Cryptomixer was a cryptocurrency mixing service allegedly used to launder proceeds from cybercrime and other illicit activity. Active since at least 2016, it is believed to have processed very large volumes of cryptocurrency on behalf of ransomware operators, darknet market participants, and other criminal actors seeking to obscure transaction provenance and cash out illicit gains. Its service model relied on proprietary transaction-obfuscation mechanisms designed to break traceability between source and destination funds. Cryptomixer is associated with the financial enablement of cybercrime rather than direct network intrusion activity. High-confidence reporting links it to laundering proceeds from ransomware, payment card fraud, drug trafficking, and weapons trafficking. In late 2025, German and Swiss law enforcement, supported by Europol, disrupted the service and seized infrastructure, data, and cryptocurrency assets. Cryptomixer is best characterized as a cybercriminal financial facilitation service whose dominant role was enabling money laundering and post-compromise monetization for other threat actors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.