Russian Mafia Involvement in Cybercrime Operations

Explore top LinkedIn content from expert professionals.

  • View profile for Alexander Leslie

    National Security, Defense & Cyber Intelligence | Senior Advisor, Recorded Future | Government Affairs, Strategic Communications & Executive Engagement | Cybercrime, Espionage & Influence Operations

    12,790 followers

    🚨 🇷🇺 - New Recorded Future Insikt Group report! I’m very excited and proud to unveil the third iteration of our landmark Dark Covenant series — examining the evolving relationship between the Russian state and cybercriminal underground. This is an important read, and a long time coming. Please read and share with your networks! Russia is no longer merely a safe haven for cybercrime — it now operates a managed market in which protection and punishment depend on political utility to the Kremlin. Following the multinational Operation Endgame campaign, Russian authorities staged a series of high-profile arrests and seizures. But our report makes clear that these actions are less about enforcement and more about optics. Moscow’s response reflects a politics of protection: expendable enablers are sacrificed to deflect Western pressure, while ransomware ecosystems with intelligence or geopolitical value remain untouched, even insulated. Leaked communications show coordination between criminal leaders and Russian intelligence intermediaries, as well as bribery, tasking, and mutual exchange of information. The result is a cyber underworld increasingly fractured by paranoia. Affiliates accuse operators of theft, betrayal, and impersonation, while recruitment networks have shifted from open advertisement to tightly vetted, Russian-speaking circles. Deposits and collateral have replaced reputation as the currency of trust. Ransomware groups now decentralize infrastructure, adopt stricter operational security, and move to decentralized communication platforms to mitigate infiltration risks. Yet despite this turmoil, ransomware remains profitable and strategically useful — serving as a tool of state influence, intelligence collection, and economic coercion. What emerges is a portrait of an ecosystem under control but not dismantled. Russian law enforcement selectively enforces the law to maintain equilibrium — detaining cybercriminals when politically necessary, releasing them when convenient, and even using some as assets in prisoner exchanges. Dark Covenant 3.0 underscores that Russian cybercrime cannot be understood in isolation from the state. It is both a profit-driven economy and a tool of foreign policy — an auxiliary intelligence resource, an influence vector, and a means of signaling resilience under sanctions. Western policymakers must therefore treat cybercrime as part of the broader Russian strategic toolkit, not a law enforcement nuisance. Countering this “controlled impunity” will require sustained transparency, coordination, and offensive cyber deterrence — not only to disrupt infrastructure, but to expose the networks of protection, patronage, and coercion that allow them to endure. Moscow’s fusion of statecraft and cybercrime represents one of the clearest examples of how authoritarian regimes weaponize criminality as a pillar of hybrid power.

  • View profile for Marie-Doha Besancenot

    Senior advisor for Strategic Communications, Cabinet of 🇫🇷 Foreign Minister; #IHEDN, 78e PolDef

