Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
1 malware family

Phobos

Also known asPhobos

Phobos is a ransomware-as-a-service (RaaS) operation and ransomware brand active since at least 2019/2020. It is described as derived from the Crysis ransomware family and has been linked to more than 1,000 victims worldwide, including public and private entities such as hospitals, schools, government agencies, healthcare providers, nonprofits, and other critical infrastructure organizations. Reported extortion totals in the provided content vary, with sources citing more than $16 million and more than $39 million in ransom payments. Phobos operated through affiliates. U.S. authorities stated that administrator Evgenii Ptitsyn administered the sale, distribution, and operation of Phobos, and that affiliates paid fees for unique decryption keys after attacks. The content also states Ptitsyn and conspirators used a RaaS model, controlled cryptocurrency wallets receiving affiliate fees and sometimes ransom proceeds, and allegedly sold Phobos on darknet forums under the aliases "derxan" and "zimmermanx." Law-enforcement actions referenced in the content include Ptitsyn’s arrest in South Korea and guilty plea in the United States, arrests of other alleged operators including Roman Berezhnoy and Egor Glebov, and Europol-coordinated Operation Aether targeting Phobos operators, affiliates, and infrastructure worldwide, including a Polish arrest of a 47-year-old suspect. Operationally, Phobos is noted as a persistent ransomware brand from 2020 through 2025. Huntress reported that Phobos actors carried out more than 30 actions on average before deploying ransomware and had longer time-to-ransom than faster-moving groups such as Play and Akira. The content also states that most ransomware actors in that dataset exfiltrated data before encryption, consistent with double-extortion behavior. Seqrite reported that Process Hacker is commonly used by Phobos operators. Another report noted overlap where the LockBit run key "XO1XADpO01" and ransom note filename "Restore-My-Files.txt" were also seen in Phobos and a Phobos imposter ransomware. The content also links Phobos to related or associated activity. 8Base is described as linked to Phobos, with some reporting stating 8Base operators are former affiliates of Dharma and/or Phobos, and other reporting describing Operation Aether as targeting the 8Base group believed to be linked to Phobos. Space Bears is described as associated with the Phobos RaaS operation and linked to the Faust operator within the Phobos ecosystem. Known related names directly mentioned in the content include Dharma/Crysis, 8Base, and Space Bears.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

13 of 15 tactics32 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
2 techniques
T1133
External Remote Services
T1566
Phishing
TA0002
Execution
1 technique
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
TA0003
Persistence
3 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1112
Modify Registry
T1133
External Remote Services
TA0004
Privilege Escalation
2 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1548
Abuse Elevation Control Mechanism
T1548.002
Bypass User Account Control
TA0005
Stealth
1 technique
T1027
Obfuscated Files or Information
TA0112
Defense Impairment
1 technique
T1112
Modify Registry
TA0006
Credential Access
2 techniques
T1003
OS Credential Dumping
T1003.001
LSASS Memory
T1110
Brute Force
TA0007
Discovery
2 techniques
T1069
Permission Groups Discovery
T1069.002
Domain Groups
T1614
System Location Discovery
T1614.001
System Language Discovery
TA0008
Lateral Movement
1 technique
T1021
Remote Services
TA0009
Collection
1 technique
T1560
Archive Collected Data
TA0011
Command and Control
4 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1090
Proxy
T1105
Ingress Tool Transfer
T1573
Encrypted Channel
TA0010
Exfiltration
1 technique
T1567
Exfiltration Over Web Service
T1567.002
Exfiltration to Cloud Storage
TA0040
Impact
2 techniques
T1486×3
Data Encrypted for Impact
T1490
Inhibit System Recovery
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping21

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.