'Phobos' Ransomware Cybercriminal Extradited From South Korea

According to the unsealed criminal charges, the operation is believed to have running for nearly four years.

Dark Reading Staff, Dark Reading

November 19, 2024

2 Min Read
The word ransomware in red surrounded by blurry, green binary code
Source: Christophe Coat via Alamy Stock Photo

After being extradited from South Korea, a Russian cybercriminal leader has made his first appearance in the US District Court for the District of Maryland to face his charges.

Evgenii Ptitsyn, 42, is a Russian national who allegedly administered the sale, distribution, and operation of Phobos ransomware, which has been used against more than 1,000 victims, including public and private entities in the United States and globally. Using Phobos ransomware, its affiliates have extorted ransom payments amounting to more than $16 million, according to the indictment.

Ptitsyn and his affiliates conspired to partake in an international computer hacking and extortion scheme using the ransomware, according to the Justice Department, which believes the activity to have begun in at least November 2020.

Along with his co-conspirators, Ptitsyn would offer access to the ransomware to other criminals, creating an operation in which affiliates would use unauthorized credentials to gain access into victims' computer networks, steal files and programs, and encrypt the original versions of the stolen data before installing and executing the Phobos ransomware. The affiliates would threaten to expose the stolen files to the public or the victim's clients, customers, or constituents if the ransom was not paid.

"Ptitsyn and his co-conspirators hacked not only large corporations, but also schools, hospitals, nonprofits, and a federally recognized tribe, and they extorted more than $16 million in ransom payments," stated Principal Deputy Assistant Attorney General Nicole M. Argentieri, head of the Justice Department's Criminal Division. "Ptitsyn's indictment, arrest, and extradition reflect the Criminal Division's commitment to leading the fight against the international scourge of ransomware."

Charged in a 13-count indictment with wire fraud conspiracy, wire fraud, conspiracy to commit computer fraud and abuse, four counts of causing intentional damage to protected computers, and four counts of extortion in relation to hacking, Ptitsyn will face a maximum penalty of 20 years in prison for each wire fraud count, 10 years for each computer hacking count, and five years for conspiracy to commit computer fraud and abuse, if he is convicted.

About the Author

Dark Reading Staff

Dark Reading

Dark Reading is a leading cybersecurity media site.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights