Phobos is a ransomware-as-a-service operation active since 2018 and widely assessed as part of the Dharma/Crysis lineage. It has historically focused on small and medium-sized organizations and commonly gained initial access through exposed or weakly protected Remote Desktop Protocol services. The operation uses an affiliate model in which administrators provide the ransomware platform and decryption-key infrastructure while separate affiliates conduct intrusions and share proceeds. Public reporting and law-enforcement actions have linked the operation to Russian nationals, including administrator Evgenii Ptitsyn, and to a broader criminal ecosystem spanning operators, affiliates, and infrastructure support personnel. Phobos has targeted more than 1,000 public- and private-sector entities worldwide, including hospitals, schools, government agencies, health care providers, educational institutions, and other essential-service organizations. It has also been described as one of the more aggressive ransomware brands affecting organizations in Russia. Known affiliate or associated sub-groups and brands include Faust, BlackRock, Devos, 8Base, and Space Bears. Faust in particular has been observed using dedicated leak infrastructure for extortion, while 8Base has been linked operationally to the broader Phobos ecosystem. Operationally, Phobos long favored relatively opportunistic intrusions and smaller ransom demands compared with major big-game ransomware crews, often encrypting limited numbers of systems rather than conducting full enterprise-wide compromises. Over time, however, the operation evolved beyond encryption-only extortion. By late 2023 and into 2024, Phobos affiliates were observed exfiltrating victim data and using leak sites to pressure victims, marking a clear shift to double extortion. Associated leak-site activity has included publication or threatened publication of stolen data as part of monetization. Observed tradecraft includes initial access via exposed RDP, use of compromised credentials, brute-force activity against remote access services, data exfiltration to external cloud services, and abuse of legitimate administrative or dual-use tools for defense evasion. Reporting has associated Phobos operators with tools such as Process Hacker and Defender Control to disable or impair security products. Phobos intrusions have also been characterized by numerous pre-encryption actions, including disabling security controls, stealing data, and conducting post-compromise activity before ransomware deployment. The operation’s affiliate-based structure, persistence across multiple years, and adaptation from single-system encryption toward data-theft-enabled extortion have made it a durable criminal ransomware threat.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced via a cracked builder offered on RAMP, lowering the barrier to launch independent ransomware attacks outside the normal affiliate model.
Ransomware operators noted for using Process Hacker as part of attacks, likely to interfere with defensive processes.
Ransomware operation administered through affiliates, extorting public and private entities globally.
Ransomware operation run via an affiliate model, coordinating sale/distribution of the Phobos ransomware and decryption keys; affiliates targeted 1,000+ organizations worldwide and collected $39M+ in ransoms, including dozens of attacks against U.S. healthcare, hospitals, education, and essential services.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.