A U.S. federal court sentenced Russian national Aleksei Volkov, 26, to 81 months in prison for acting as an initial access broker who helped major cybercrime groups, including the Yanluowang ransomware operation, compromise U.S. companies and other organizations. Prosecutors said Volkov gained unauthorized access to victim networks and sold that access to ransomware operators, who then deployed malware, encrypted systems, stole data, and extorted victims through cryptocurrency ransom demands.
The U.S. Department of Justice said the campaign caused more than $9 million in actual losses and more than $24 million in intended losses. Volkov was indicted in Indiana and Pennsylvania, arrested in Rome, extradited from Italy to the United States, and later pleaded guilty after the cases were consolidated. As part of the plea, he admitted hacking victim networks, stealing data, helping co-conspirators deploy ransomware, and sharing in ransom proceeds; he was also ordered to pay at least $9,167,198.19 in restitution and forfeit equipment used in the crimes.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
U.S. prosecutors charged Angelo Martino as a third negotiator tied to BlackCat/ALPHV ransomware attacks, alleging he helped pressure at least 10 victims into paying higher ransoms while working for DigitalMint. Authorities also seized nearly $9.2 million in cryptocurrency and other assets connected to the case.
The Southern District of Indiana sentenced Volkov to 81 months in prison for assisting major cybercrime groups, including the Yanluowang ransomware gang. He was also ordered to pay at least $9,167,198.19 in restitution and forfeit equipment used in the crimes.
Volkov pleaded guilty after the Indiana and Pennsylvania cases were consolidated. In his plea, he admitted to hacking victim networks, stealing data, enabling ransomware deployment through co-conspirators, and sharing in ransom proceeds.
After being charged, Volkov was arrested in Rome and transferred from Italy to the United States to face prosecution. The extradition enabled the U.S. cases against him to proceed.
U.S. prosecutors charged Volkov in separate cases in the Southern District of Indiana and the Eastern District of Pennsylvania for his role in intrusions and ransomware-enabling activity. The cases were later consolidated.
Aleksei Volkov acted as an initial access broker, hacking into victim networks and selling that access to cybercrime groups including the Yanluowang ransomware gang. The resulting intrusions led to data theft, ransomware deployment, and extortion against numerous U.S. companies and organizations, causing more than $9 million in actual losses and more than $24 million in intended losses.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecyberscoop.com
Open sourcesecurityaffairs.com
Open sourceitpro.com
Open sourcejustice.gov
Open sourcedatabreaches.net
Open sourceinfosec.pub
Open sourceismg-cdn.nyc3.cdn.digitaloceanspaces.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.