom payments.

Ptitsyn takes leadership role in Phobos

Court records cited by multiple reports say Evgenii Ptitsyn assumed a leadership role in the Phobos ransomware operation in January 2022, overseeing distribution and affiliate coordination.

Nov 1, 20206y ago

Phobos ransomware activity begins

Prosecutors said Phobos ransomware activity began by November 2020, with the operation later growing into a global affiliate-based extortion scheme.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

3 LINKEDOpen in app
Threat actors
1 linked
Malware
1 linked
Organizations
1 linked
CyberScoop
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Phobos Ransomware Administrator Evgenii Ptitsyn Pleads Guilty in U.S. Case | Mallory