    42,175 followers

    🇷🇺 🗞️ How Russia selectively controls the impunity enjoyed by Cybercriminals: an enlightening report issued this week by INSIKT Group / Recorded Future, documenting how the Russian cyber-criminal ecosystem shifted from broad tolerance to managed control. 🔎 Research from May 2024–Sept 2025 using data from dark-web forums, leaked chats, public enforcement.. It sheds light on Operation Endgame, a multinational takedown effort from May 2024 & shows how it changed ground dynamics 🔹It targeted loaders, enablers, money-mules and infrastructure 🔹The actions signalled to the ecosystem: the cost-benefit calculus for operating from/within Russia has shifted; enforcement is not zero-risk. 🔹The selective pressure triggered changes in the underground: fragmentation, tighter vetting, paranoia, evolving ransomware TTPs, group rivalries, payment/target strategies 🔹The “politics of protection” = enforcement or lack thereof signals which actors are expendable and which are strategically useful. Take-aways 1️⃣ A managed market 🔹 🇷🇺cyber-criminal ecosystem has evolved from near-blanket tolerance toward selective State management: actors with little strategic value are targeted, those providing intelligence, geopolitical leverage & state utility are insulated. 🔹protection no longer depends on location. 🔹Direct, task-level coordination between cyber-criminal leadership and Russian intelligence. In addition, the“Dark Covenant” model (direct, indirect, tacit links) remains operative. 2️⃣ Underground ecosystem adapts 🔹Affiliates are less visible; open-call RaaS (ransomware-as-a-service) programs declined in public forums 🔹Operators have heightened vetting: deposits, KYC-lite checks, stricter inactivity rules. 🔹Business rules: some ransomware programs explicitly exclude nonprofits, healthcare, government entities; minimum ransom demands; anti-collision rules. These act as both reputational hedges and political boundary markers. 🔹Impersonator groups proliferate: façade ransomware groups or “scam” groups trying to ride brand equity = erodes trust & raises barriers to entry. 🔹Forum discussions show increased emphasis on OPSEC: moving to decentralized communication: burner phones, hidden volumes.. 3️⃣ Enforcement signals / “politics of protection” • Russian authorities have taken visible action against certain monetisation/enabler nodes (e.g., Cryptex, UAPS) • By contrast, core high-value ransomware groups (Conti, Trickbot) have avoided this= insulation via state-links. 4️⃣ Cyber-criminal groups are increasingly embedded in Russia’s geopolitical strategy 🔹 arrests, releases, negotiations align with diplomatic cycles, prisoner exchanges. 🔹Cyber-crime = a hybrid instrument of state influence, intelligence gathering, plausible deniability & leverage. ➡️ defenders should understand the state-criminal bargain 🔹Disruption strategies need to target also the enablers (cash-out, money-laundering, hosting) 📰 ☕️ enjoy the weekend read!

  • View profile for Zach Edwards

    threat researcher | privacy & ad tech expert

    5,215 followers

    Our team at Silent Push have released a monster research piece today about a new malware strain we’re calling CountLoader which is apparently being used by an Initial Access Broker or ransomware affiliate who has connections to several of the most serious Russian ransomware gangs including LockBit, BlackBasta, and Qilin. The new malware has 3 unique versions coded in .NET, PowerShell, and JScript. This type of effort is typically only seen with threat actors who are building something long-term, aka, this could be a strain of malware seen in future Russian attacks against potentially a wide range of organizations who are part of their typical targeting. CountLoader was recently used in a PDF-based phishing lure targeting individuals in Ukraine, in a campaign that impersonated the Ukrainian police.   This malware was first written about by Kaspersky, who discovered a portion of the operation in 2025. However, they were only able to identify the PowerShell version, which at the time utilized a “DeepSeek” AI phishing lure to trick users into downloading and executing it. Our team identified indications of several additional unique campaigns utilizing various other lures and targeting methods, including a .NET version of CountLoader, which was named twitter1[.]exe. Our analysis has observed CountLoader dropping several malware agents, like CobaltStrike and AdaptixC2. Technical evidence obtained from within these samples allowed our team to make the connection between the agents dropped by CountLoader and the malware agents observed in several ransomware attacks. Based on this observation, we assess with medium-high confidence that CountLoader is being used either as part of the toolset of an IAB or by a ransomware affiliate with ties to the LockBit, BlackBasta, and Qilin ransomware groups. We also discovered that the loader’s primary code loop attempts a connection to many different C2s, retrying up to a million times. This iterative counting feature is primarily why we’ve called the threat CountLoader. For defenders trying to track this threat, we’ve provided a wide range of details and how to track the different versions of the malware.   Based on the diversity of the lures currently seen (Ukraine police phishing lure, a fake DeepSeek AI app, an executable referencing Twitter) it seems incredibly likely that there are other malicious versions or will be sometime soon. And with the connections to three of the most serious Russian ransomware gangs, the impacts from ignoring this threat could be substantial. Research link and some news coverage in the comments!  

