The Russian cybercriminal ecosystem refers here to Russia-based criminal operators and supporting financial infrastructure implicated in monetizing cryptocurrency stolen from cracked LastPass vaults following the 2022 breach. According to the provided content, TRM Labs identified repeated use of Russian cybercrime infrastructure, continuity of wallet control, and consistent on-chain patterns linking laundering activity to Russia-based operators. The activity involved theft of cryptocurrency from decrypted vault data, conversion of stolen assets to Bitcoin, use of Wasabi Wallet for mixing in 2024–2025, and off-ramping through high-risk Russian exchanges including Cryptex and Audi6. The content states that more than $28 million in crypto was traced as stolen and laundered through this infrastructure. The original intrusion is not definitively attributed in the provided material, but the monetization and laundering pipeline is described as likely involving Russian criminal actors. More broadly, the content characterizes Russian exchanges and laundering services as critical off-ramps for cybercriminal networks, ransomware groups, and sanctions evaders, and highlights the systemic role of Russia-based financial infrastructure in enabling global cybercrime. No additional aliases or sub-groups are provided beyond the name used in the content.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.