The UK imposed a new sanctions package targeting Russia’s sanctions-evasion infrastructure, naming 18 entities and individuals tied to crypto-enabled finance, the Kremlin-backed A7 network, and a Kyrgyz bank suspected of facilitating payments for Russia’s war economy. The measures also designated Huobi Global S.A., the entity behind crypto exchange HTX, over allegations that it helped channel funds to Russia, alongside three Georgia-based companies operating Russia-focused exchanges and other actors linked to illicit financial flows.
Subsequent blockchain analysis said HTX continued operating under the same brand after the designation while rapidly rotating hot wallets and funding addresses across TRON, Ethereum, BNB Smart Chain, and Solana, complicating sanctions screening based on static wallet blocklists. The reporting tied the action to alleged support for A7 LLC and Garantex and to the UK National Crime Agency-led Operation Destabilize, underscoring compliance risks for firms that rely only on fixed address lists rather than behavior-based attribution and enhanced due diligence.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-23, the Council of the European Union adopted its 21st sanctions package against Russia, adding 218 listings and extending transaction bans to 14 crypto-related service platforms outside the EU. The package also included four designations tied to the A7 network and introduced authority to ban crypto-asset services from third countries hosting platforms that facilitate Russian sanctions evasion.
After the UK’s 2026-05-26 designation, HTX remained operational under the same brand and rapidly rotated hot wallets and funding addresses across TRON, Ethereum, BNB Smart Chain, and Solana. This post-designation activity was cited as evidence that static address blocklists were insufficient for sanctions screening.
On 2026-05-26, the UK announced a sanctions package with 18 designations targeting Russia’s sanctions-evasion infrastructure, including the Kremlin-backed A7 network, a Kyrgyz bank, Georgian exchange operators, and Huobi Global S.A., the entity behind HTX. The measures took effect immediately as part of efforts to disrupt Russian war financing and illicit financial flows.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
trmlabs.com
Open sourcescworld.com
Open sourcetrmlabs.com
Open sourcegov.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.