Rublevka Team is a Russian-speaking cybercriminal cryptocurrency theft operation active since 2023 that specializes in affiliate-driven wallet-draining fraud. The group is commonly described as a traffer team and operates a scalable scam-as-a-service model that lowers the barrier to entry for affiliates by providing turnkey tooling, automation, and operational support. Known aliases include rublevka and rublevka_team, with Rublevka Team being the most widely recognized name. The operation focuses on social engineering rather than traditional network intrusion. Its campaigns direct victims to spoofed cryptocurrency-themed landing pages that impersonate trusted brands, exchanges, wallets, token launches, giveaways, and airdrops. These pages prompt users to connect their wallets and sign malicious transactions, enabling theft of cryptocurrency assets. Rublevka Team initially targeted The Open Network ecosystem and later shifted heavily toward Solana, where its campaigns reportedly generated most of its known revenue. The group has been assessed as responsible for more than $10 million in stolen cryptocurrency. Rublevka Team provides affiliates with Telegram-based bots, landing-page generators, cloaking and filtering controls, hosting and domain options, automated notifications, and payout mechanisms. Its platform has been advertised as supporting more than 90 wallet types and multiple asset classes within the Solana ecosystem, including tokens, NFTs, and staked assets. The operation also uses evasion features such as white-page presentation, scanner discrimination, access restrictions based on geography or network characteristics, and rapid infrastructure rotation. The group maintains an organized affiliate ecosystem with private Telegram channels for chat, operational updates, landing-page distribution, and profit tracking. Reporting indicates it uses leaderboard-style performance tracking and high affiliate revenue shares, reflecting a mature cybercrime business model analogous to ransomware-as-a-service structures. Rublevka Team has also been associated with Russian-language underground forums including LolzTeam, with additional presence on Exploit and XSS. Rublevka Team is notable for using custom obfuscated JavaScript wallet-drainer logic embedded in phishing pages instead of relying primarily on infostealer malware. Its tradecraft emphasizes brand impersonation, wallet-specific social engineering, automation, and anti-detection measures. The group exemplifies the industrialization of Web3-focused financial cybercrime through reusable tooling, affiliate enablement, and service-based fraud operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates a highly automated scam-as-a-service platform focused on crypto wallet draining. Provides affiliates turnkey tooling (Telegram bots, landing page generators, cloaking, automated payout infrastructure) to run high-volume social-engineering campaigns that trick users into signing malicious transactions (airdrop/token-buy scams), with a pivot from TON to Solana driving most revenue.
Affiliate-driven cryptocurrency wallet-draining operation (since 2023) using spoofed landing pages and custom JavaScript to trick victims into connecting wallets and approving fraudulent transactions; provides automation via Telegram bots and landing-page generators.
Affiliate-driven cryptocurrency drainer operation ("cryptoscam"/traffer team) primarily active on LolzTeam with presence on Exploit and XSS. Initially ran fake crypto exchanges and TON-themed lures, then shifted (2024 onward) to a custom JavaScript wallet drainer embedded in landing pages impersonating token airdrops/giveaways and DeFi services; later pivoted to Solana (SOL) in 2025. Uses Telegram bots/channels for affiliate onboarding, landing-page generation, cloaking/"white pages" for evasion, and automated profit splitting; rotates domains and uses obfuscated JS (index.js) plus RPC services (Helius/WalletConnect/PublicNode) to execute draining transactions.
Affiliate-driven cryptocurrency drainer operation ("traffer"/cryptoscam team) advertising on underground forums and operating primarily via Telegram + LolzTeam. Uses custom obfuscated JavaScript wallet-drainer landing pages impersonating airdrops/giveaways and DeFi/crypto brands to trick victims into signing Solana transactions, draining SOL/SPL tokens/NFTs; provides bots, landing-page generator, cloaking/bypass features, and profit-splitting to affiliates.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.