Armenia Detains Russian National Aleksandr Ermakov on US Extradition Request Tied to Sodinokibi/REvil Ransomware
Armenia Detains Russian National Aleksandr Ermakov on US (TL-2026-1446), also tracked as Medibank hacker case, is a medium-severity tracked threat-actor profile, first published 2026-07-17. It is attributed to REvil (Russia) with medium confidence, affects N/A Law-enforcement/extradition matter (not a software vulnerability), maps to 36 MITRE ATT&CK techniques (T1007, T1012, T1027.011), and is covered by 9 detection rules and 17 indicators of compromise.
Key facts for TL-2026-1446
- Threat ID
- TL-2026-1446
- Also known as
- Medibank hacker case, SugarLocker case, GustaveDore identification dispute
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- THREAT_ACTOR
- First published
- 2026-07-17
- Last reviewed
- 2026-07-17
- Attribution
- REvil
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- government administration, police - law enforcement, health, education, manufacturing, transport, energy, privateindustry, legalservices
- Target regions
- North America, australia, Europe, russia, armenia, united states of america
- Detection rules
- 9
- Indicators of compromise
- 17
Malware and tooling in Armenia Detains Russian National Aleksandr Ermakov on US
Malware and tooling: SugarPanel
Armenian border officers detained Aleksandr Yuryevich Ermakov, a Russian tourist from Omsk, at Yerevan's Zvartnots airport on June 28, 2026, on a US extradition warrant (Northern District of Texas, June 26, 2026) alleging participation in the Sodinokibi/REvil ransomware operation (April 2019-July 2021, 1,000+ victims, ~$13.7M as platform administrator). Defense counsel argues the warrant misidentifies the detainee, who lacks the patronymic 'Gennadievich' matching the actually-wanted Aleksandr Gennadievich Ermakov (b. May 16, 1990), separately sanctioned by Australia/US/UK in January 2024 for the October 2022 Medibank Private breach and previously convicted in Russia in connection with the SugarLocker ransomware operation.
How Armenia Detains Russian National Aleksandr Ermakov on US works
On June 28, 2026, Armenian border authorities at Yerevan's Zvartnots International Airport detained a Russian tourist identified as Aleksandr Yuryevich Ermakov, a resident of Omsk traveling with his wife Maria Yurova. The detention followed an Interpol red notice/detention order and a US extradition warrant issued June 26, 2026, by the US District Court for the Northern District of Texas, alleging the wanted individual was a platform administrator for the Sodinokibi/REvil ransomware-as-a-service (RaaS) operation between April 2019 and July 12, 2021. Prosecutors allege the REvil campaign compromised more than 1,000 victim organizations across private industry, law enforcement, government, and education/healthcare sectors, generating an estimated $13.7 million in ransom proceeds attributable to the administrator role.
Defense counsel (attorney Dylan Rajavi) disputes the identification, arguing the US warrant omits a patronymic and that Armenian/Interpol wanted-persons records list the actually sought individual as Aleksandr Gennadievich Ermakov, born May 16, 1990 and based in Moscow -- not the detainee, whose patronymic is Yuryevich (son of Yuri), who has no IT background, does not speak English, and previously worked as a lawyer within Russia's federal prison service (FSIN). The defense has requested consular assistance from the Russian Foreign Ministry; spokesperson Maria Zakharova confirmed the Russian Embassy in Yerevan sought consular access. As of this reporting the detainee remains held under a 30-day Interpol provisional-arrest window pending an Armenian court extradition ruling.
Aleksandr Gennadievich Ermakov -- the individual the US warrant is understood to target -- is a previously sanctioned and identified REvil-linked threat actor. On January 23, 2024, Australia's Minister for Foreign Affairs imposed the country's first-ever thematic cyber sanctions under the Autonomous Sanctions Act 2011 against him for his role as an alleged ringleader/key actor in the October 2022 Medibank Private data breach, in which approximately 9.7 million customer records (including sensitive health claims data) were stolen and partially leaked on the dark web after Medibank refused to pay a ransom. On January 24, 2024, the US Treasury's Office of Foreign Assets Control (OFAC) and the UK's Office of Financial Sanctions Implementation (OFSI) imposed coordinated financial sanctions and travel bans against the same individual, publicly naming him and listing aliases including GustaveDore/GistaveDore, blade_runner, aiiis_ermak, JimJones, and SHTAZI.
