AudiA6 was an industrial-scale cryptocurrency laundering service that functioned as a financial enabler for ransomware operators, cryptocurrency thieves, darknet-market actors, and other cybercriminal networks. Active since at least 2021, it was used to obscure the origin of illicit digital assets and return cleaned funds to customers through rapid, complex transaction chains spanning multiple wallets, exchanges, and laundering intermediaries. Investigators linked the service to more than 15 investigations involving ransomware activity and large-scale cryptocurrency theft. AudiA6 marketed anonymity, speed, and cash-out capability to criminal customers and reportedly charged commissions in the low single-digit to low double-digit range. The operation relied on thousands of fraudulent exchange accounts and more than 6,000 KYC records associated with money-mule infrastructure, including accounts created with stolen or purchased identities. Investigators also assessed that the same operators likely managed Dark2Web, a cybercrime forum used to advertise illicit services and connect threat actors. The organization has been tied to senior members of Ukrainian and Russian nationality operating from Georgia, and law-enforcement action in 2026 disrupted its infrastructure, seized assets, and led to arrests of alleged administrators. AudiA6 is best characterized as a cybercrime support service rather than an intrusion operator: its core role was laundering criminal proceeds and sustaining the ransomware ecosystem by enabling cash-out, concealment of fund provenance, and financial obfuscation for other threat actors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operated as a professional cryptocurrency laundering service and central financial enabler for ransomware actors and other cybercriminal networks, processing illicit funds and returning cleaned cryptocurrency through rapid, complex transaction chains.
Industrial-scale cryptocurrency laundering operation used by ransomware actors and cybercriminal networks to wash illicit proceeds through fraudulent exchange accounts, mule wallets, and complex transaction chains.
A cryptocurrency money laundering organization and service allegedly responsible for laundering more than $389 million in cryptocurrency and advertising concealment of criminally sourced funds via the Dark2Web cybercrime forum.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.