Smart is a Russian-speaking criminal financial facilitation and money-laundering network disrupted in 2024 during Operation Destabilise. It operated alongside the TGR network and provided illicit financial services to organized crime groups, cybercriminals, sanctioned Russian elites, and other illicit actors. The network is associated with large-scale laundering of cash and cryptocurrency, cross-border cash-for-crypto swaps, and the movement of criminal proceeds through international controllers, couriers, and exchange infrastructure with weak anti-money-laundering controls. Smart has been linked to laundering for multiple criminal constituencies, including the Kinahan cartel and ransomware actors such as Ryuk. It also enabled sanctions evasion for Russian elites and designated persons by helping move funds into otherwise restricted financial channels. U.K. authorities further stated that Smart directly funded Russian espionage operations between late 2022 and summer 2023, indicating overlap between organized crime financial services and state-linked intelligence activity. A prominent figure associated with Smart is Ekaterina Zhdanova, previously sanctioned for laundering large volumes of cryptocurrency for Russian elites and criminal syndicates. Reporting has linked her operations with associates including Khadzhi Murat Dalgatovich Magomedov and Nikita Vladimirovich Krasnov. Smart-linked facilitators also helped clients obtain overseas tax residency, identification documents, and bank accounts to support the movement and concealment of illicit funds. The network’s demonstrated capabilities center on financial obfuscation, sanctions evasion support, and post-compromise monetization rather than direct intrusion activity. Its role in servicing ransomware proceeds and broader criminal ecosystems makes it a significant enabler of cybercrime and other transnational illicit operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian-speaking money laundering network involved in exchanging cryptocurrency for cash and vice versa, supporting organized crime, ransomware groups, and Russian espionage operations.
Russian-speaking money laundering and financial facilitation network that laundered funds for criminal groups and Russian elites, helped evade sanctions, exchanged cash and cryptocurrency across borders, and directly funded Russian espionage operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.