Phobos Ransomware Mastermind Evgenii Ptitsyn Pleads Guilty to U.S. Fraud Charges
Mar 5, 2026 // 13:42 - Norina Velotta


Evgenii Ptitsyn, a 43-year-old Russian national and high-level administrator of the Phobos ransomware-as-a-service (RaaS) operation, has pleaded guilty in federal court to wire fraud conspiracy.

Key Details of the Plea

  • Role and Extradition: Ptitsyn oversaw the sale, distribution, and day-to-day operation of Phobos, often using the online aliases “derxan” and “zimmermanx.” He was extradited to the United States from South Korea in November 2024.
  • Victims and Impact: The Phobos operation victimized over 1,000 public and private entities worldwide, including schools, hospitals, and local governments.
  • Extorted Amount: The conspiracy successfully extorted ransom payments totaling more than $39 million.
  • Sentencing: Ptitsyn is scheduled to be sentenced on July 15, 2026. He faces a maximum penalty of 20 years in prison for the wire fraud conspiracy charge.

The Phobos Operation

Operating since at least November 2020, Phobos functioned as a Ransomware-as-a-Service model where Ptitsyn provided the malware to “affiliates.” These affiliates carried out the actual hacks—often via phishing or exploiting Remote Desktop Protocol (RDP)—and paid Ptitsyn a fee to obtain the decryption keys required to unlock victim data.

For further details, you can view the official press release from the U.S. Attorney’s Office, District of Maryland.

#charges  #evgenii  #fraud  #guilty  #mastermind  #news  #phobos  #pleads  #ptitsyn  #ransomware  #u.s.   —   News