The international battle against cybercrime continues with new developments, as a Russian national has pleaded guilty to his participation in one of the most notorious ransomware operations of recent years. The case concerns the management of the Phobos ransomware malware , which has been linked to hundreds of attacks against organizations and businesses worldwide.

Confession of guilt for the manager of the ransomware operation
According to US authorities, 43-year-old Evgenii Ptitsyn has pleaded guilty to conspiracy to commit wire fraud. The case is related to his role in organizing and operating the Phobos ransomware, which was used in massive cyber-extortion attacks.
Ptitsyn was extradited to the United States in November 2024 from South Korea after an international investigation revealed his role in managing the ransomware infrastructure. US authorities accused him of overseeing the distribution, sale and operation of the Phobos platform.
See also: Authorities dismantled the infrastructure of the phishing service Tycoon2FA
His sentence is expected to be announced on July 15 and he faces a prison sentence that could reach up to 20 years.
The ransomware-as-a-service model
Phobos operated under the now-famous ransomware-as-a-service (RaaS) model. This architecture allows malware creators to distribute their malware to partners, who then carry out the attacks in exchange for a percentage of the ransom.
This ransomware is related to the Crysis ransomware and has been widely distributed through multiple criminal networks. According to data from ID Ransomware, Phobos accounted for approximately 11% of all reported incidents between May and November 2024.
The United States Department of Justice estimates that the criminal organization extorted more than $39 million in ransom, targeting over 1,000 public and private sector organizations.

Phobos ransomware: How the cybercrime network operated
According to court documents, the cybercrime operation began no later than November 2020. Ptitsyn and his accomplices advertised the ransomware on dark web forums and darknet websites using the aliases “derxan” and “zimmermanx.”
The attacks were carried out by associates who purchased access to the malware. They often broke into corporate networks using stolen credentials or exploiting vulnerabilities in remote access systems.
See also: LeakBase: Authorities dismantle stolen data exchange forum
The attacks targeted organizations such as hospitals, schools, and government agencies. Once they gained access, the attackers stole data and then encrypted critical files, demanding a ransom to restore access.
Ransomware and data leak threats
The groups using Phobos didn't just limit themselves to encrypting data. In many cases, they also employed double-blackmail tactics. If a victim refused to pay, the attackers threatened to publish the stolen files online.
These threats were often accompanied by emails and phone calls to the victims, with warnings that the data would be sent even to customers or partners of the company.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The financial structure of the operation was also clearly organized. After each successful attack, the partners paid around $300 to Phobos administrators to receive the corresponding decryption key.
Each attack was accompanied by a unique alphanumeric identifier corresponding to the specific key. These fees were paid into cryptocurrency wallets associated with the partners.

The path of money through cryptocurrencies
Researchers discovered that between December 2021 and April 2024, the fees for the decryption keys were ultimately transferred to a centralized cryptocurrency wallet allegedly controlled by Ptitsyn.
See also: Malicious Laravel Packages on Packagist Install RAT
The use of cryptocurrencies is a core element in many ransomware operations, as it provides a level of anonymity in the financial transactions of criminals.
However, authorities have now developed sophisticated blockchain analysis techniques, which allow money routes to be traced and linked to real people.
The international operation Aether
The arrest and prosecution of those involved is also linked to the international police operation Operation Aether, a coordinated effort supported by Europol and Eurojust.
As part of this operation, authorities made multiple arrests in different countries and seized infrastructure used to operate the ransomware.
Earlier in 2025, Polish police arrested a 47-year-old suspect allegedly with ties to the Phobos network, while computers and mobile phones containing stolen credentials, credit card numbers and server access details were seized.

Mass seizures of infrastructures and warnings to companies
The operation had other significant results. In February 2025, authorities arrested two more associates and seized a total of 27 servers used for ransomware attacks.
Meanwhile, law enforcement services managed to warn more than 400 companies worldwide about attacks that were ongoing or were about to be carried out.
According to Europol, law enforcement agencies from a total of 14 countries participated in this complex international operation, showing how necessary transnational cooperation in tackling modern cybercrime.
Source: www.bleepingcomputer.com