Separately, in Russia, Ermakov and associates were tied to SugarLocker, a smaller domestic ransomware operation marketed through a front company ('Shtazi-IT') offering web/app development services as legitimate cover. Group-IB/F.A.C.C.T. researchers identified a web-server misconfiguration in SugarLocker's affiliate control panel ('SugarPanel') in January 2022 and used it to map the group's Tor-hosted infrastructure and affiliate roster. Russian police arrested SugarLocker-linked suspects operating under the handles blade_runner, GustaveDore, and JimJones in January 2024 -- roughly one month after the Australian/US/UK Medibank sanctions publicly linked those same aliases to Ermakov. A Moscow court convicted Ermakov in October 2024 under Russian Criminal Code Article 273(2) (creation/use/distribution of malicious computer programs), sentencing him to two years' restriction of freedom (a form of probation with travel and movement restrictions) rather than incarceration -- Russia does not extradite its own nationals, and the domestic conviction/light sentence has been characterized by Western officials as protecting a cybercriminal asset from foreign prosecution.
This event is a law-enforcement/attribution development rather than a new technical exploitation event: no new CVE, malware sample, or C2 infrastructure was disclosed. It is documented here for threat-actor tracking and correlation with prior REvil/Sodinokibi and Medibank/SugarLocker coverage, and because the identity dispute itself is operationally relevant -- it illustrates both the persistent difficulty of cross-jurisdictional attribution for RaaS platform operators and Russia's pattern of shielding sanctioned ransomware affiliates via light domestic prosecution in lieu of extradition.
MITRE ATT&CK techniques used in TL-2026-1446
Discovery
T1007 System Service Discovery; T1012 Query Registry; T1069.002 Domain Groups; T1082 System Information Discovery; T1083 File and Directory Discovery; T1614.001 System Language Discovery; T1680 Local Storage Discovery
Defense Evasion
T1027.011 Fileless Storage; T1027.013 Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1055 Process Injection; T1070.004 File Deletion; T1140 Deobfuscate/Decode Files or Information
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1047 Windows Management Instrumentation; T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.005 Visual Basic; T1106 Native API; T1204.002 Malicious File
Privilege Escalation
T1055 Process Injection; T1134.002 Create Process with Token
Command and Control
T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1573.002 Asymmetric Cryptography
defense-impairment
T1112 Modify Registry; T1685 Disable or Modify Tools; T1688 Safe Mode Boot
Initial Access
T1133 External Remote Services; T1189 Drive-by Compromise; T1195 Supply Chain Compromise; T1566.001 Spearphishing Attachment
stealth
T1134.001 Token Impersonation/Theft
Impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery
Affected products and versions in Armenia Detains Russian National Aleksandr Ermakov on US
- N/A — Law-enforcement/extradition matter (not a software vulnerability)
Remediation for Armenia Detains Russian National Aleksandr Ermakov on US
Immediate actions
- Legal/HR teams handling extradition or sanctions-screening workflows should verify full identity attributes (patronymic, DOB, aliases) rather than name-matching alone before taking action against a named individual
- Compliance teams should cross-check OFAC/OFSI/Australian DFAT sanctions listings for Aleksandr Gennadievich Ermakov (DOB 1990-05-16) using the full alias set (GustaveDore, blade_runner, aiiis_ermak, JimJones, SHTAZI) to avoid false-positive/false-negative sanctions screening
- Organizations previously affected by REvil/Sodinokibi (2019-2021) or Medibank-adjacent healthcare-sector breaches should review historical IOCs against current threat intel to detect any resurfacing infrastructure or affiliate reuse
Longer-term hardening
- Maintain layered ransomware defenses (offline/immutable backups, EDR with behavioral ransomware detection, network segmentation) given RaaS affiliate personnel and tooling frequently persist or resurface under new brands after law-enforcement action
- Monitor dark-web/RaaS forum activity for aliases historically tied to REvil/SugarLocker administrators in case of a rebrand following this arrest/extradition dispute
- Track Interpol/DOJ extradition case outcomes for downstream shifts in threat-actor operational security or forum activity
Timeline of Armenia Detains Russian National Aleksandr Ermakov on US
- REvil/Sodinokibi ransomware-as-a-service operation begins active campaigns, with Ermakov alleged by US prosecutors to have acted as a platform administrator from this point.
