Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
enforcement-actionransomware-group-operationcybercrime-service-ecosysteminitial-access-method

Initial access broker Aleksei Volkov sentenced for enabling Yanluowang ransomware attacks

Updated 3mo agoFirst seen Mar 24, 202612 sources

A U.S. federal court sentenced Russian national Aleksei Volkov, 26, to 81 months in prison for acting as an initial access broker who helped major cybercrime groups, including the Yanluowang ransomware operation, compromise U.S. companies and other organizations. Prosecutors said Volkov gained unauthorized access to victim networks and sold that access to ransomware operators, who then deployed malware, encrypted systems, stole data, and extorted victims through cryptocurrency ransom demands.

The U.S. Department of Justice said the campaign caused more than $9 million in actual losses and more than $24 million in intended losses. Volkov was indicted in Indiana and Pennsylvania, arrested in Rome, extradited from Italy to the United States, and later pleaded guilty after the cases were consolidated. As part of the plea, he admitted hacking victim networks, stealing data, helping co-conspirators deploy ransomware, and sharing in ransom proceeds; he was also ordered to pay at least $9,167,198.19 in restitution and forfeit equipment used in the crimes.

Share:
Initial access broker Aleksei Volkov sentenced for enabling Yanluowang ransomware attacks
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Mar 24, 20263mo ago

U.S. charges Angelo Martino in BlackCat ransomware extortion case

U.S. prosecutors charged Angelo Martino as a third negotiator tied to BlackCat/ALPHV ransomware attacks, alleging he helped pressure at least 10 victims into paying higher ransoms while working for DigitalMint. Authorities also seized nearly $9.2 million in cryptocurrency and other assets connected to the case.

U.S. Sentences Russian Hacker to 6.75 Years for Role in $9M Ransomware Damage
May 8, 20233y ago

U.S. court sentences Volkov to 81 months in prison

The Southern District of Indiana sentenced Volkov to 81 months in prison for assisting major cybercrime groups, including the Yanluowang ransomware gang. He was also ordered to pay at least $9,167,198.19 in restitution and forfeit equipment used in the crimes.

Volkov pleads guilty in consolidated U.S. cybercrime case

Volkov pleaded guilty after the Indiana and Pennsylvania cases were consolidated. In his plea, he admitted to hacking victim networks, stealing data, enabling ransomware deployment through co-conspirators, and sharing in ransom proceeds.

Volkov is arrested in Rome and extradited from Italy to the United States

After being charged, Volkov was arrested in Rome and transferred from Italy to the United States to face prosecution. The extradition enabled the U.S. cases against him to proceed.

Volkov is indicted in Indiana and Pennsylvania cybercrime cases

U.S. prosecutors charged Volkov in separate cases in the Southern District of Indiana and the Eastern District of Pennsylvania for his role in intrusions and ransomware-enabling activity. The cases were later consolidated.

Volkov brokers unauthorized access for ransomware attacks on U.S. victims

Aleksei Volkov acted as an initial access broker, hacking into victim networks and selling that access to cybercrime groups including the Yanluowang ransomware gang. The resulting intrusions led to data theft, ransomware deployment, and extortion against numerous U.S. companies and organizations, causing more than $9 million in actual losses and more than $24 million in intended losses.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

12 LINKEDOpen in app
Threat actors
3 linked
Organizations
6 linked
LinkedinDigitalMintXBroadcomGoogleSecurity Affairs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.