Reporting highlighted Coinbase Cartel, a newer extortion actor that prioritizes data exfiltration without encryption (“data-theft-first” extortion). The group is described as emerging in 2025 and rapidly scaling victim claims, with healthcare, technology, and transportation comprising a large share of targets; coverage also notes a notable concentration of victims in UAE healthcare. Initial access is attributed primarily to social engineering and the use of initial access brokers and exposed/underground-sourced credentials, followed by use of administrative accounts and log tampering to reduce detection.
Separate threat research detailed the Rublevka Team, a Russian cybercrime operation running a highly automated “scam-as-a-service” platform used to drain cryptocurrency wallets, with reported thefts exceeding $10M since 2023. The operation is characterized as affiliate-driven and Telegram-bot-enabled, providing landing-page generators, cloaking, and payout automation; campaigns commonly impersonate brands (e.g., Phantom, Jito, Bitget) and pivoted from TON to Solana, with a major campaign reportedly generating most of the revenue. A third article provided broad, industry-level ransomware targeting statistics for 2025 (e.g., manufacturing as the most-targeted sector) and examples of past incidents, but it did not materially add to either the Coinbase Cartel extortion reporting or the Rublevka crypto-drainer activity.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
Insikt Group at Recorded Future reported that Rublevka Team had stolen more than $10 million in cryptocurrency since 2023. The report said the latest Solana-focused campaign generated about $8.2 million of that total.
Within its first months of operation, Coinbase Cartel claimed more than 60 victims across multiple sectors, with healthcare, technology, and transportation making up over half of the total and UAE healthcare notably affected.
Bitdefender also ranked Coinbase Cartel among the top 10 ransomware groups in December 2025, showing the group's continued prominence after its emergence.
Bitdefender assessed Coinbase Cartel as a top-10 ransomware group in September 2025, reflecting the group's rapid rise despite using extortion without encryption.
During its first month of activity, Coinbase Cartel claimed 14 victims, indicating a rapid early expansion of its extortion operations.
The Coinbase Cartel threat actor emerged in September 2025, using a data-theft-only extortion model rather than encrypting victim systems. The group relied on social engineering, exposed credentials, and initial access brokers to compromise organizations.
After initially targeting TON, Rublevka Team shifted its scam infrastructure to Solana, where its drainer tooling reportedly supported more than 90 wallet types and used fake airdrop or token-purchase lures.
In the earlier phase of its operation, Rublevka Team focused its wallet-draining fraud on The Open Network (TON) ecosystem before later shifting to other chains.
Recorded Future said the Russia-linked Rublevka Team has been stealing cryptocurrency since 2023 through a highly automated scam-as-a-service model using social engineering, malicious landing pages, and Telegram-based tooling.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.