Thai authorities, acting on intelligence provided by the FBI, arrested Denis Obrezko, an alleged member of the Russia-linked threat group Void Blizzard, at a hotel in Phuket on November 6. The operation, conducted jointly by the FBI and Thai police, resulted in the seizure of multiple electronic devices, including laptops, mobile phones, and cryptocurrency wallets. Obrezko, who had entered Thailand on October 30, was detained in Bangkok's Criminal Court pending extradition to the United States, with the Russian embassy confirming the arrest and considering consular assistance.
Obrezko is suspected of having previously breached security systems and attacked government agencies in both Europe and the United States. The arrest was made after authorities received information that he was targeting Thailand, and an arrest warrant was obtained based on a U.S. extradition request. The U.S. Department of Justice has not yet commented on the case, while Russian officials have acknowledged the detention and are monitoring the situation.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
After the detention became public, the Russian embassy in Thailand confirmed that a Russian citizen had been arrested at the request of the United States. At the time of reporting, the U.S. Department of Justice had not publicly commented on the case.
In a joint operation involving the FBI and Thai police, Thai authorities detained Obrezko and brought him before Bangkok’s Criminal Court ahead of extradition proceedings to the U.S. Thailand’s Cyber Crime Investigation Bureau said the suspect had previously breached security systems and targeted government agencies in Europe and the United States.
Thai authorities said they found Russian national Denis Obrezko in a hotel room in Thailand on 2025-11-06, about a week after his arrival. During the operation, officers seized multiple electronic devices, including a mobile phone, notebook computer, and a digital wallet.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
4 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcescworld.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.