Cryptex is a Russia-linked cryptocurrency exchange and money-movement platform associated with cybercriminal laundering activity. It has been identified as a financial facilitation service used to receive and process proceeds from cybercrime, including ransomware payments and cryptocurrency stolen in intrusion-related thefts. In 2024, Cryptex was sanctioned by the U.S. Treasury Department's Office of Foreign Assets Control for facilitating ransomware payments. Cryptex is associated with the laundering of illicit cryptocurrency through layered transfer chains that included privacy-enhancing services before funds were routed to Russian exchanges. Reporting has linked it to the handling of stolen funds derived from long-running wallet theft activity connected to compromised password vault data, as well as broader cybercriminal money-laundering ecosystems. Cryptex has also been discussed alongside other Russian financial cybercrime services in the context of Russian law-enforcement action against money-laundering infrastructure. Cryptex is best characterized not as an intrusion operator or malware crew, but as a cybercriminal financial enabler that supports post-compromise monetization. Its role is tied to the movement, laundering, and cash-out of illicit proceeds rather than direct network intrusion, espionage, or destructive operations. The dominant motivation is financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian cryptocurrency exchange involved in laundering stolen cryptocurrency from the LastPass breach, facilitating ransomware payments and serving as a key node in cybercriminal money laundering operations.
Described as a money-movement cybercrime platform whose operators were targeted by authorities, contrasted with ransomware groups in how Russia treats different cybercrime ecosystems.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.