logo

Phobos ransomware admin pleads guilty to wire fraud conspiracy

ID: 8b54c291-f020-5602-b710-8eb84a786e86

STIX ID: report--8b54c291-f020-5602-b710-8eb84a786e86

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-03-05

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Phobos, a long-running ransomware-as-a-service linked to the Crysis family, has been operated by affiliates who used stolen credentials to breach networks, exfiltrate data, and encrypt victims' files; the operation collected over $39 million from more than 1,000 victims. U.S. authorities extradited and secured a guilty plea from a suspected Phobos administrator (Evgenii Ptitsyn) and international law enforcement efforts (Operation Aether) have led to arrests and infrastructure seizures that disrupted the RaaS operation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.