TGR is a Russian-speaking transnational money-laundering network involved in moving illicit funds for cybercriminals, organized crime groups, sanctioned Russian elites, and other illicit actors. It has been publicly linked to large-scale laundering operations spanning more than 30 countries and to collaboration with the related Smart network. TGR has been described as providing cryptocurrency trading, foreign-exchange payment, and concierge-style financial services that enabled clients to obscure the origin of funds, move value across borders, and access restricted financial channels. The network has been associated with George Rossi, Elena Chirkinyan, and Andrejs Bradens, and with business structures operating from multiple jurisdictions including Russia, the United Kingdom, the United Arab Emirates, Thailand, and the United States. TGR used cross-border cash-for-cryptocurrency swaps, exchange deposit accounts, and wallets at venues with weak anti-money-laundering controls to launder proceeds. Its services allegedly supported sanctions evasion for Russian elites and facilitated laundering for organized crime groups, including actors tied to ransomware such as Ryuk. Authorities have also linked the broader Smart-TGR ecosystem to funding Russian espionage operations. TGR’s core role is financial enablement rather than direct intrusion activity. Its demonstrated capabilities center on exfiltration of criminal proceeds and post-exploitation support for other threat actors by converting, transferring, and concealing illicit funds after cybercrime or other criminal activity. The group is best characterized as a financially motivated criminal laundering service embedded in the Russian-speaking cybercrime ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian-speaking money laundering network that worked with Smart to move criminal proceeds through crypto-to-cash exchange services and support ransomware and espionage-linked activity.
Russian-speaking money laundering and financial facilitation network providing illicit financial services, including cryptocurrency trading, foreign exchange payments, concierge services, and sanctions evasion support for elites and criminal actors.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.