  • View profile for Ari Redbord

    Global Head of Policy and Government Affairs at TRM Labs

    34,537 followers

    Yesterday, attackers exploited wallet infrastructure associated with the Russian-linked exchange Grinex, extracting approximately $15 million in digital assets and initiating a rapid series of transactions that TRM Labs analysis shows moved through dozens of intermediary addresses within minutes. The initial outflows fragmented across multiple wallets before consolidating into a core cluster of fewer than ten primary addresses, followed by cross-chain bridging and a concentration of funds into TRON-based assets, a pattern consistent with high-liquidity routing and commonly observed in large-scale laundering operations. Grinex halted trading and withdrawals shortly after detection, while parallel exposure emerged through Tokenspot, where overlapping address interactions indicate shared flow pathways across the same network. TRM Labs tracing identifies that the initial exploit targeted hot wallet infrastructure, with funds exiting through at least 25–30 distinct transactions in the first phase, followed by secondary layering across more than 100 unique addresses designed to obfuscate origin before consolidation, with timing intervals between hops often measured in seconds, reflecting automated execution. Grinex operates as a direct successor to Garantex, the sanctioned Russian exchange disrupted in March 2025, and TRM data shows clear continuity between the two platforms, including wallet clusters, transaction counterparties, and liquidity patterns, with previously identified Garantex-linked addresses interacting directly with Grinex infrastructure following its launch. The platform incorporates A7A5, a ruble-denominated stablecoin used for settlement, which TRM has observed moving across exchange-linked wallets and intermediary services to maintain ruble exposure while enabling cross-border transfers outside traditional financial channels. Since its emergence, Grinex has processed billions in cryptocurrency transactions, with TRM analysis identifying exposure to ransomware proceeds, darknet market activity, and sanctioned entity flows, and transaction typologies consistently show multi-hop layering, rapid consolidation, and use of high-liquidity networks to absorb volume. The flow of funds in yesterday’s incident followed that same structure, with fragmentation, cross-chain movement, and re-aggregation into wallets positioned for further distribution or off-ramping. Tokenspot’s role reflects how exchanges in emerging regulatory environments integrate into these flows, with TRM identifying repeated interactions between Tokenspot-linked wallets and high-risk clusters, enabling routing, conversion, and liquidity extension across jurisdictions, and reinforcing a networked system where exchanges, tokens, and blockchain infrastructure operate together to facilitate movement of value at scale. TRM will continue to monitor the movement of funds from this theft.

  • View profile for Yelisey Bohuslavskiy

    RedSense Partner & AdvIntel Co-Founder | I obtain access to adversarial infra to warn & prevent cyberattacks before they happen

    22,964 followers

    New Chapter in #REvil Trial 🏛️⚖️ New details on REvil operations have been revealed by Russian "courts" - or whatever you call the mockery of a judicial system they have there. Apparently, the "trial" against eight members of REvil is close to the conclusion. Unsurprisingly, since it is Russia, they are only accused of carding and fraud, as if their #ransomware activity never existed. Funny enough, the closing arguments in the trial will take place at the Saint Petersburg Garrison Military Court because one of the defendants was a military serviceman at the time of the alleged crime. The defense claims that during REvil carding operations, no specific harm was done. 🤷♂️🤷♂️ However, even with this fake justice, new information about REvil's structure and operations emerged, especially in relation to some of their most significant attacks. 📍 Colonial Pipeline The Russians claim that Daniiil Puzyrevsky is the group's leader and the primary beneficiary of the Colonial Pipeline attack, for which he allegedly received 85% of the ransom - 63.7 BTC (~$2,359,000). Possibly, he didn't want to share with the handlers from the government, which led to predictable consequences. 📍 Tesla Reportedly, in the summer of 2020, another key REvil associate, Alexei Skorobogatov, asked Yegor Kryuchkov if he knew anyone at major foreign companies. Kryuchkov mentioned a Tesla engineer, Dmitry Volkov. Skorobogatov offered Kryuchkov $500,000 to have Volkov install malware at Tesla. Kryuchkov flew to the U.S. and met Volkov, who demanded $1 million but then reported the plot to U.S. authorities. The FBI arrested Kryuchkov, who was later deported after serving a 10-month sentence. He then testified against REvil in Russia. 🕵️ Larger REvil Network Even after the 2021 disbandment, REvil profoundly impacted the Russian-speaking cybercrime and ransomware landscape. It is known that core REvil pentesters are behind the #BlackBasta group leadership, even though this group is a post-Conti derivative. Royal/BlackSuit has a designated elite team for Big Game hunting consisting of former REvil members. Finally, Royal leadership claims that many top REvil pentesters, after the government crackdown, volunteered to collaborate with Yevgeny Prigozhin's business empire in 2022. After his failed coup, many were allegedly transferred to other government-affiliated services.

