A Russian-linked money laundering network acquired a controlling stake in Keremet Bank in Kyrgyzstan, using it to launder proceeds from UK-based drug, firearms, and immigration crimes, and to facilitate sanctions evasion for Russia’s military-industrial complex. The UK’s National Crime Agency (NCA), through Operation Destabilise, uncovered that the network—operated by the SMART and TGR groups—converted illicit cash into cryptocurrency, which was then funneled through Keremet Bank. This bank was later identified as providing cross-border payment services for Promsvyazbank (PSB), a Russian state-owned lender supporting the war in Ukraine. The laundering operation connected street-level criminal activity in the UK to Russian state interests, with the NCA and international partners seizing millions in cash and cryptocurrency as part of the investigation.
Investigators also linked the laundering network to a spy ring of Bulgarian nationals, run by Jan Marsalek, who were convicted for surveilling targets on behalf of Russian intelligence. The NCA’s findings revealed that Keremet Bank enabled PSB to bypass Western sanctions, allowing the Russian defense sector to acquire restricted components for the war effort. The operation demonstrates a direct financial pipeline from UK criminal proceeds to Russian state-sponsored activities, highlighting the global reach and complexity of modern money laundering schemes supporting sanctioned entities.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting said proceeds from UK drug trafficking were funneled through the bank and connected the institution to Russian spy services and the military, expanding the known scope of the bank's alleged use beyond cybercrime proceeds. This represents the public disclosure of the bank's role in laundering multiple criminal revenue streams.
The referenced reporting indicates that Russia-linked cybercriminal and drug-trafficking networks purchased or took control of a bank allegedly tied to Russian military and intelligence interests in order to move and launder illicit funds. The acquisition appears to be the central real-world development described across both sources.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.