New reporting highlighted the growing role of cryptocurrency in sanctions evasion and illicit finance, with 2025 seeing a sharp increase in value received by sanctioned entities and record illicit transaction volume. Chainalysis reported a 694% surge in value received by sanctioned entities and described nation-state integration of crypto into national financial infrastructure, including Iranian state-linked activity (with IRGC/proxy networks accounting for over half of value received in Q4 2025) and Russia-linked sanctions workarounds such as the ruble-backed A7A5 stablecoin, which processed $93.3B in under a year. The same reporting noted sanctions against exchanges Grinex and Meer for facilitating A7A5-related activity, and assessed that North Korea stole over $2B in crypto in 2025, with proceeds reportedly supporting the regime’s WMD program; it also pointed to sanctions targeting Southeast Asian scam facilitators tied to “pig butchering” operations.
Separate analysis of Iran’s crypto ecosystem described Nobitex as a major on/off-ramp with >$5B in observed volume since 2025 and extensive exposure to sanctioned and high-risk counterparties. TRM Labs said post–Feb. 28 US-Israeli strikes activity (including >$35M moved to cold storage) appeared consistent with operational liquidity management rather than user capital flight, and it detailed how a June 2025 breach (~$90M loss) revealed a multi-tier custody architecture (hot/warm/cold wallets) and controls for high-value or politically connected clients, alongside structures intended to mitigate sanctions constraints; TRM also observed ~$2.7M consolidated from dormant mining-linked wallets after the breach, suggesting reserve mobilization to restore liquidity. Other items in the set—an Europol-backed takedown of a gambling-fraud money-laundering ring exploiting Ukrainian women and a US guilty plea by an alleged Phobos ransomware administrator—concern cyber-enabled crime but do not materially address the same crypto-sanctions focus, while a TRM post about legislative testimony is primarily an event write-up rather than incident-specific intelligence.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
18 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-28, the U.S. Treasury Department froze more than $344 million in cryptocurrency tied to Iran as part of Operation Economic Fury and the broader maximum-pressure campaign. Officials said the move targeted digital-asset channels linked to sanctions evasion, weapons procurement, and other Iranian revenue streams.
On 2026-04-24, the European Union adopted sanctions restricting exports of CNC machines and radio equipment to Kyrgyzstan, citing a high risk of re-export to Russia for missile and drone production. The move marked the first direct country-level EU trade restrictions on Kyrgyzstan after consultations with Bishkek failed to halt the flow of sensitive goods.
On 2026-04-23, a cross-party group of 26 British MPs called on the U.K. government to sanction senior Kyrgyz officials for allegedly enabling the ruble-pegged cryptocurrency A7A5 to operate from Kyrgyzstan and support Russian sanctions evasion. The lawmakers warned that broader sectoral sanctions on Kyrgyzstan could follow if the alleged complicity continues.
By April 2026, reporting indicated Iran was accepting cryptocurrency payments, including bitcoin and reportedly USD-pegged stablecoins, from cargo ships transiting the Strait of Hormuz. Analysts cited this as a new extension of Iran's sanctions-evasion trade network, linking maritime commerce to IRGC-associated crypto and stablecoin use.
In a report published on March 30, 2026, Chainalysis said cryptocurrency was being used to finance drone procurement by Russian and Iranian-linked actors. It highlighted more than $8.3 million raised by pro-Russia groups since 2022, repeated wallet payments tied to sanctioned drone maker KB Vostok, and Iranian-linked flows from Nobitex, IRGC-associated wallets, and sanctioned facilitator Alireza Derakhshan to drone-part suppliers.
In a report published on March 26, 2026, 38 North described how DPRK-linked actors including Lazarus launder stolen cryptocurrency through OTC brokers, exchanges, P2P platforms, and facilitators across multiple countries. The analysis also warned that North Korea is increasingly exploring direct use of cryptocurrency, especially USDT, to pay for sanctioned goods and weapons-related procurement, reducing reliance on traditional cash-out channels.
In its March 2026 report, Chainalysis said multiple nation-states had integrated blockchain and stablecoins into national financial infrastructure for sanctions evasion, procurement, and cyber operations, highlighting Iran, Russia, and North Korea.
By March 2026, TRM observed Nobitex consolidating about $2.7 million from more than 100 previously dormant mining-linked wallets, with funds traced largely to EMCD and ViaBTC. The activity suggested reserve mobilization to restore liquidity as services resumed after the June 2025 breach.
After the February 28 US-Israeli strikes, TRM observed increased on-chain activity at Nobitex, including transfers exceeding $35 million to cold storage. TRM assessed these movements as routine internal liquidity management rather than user-driven capital flight.
During 2025, Kyrgyzstan's licensed virtual asset service providers processed an estimated $20.5 billion to $32 billion in turnover, far exceeding the country's GDP. Reporting and blockchain analytics cited in the article indicated some Kyrgyz-licensed entities handled transaction patterns consistent with sanctions-evasion pipelines, especially fiat-to-USDT conversion for cross-border payments involving Russia, Central Asia, and China.
In 2025, sanctioned entities received about $104 billion in cryptocurrency, driving a broader 162% year-over-year rise in illicit-address inflows to at least $154 billion.
Across 2025, North Korea reportedly stole over $2 billion in cryptocurrency, with proceeds allegedly supporting the regime's weapons of mass destruction program.
During 2025, IRGC-linked networks moved more than $3 billion in cryptocurrency to support proxy activity and procurement, reflecting increasing state dominance over Iran's crypto ecosystem.
By the fourth quarter of 2025, IRGC-linked networks were responsible for more than half of the value received by Iranian entities, underscoring the state's growing control over the sector.
On 2025-08-20, the UK sanctioned Kyrgyzstan-based Capital Bank and its director, along with the Grinex and Meer exchanges and entities tied to the rouble-backed A7A5 token, alleging they were used by Russia to circumvent sanctions. The UK said these Kyrgyz financial and crypto networks helped facilitate payments for military goods and cited $9.3 billion moved through A7A5 infrastructure in four months.
In June 2025, the Israel-linked group Predatory Sparrow reportedly breached Nobitex, causing roughly $90 million in losses. The incident also exposed internal code and documentation describing the exchange's custody architecture and transaction-routing logic.
In March 2025, OFAC delisted Tornado Cash following a court ruling concerning autonomous smart contracts, marking a notable sanctions enforcement change in the crypto sector.
Since 2019, Nobitex has processed tens of billions of dollars and developed into Iran's primary cryptocurrency on- and off-ramp, making it central to the country's financial ecosystem under sanctions pressure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
timesca.com
Open sourcefoxbusiness.com
Open sourceoccrp.org
Open sourceoccrp.org
Open source38north.org
Open sourcechainalysis.com
Open sourcetrmlabs.com
Open sourcegov.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.