- REvil affiliate operators conduct the Kaseya VSA MSP supply-chain ransomware attack, among the group's most prominent campaigns during the alleged administration period (contextual reference, not directly charged in this warrant).
- US indictment window for the alleged REvil administrator activity closes; cumulative campaign reported to have affected over 1,000 victim organizations for an alleged $13.7 million in administrator proceeds.
- Medibank Private, an Australian health insurer, suffers a data breach attributed to REvil-linked actors; attackers steal approximately 9.7 million customer records including sensitive health claims data.
- After Medibank refuses to pay ransom, attackers begin publishing stolen customer data, including sensitive medical records, on dark-web forums.
- Russian police arrest suspects linked to the domestic SugarLocker ransomware operation, using handles blade_runner, GustaveDore, and JimJones -- aliases matching those later publicly tied to Aleksandr Gennadievich Ermakov.
- Australia's Minister for Foreign Affairs imposes the country's first thematic cyber sanctions under the Autonomous Sanctions Act 2011 against Aleksandr Gennadievich Ermakov for his alleged role in the Medibank breach.
- US Treasury OFAC and UK OFSI impose coordinated financial sanctions and travel bans against Ermakov, publicly naming his aliases GustaveDore, blade_runner, aiiis_ermak, JimJones, and SHTAZI.
- A Moscow court convicts Ermakov under Russian Criminal Code Article 273(2) (malicious computer programs) and sentences him to two years' restriction of freedom rather than incarceration; Russia does not extradite its own nationals.
- US District Court for the Northern District of Texas issues an extradition warrant for 'Aleksandr Ermakov' tied to Sodinokibi/REvil platform-administrator activity.
- Armenian border officers detain a Russian tourist identified as Aleksandr Yuryevich Ermakov at Yerevan's Zvartnots International Airport on the US extradition warrant and an Interpol detention order.
- Defense counsel (Dylan Rajavi) publicly disputes the identification, noting the US warrant lacks a patronymic and that the detainee's patronymic (Yuryevich) does not match the wanted individual's (Gennadievich); Russian Foreign Ministry spokesperson Maria Zakharova confirms consular-access request.
- The Hacker News and Russian outlets (RIA Novosti, Armenia Today, Kommersant, Izvestia) report ongoing detention, pending Armenian court extradition ruling, and statements from the detainee's brother and defense team.
Sources cited for Armenia Detains Russian National Aleksandr Ermakov on US
- Armenia Detains Russian Tourist on US Extradition Warrant Over Alleged REvil Ransomware Ties
- The Russian was detained at the Armenian airport ... namesake of a hacker wanted by Interpol
- Тезку разыскиваемого хакера готовят в Армении к экстрадиции в США
- Брат арестованного в Армении россиянина рассказал новые подробности
- Защита задержанного в Армении россиянина обратилась в МИД
- Medibank attack: Australia sanctions Russian Aleksandr Ermakov accused of hacking in data leak
- UK, US and Australia sanction Russian citizen over Medibank hack
- US sanctions Russian citizen accused of playing key role in Medibank ransomware attack
- Who is Alleged Medibank Hacker Aleksandr Ermakov?
- Breaking Down The Ermakov Sanctions: What You Need To Know
- Government names, sanctions Medibank hacker
- Aleksandr Gennadievich ERMAKOV - OpenSanctions entity record
- Russia arrests three alleged SugarLocker ransomware members
- SugarLocker Member Arrest: Russian Enforcement Takes Lead
- Russia Announces Arrest of Medibank Hacker Tied to REvil
Threats related to Armenia Detains Russian National Aleksandr Ermakov on US
Detection coverage for TL-2026-1446
As of 2026-07-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1446 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.