A7 is a Russia-associated network described by the U.K. government as a group of companies and individuals supporting the Russian regime through cryptocurrency transfers and helping Russia bypass international trade restrictions. The U.K. sanctions package stated that the A7 network claimed to have moved $90 billion into Russia’s economy in the previous year. Supporting content links A7 closely to the ruble-backed A7A5 stablecoin, issued in Kyrgyzstan and circulating on Ethereum and TRON. In May 2025, the U.K. sanctioned A7 LLC, a Russian company that supports A7A5, for supporting Russia’s war in Ukraine, and later expanded sanctions to additional companies connected to A7 and A7A5. TRM Labs also identified A7 and A7A5 as major drivers of sanctions-linked crypto activity associated with Russia. The content further states that exchanges and entities with Russian ties, including HTX, Grinex, and Garantex-linked exposure, provided services or trading infrastructure connected to the A7 network. No additional aliases or sub-groups beyond A7 and the related entity A7 LLC are directly provided in the content.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A network of companies and individuals allegedly supporting the Russian regime by using cryptocurrency transfers and stablecoin infrastructure to bypass international trade blockades and sanctions, including support tied to Russia’s war in Ukraine.
Russia-associated sanctions-linked cryptocurrency network driving increased illicit on-chain volumes; associated with the A7A5 stablecoin and activity surfaced via improved attribution/intelligence sharing.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.