QQAAZZ is a transnational cybercrime-linked money laundering organization that has operated since at least 2016 as a cash-out and laundering service for other criminal actors. The group is known for laundering proceeds from computer fraud and banking theft, including funds associated with major crimeware ecosystems such as TrickBot, Dridex, and GozNym. It advertised itself on Russian-speaking cybercriminal forums as a global bank-drops service and functioned as a financial enablement layer for malware operators rather than as a primary malware developer. QQAAZZ used shell companies, fraudulent and legitimate identity documents, and hundreds of corporate and personal bank accounts to receive and move stolen funds through the banking system. The organization transferred money among accounts under its control and also converted proceeds into cryptocurrency while using tumbling services to obscure fund flows. Reporting indicates the group retained a substantial percentage of stolen proceeds as fees before returning the remainder to its cybercriminal clients. The organization had a multilayered membership structure spanning multiple countries in Europe and Eurasia, with members and defendants identified from Latvia, Georgia, Bulgaria, Romania, Belgium, and Russia among others. Law enforcement actions tied to the group included coordinated searches, arrests, and parallel prosecutions across several countries. QQAAZZ is best characterized as a financially motivated criminal laundering network that enabled post-compromise monetization for banking trojan and broader cybercrime operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cash-out network used by the RM3/Global Network group to launder proceeds from banking fraud.
A criminal group that materially supported Trickbot by laundering funds stolen from victims' bank accounts.
Transnational criminal money-laundering network that provided 'global, complicit bank drops service' to cybercriminals, laundering stolen funds through shell companies, hundreds of bank accounts, inter-account transfers, and cryptocurrency tumbling services.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.