Armenia Detains Russian National Aleksandr Ermakov on US Extradition Request Tied to Sodinokibi/REvil Ransomware — Threadlinqs Intelligence
As of 2026-07-17, Armenia Detains Russian National Aleksandr Ermakov on US Extradition Request Tied to Sodinokibi/REvil Ransomware is a medium-severity threat actor threat attributed to REvil (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 17 indicators of compromise.
Threat ID: TL-2026-1446 · Severity: MEDIUM · Status: ACTIVE · Category: THREAT_ACTOR
Attribution: REvil · Russia · FINANCIAL
Armenian border officers detained Aleksandr Yuryevich Ermakov, a Russian tourist from Omsk, at Yerevan's Zvartnots airport on June 28, 2026, on a US extradition warrant (Northern District of Texas,
On June 28, 2026, Armenian border authorities at Yerevan's Zvartnots International Airport detained a Russian tourist identified as Aleksandr Yuryevich Ermakov, a resident of Omsk traveling with his wife Maria Yurova. The detention followed an Interpol red notice/detention order and a US extradition warrant issued June 26, 2026, by the US District Court for the Northern District of Texas, alleging the wanted individual was a platform administrator for the Sodinokibi/REvil ransomware-as-a-service (RaaS) operation between April 2019 and July 12, 2021. Prosecutors allege the REvil campaign compromised more than 1,000 victim organizations across private industry, law enforcement, government, and education/healthcare sectors, generating an estimated $13.7 million in ransom proceeds attributable to the administrator role.
Defense counsel (attorney Dylan Rajavi) disputes the identification, arguing the US warrant omits a patronymic and that Armenian/Interpol wanted-persons records list the actually sought individual as Aleksandr Gennadievich Ermakov, born May 16, 1990 and based in Moscow -- not the detainee, whose patronymic is Yuryevich (son of Yuri), who has no IT background, does not speak English, and previously worked as a lawyer within Russia's federal prison service (FSIN). The defense has requested consular assistance from the Russian Foreign Ministry; spokesperson Maria Zakharova confirmed the Russian Embassy in Yerevan sought consular access. As of this reporting the detainee remains held under a 30-day Interpol provisional-arrest window pending an Armenian court extradition ruling.
Aleksandr Gennadievich Ermakov -- the individual the US warrant is understood to target -- is a previously sanctioned and identified REvil-linked threat actor. On January 23, 2024, Australia's Minister for Foreign Affairs imposed the country's first-ever thematic cyber sanctions under the Autonomous Sanctions Act 2011 against him for his role as an alleged ringleader/key actor in the October 2022 Medibank Private data breach, in which approximately 9.7 million customer records (including sensitive health claims data) were stolen and partially leaked on the dark web after Medibank refused to pay a ransom. On January 24, 2024, the US Treasury's Office of Foreign Assets Control (OFAC) and the UK's Office of Financial Sanctions Implementation (OFSI) imposed coordinated financial sanctions and travel bans against the same individual, publicly naming him and listing aliases including GustaveDore/GistaveDore, blade_runner, aiiis_ermak, JimJones, and SHTAZI.
Separately, in Russia, Ermakov and associates were tied to SugarLocker, a smaller domestic ransomware operation marketed through a front company ('Shtazi-IT') offering web/app development services as legitimate cover. Group-IB/F.A.C.C.T. researchers identified a web-server misconfiguration in SugarLocker's affiliate control panel ('SugarPanel') in January 2022 and used it to map the group's Tor-hosted infrastructure and affiliate roster. Russian police arrested SugarLocker-linked suspects operating under the handles blade_runner, GustaveDore, and JimJones in January 2024 -- roughly one month after the Australian/US/UK Medibank sanctions publicly linked those same aliases to Ermakov. A Moscow court convicted Ermakov in October 2024 under Russian Criminal Code Article 273(2) (creation/use/distribution of malicious computer programs), sentencing him to two years' restriction of freedom (a form of probation with travel and movement restrictions) rather than incarceration -- Russia does not extradite its own nationals, and the domestic conviction/light sentence has been characterized by Western officials as protecting a cybercriminal asset from foreign prosecution.
This event is a law-enforcement/attribution development rather than a new technical exploitation event: no new CVE, malware sample, or C2 infrastructure was disclosed. It is documented here for threat-actor tracking and correlation with pr
Target sectors: government administration, police - law enforcement, health, education, manufacturing, transport, energy, privateindustry, legalservices
Target regions: North America, australia, Europe, russia, armenia, united states of america
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 17 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_ACTOR, MEDIUM, threat intelligence, cybersecurity, T1566.001, T1189, T1195, T1133, T1059.001, T1059.003, T1059.005, T1204.002, T1047, T1106