  • View profile for Isabella Chase

    Head of Policy EMEA @ TRM Labs | Crypto Policy & Illicit Finance | Blockchain Intelligence for Regulators & Compliance

    7,532 followers

    🚨New TRM Labs Report 🚨 Out now, ‘Comrades in Crime - Exploring the Russian-speaking Illicit Crypto Ecosystem is out now 📥 Russian language entities play an outsized role in most types of crypto-enabled cybercrime, leading in: 🦠 Ransomware: Russian-speaking ransomware groups accounted for at least 69% of all crypto proceeds from ransomware in 2023, exceeding USD 500 million 🛒 Darknet markets: Russian-language darknet markets comprised 95% of all crypto-denominated illicit drug sales on the dark web in 2023 🌐 Sanctions: Inflows to just one Russia-based crypto exchange, Garantex, accounted for 82% of crypto volumes belonging to all sanctioned entities internationally But the finding that stood out to me the most is that “since 2021, at least $85 million has been sent to wallets linked to both Russian and Chinese entities involved in the manufacturing, transport, and sale of military and dual use equipment and critical components.” Download link in the comments👇 #illicitfinance #moneylaundering 

  • View profile for Andy Jenkinson - WHITETHORN SHIELD

    Fellow Cyber Theory Institute. Director Fintech (FITCA). NAMED AN EXPERT IN INTERNET ASSET & DNS VULNERABILITIES AND THREAT INTELLIGENCE. IF I REACH OUT TO YOU - CHANCES ARE YOU HAVE A PROBLEM...

    39,707 followers

    Cryptomus: A Canadian-Registered Entity at the Heart of Russian Cybercrime Payment Processing. Recent revelations by cybersecurity journalist Brian Krebs expose Cryptomus, a financial firm registered in Canada, as a payment processor for numerous Russian cryptocurrency exchanges and cybercrime services targeting Russian-speaking customers. This startling discovery highlights severe lapses in regulatory oversight and the troubling role of technology providers like Cloudflare in enabling these activities. Investigations into the Vancouver address listed by Cryptomus reveal a façade. The location is purportedly home to dozens of cryptocurrency exchanges, money transfer services, and foreign currency dealers—none of which physically operate from there. Instead, this address serves as a veneer of legitimacy for entities tied to illicit activities. Cryptomus and many similar questionable financial entities rely on Cloudflare’s infrastructure. Our research indicates systemic vulnerabilities, including DNS misconfigurations, deprecated PKI protocols, and exposed servers. These flaws leave Cloudflare-hosted services—including those of Cryptomus—ripe for exploitation. Alarmingly, some of these protocols, such as those tied to the outdated RFC 2246, were deprecated over 16 years ago, yet continue to be used by Cloudflare and facilitates cybercrime. The truly concerning aspect is the dual role of Cloudflare. Despite previously being implicated in hosting ransomware domains like Maze, it remains the U.S. and UK's chosen provider for protective DNS services. This paradox underscores Canada’s regulatory failure to scrutinize entities like Cryptomus, which exploit its jurisdiction to aid sanctioned Russian banks and cybercriminals. This case demands urgent attention to address the systemic gaps enabling financial crime and cybercriminal enterprises. Cybersec Innovation Partners For the full KrebsOnSecurity article: https://lnkd.in/e_XNp_-2

  • View profile for Sean O'Connor

    Cybersecurity Leader | Veteran | Board Advisor | Author | Speaker

    28,453 followers

    Recorded Future investigates how Russia’s intelligence services maintain controlled impunity over cybercriminal groups, identifying direct links, indirect affiliations, and tacit agreements that provide plausible deniability while supporting state objectives. Blog: https://lnkd.in/eAdzpAUZ PDF: https://lnkd.in/eFTDTvbB #RecordedFuture #cyber #threatintelligence #infosec #CTI #Russia #cybercrime #espionage #DarkCovenant

Explore categories