Phobos ransomware administrator faces US cybercrime charges

Share:

The Justice Department unsealed criminal charges against Evgenii Ptitsyn, 42, a Russian national, for allegedly administering the sale, distribution, and operation of Phobos ransomware.

Ptitsyn made his initial appearance in the US District Court for the District of Maryland on Nov. 4 after being extradited from South Korea. Phobos ransomware, through its affiliates, victimized more than 1,000 public and private entities in the United States and around the world, and extorted ransom payments worth more than $16 million dollars.

Phobos ransomware used in international hacking and extortion scheme

As alleged in the indictment, beginning in at least November 2020, Ptitsyn and others conspired to engage in an international computer hacking and extortion scheme that victimized public and private entities through the deployment of Phobos ransomware.

As part of the scheme, Ptitsyn and his co-conspirators allegedly developed and sold access to Phobos ransomware on the darknet. They used online monikers to advertise their services on criminal forums and messaging platforms. Ptitsyn reportedly used the monikers “derxan” and “zimmermanx.”

Affiliates, after gaining access to victim computer networks, would copy and steal files and programs, and encrypt the original versions of the stolen data by installing and executing Phobos ransomware. They would then demand a ransom payment from victims in exchange for the decryption keys to regain access to the encrypted data. The affiliates also threatened to expose victims’ stolen files if the ransoms were not paid.

After a successful Phobos ransomware attack, criminal affiliates paid fees to Phobos administrators for a decryption key to regain access to the encrypted files. Each deployment of Phobos ransomware was assigned a unique alphanumeric string to match it to the corresponding decryption key, and each affiliate was directed to pay the decryption key fee to a cryptocurrency wallet unique to that affiliate. From December 2021 to April 2024, the decryption key fees were then transferred from the unique affiliate cryptocurrency wallet to a wallet controlled by Ptitsyn.

Phobos ransomware suspect charged with 13 crimes

Ptitsyn is charged in a 13-count indictment with wire fraud conspiracy, wire fraud, conspiracy to commit computer fraud and abuse, four counts of causing intentional damage to protected computers, and four counts of extortion in relation to hacking.

If convicted, he faces a maximum penalty of 20 years in prison for each wire fraud count; 10 years in prison for each computer hacking count; and five years in prison for conspiracy to commit computer fraud and abuse.

Help Net Security

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
12:27 pm, Mar 12, 2025
weather icon 7°C
L: 6° | H: 8°
light rain
Humidity: 71 %
Pressure: 1003 mb
Wind: 6 mph NW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0.13 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 6:21 am
Sunset: 5:59 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
6° | 8°°C 0 mm 0% 10 mph 83 % 1003 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
2° | 6°°C 0.97 mm 97% 9 mph 92 % 1007 mb 0.57 mm/h
Fri Mar 14 9:00 pm
weather icon
1° | 7°°C 0.57 mm 57% 8 mph 91 % 1015 mb 0 mm/h
Sat Mar 15 9:00 pm
weather icon
1° | 7°°C 0.2 mm 20% 11 mph 76 % 1026 mb 0 mm/h
Sun Mar 16 9:00 pm
weather icon
2° | 9°°C 0 mm 0% 11 mph 79 % 1030 mb 0 mm/h
Today 3:00 pm
weather icon
7° | 7°°C 0 mm 0% 10 mph 65 % 1003 mb 0 mm/h
Today 6:00 pm
weather icon
6° | 6°°C 0 mm 0% 7 mph 67 % 1002 mb 0 mm/h
Today 9:00 pm
weather icon
4° | 4°°C 0 mm 0% 9 mph 83 % 1003 mb 0 mm/h
Tomorrow 12:00 am
weather icon
3° | 3°°C 0 mm 0% 8 mph 82 % 1003 mb 0 mm/h
Tomorrow 3:00 am
weather icon
2° | 2°°C 0 mm 0% 7 mph 82 % 1003 mb 0 mm/h
Tomorrow 6:00 am
weather icon
2° | 2°°C 0 mm 0% 8 mph 92 % 1003 mb 0 mm/h
Tomorrow 9:00 am
weather icon
3° | 3°°C 0.6 mm 60% 8 mph 85 % 1004 mb 0.57 mm/h
Tomorrow 12:00 pm
weather icon
5° | 5°°C 0.53 mm 53% 9 mph 63 % 1004 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€76,037.76
1.45%
Ethereum(ETH)
€1,754.99
0.46%
Tether(USDT)
€0.92
-0.01%
XRP(XRP)
€2.02
3.32%
Solana(SOL)
€116.14
1.76%
USDC(USDC)
€0.92
-0.01%
Dogecoin(DOGE)
€0.154285
4.46%
Shiba Inu(SHIB)
€0.000011
5.00%
Pepe(PEPE)
€0.000006
9.83%