A7 is a Russia-linked sanctions-evasion network composed of companies, exchanges, and associated individuals that has been used to move value into the Russian economy through cryptocurrency infrastructure. It is closely associated with the ruble-backed A7A5 stablecoin, which was issued in Kyrgyzstan, and has been identified by European and U.K. authorities as supporting Russian interests and helping bypass international sanctions imposed over Russia’s war against Ukraine. The network has been described as cross-border and has included links extending into Africa. A7 emerged as a significant node in Russia-associated crypto finance after the March 2025 disruption of Garantex. Authorities and blockchain intelligence reporting indicate that activity displaced by the Garantex takedown shifted into successor infrastructure tied to A7 and related exchanges. The network has been linked to very large transaction volumes and to services provided by multiple exchanges and financial intermediaries with Russian ties. Operationally, A7 is associated with sanctions evasion, movement of funds through crypto-asset service providers, and use of stablecoin-based settlement rails. Its ecosystem has included entities designated by the U.K. and EU for supporting the Russian financial sector, making funds or economic resources available to sanctioned interests, or otherwise facilitating transactions connected to Russia. Reporting also links the network to rapid wallet rotation and multi-chain operations, complicating static sanctions enforcement and requiring blockchain tracing to follow successor flows. A7’s dominant role is financial support to sanctioned Russian interests rather than conventional intrusion activity. Available high-confidence reporting supports its characterization as a crypto-enabled sanctions-evasion and financial facilitation network tied to Russia’s wartime economy.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A sanctions evasion network tied to Russian interests that uses a set of entities, exchanges, and a ruble-pegged stablecoin to move financial flows and absorb activity displaced by prior enforcement actions.
A network of companies and individuals allegedly supporting the Russian regime by using cryptocurrency transfers and stablecoin infrastructure to bypass international trade blockades and sanctions, including support tied to Russia’s war in Ukraine.
Russia-associated sanctions-linked cryptocurrency network driving increased illicit on-chain volumes; associated with the A7A5 stablecoin and activity surfaced via improved attribution/intelligence sharing.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.