An international law enforcement operation coordinated by Europol and Eurojust dismantled the AudiA6 cryptocurrency laundering service, which investigators say washed more than EUR 336 million (about $380 million) between 2022 and 2025 for ransomware groups and other cybercriminal networks. Authorities linked the service to more than 15 international investigations involving ransomware and major cryptocurrency theft, describing AudiA6 as an industrial-scale laundering pipeline that relied on thousands of fraudulent exchange accounts, stolen or purchased identities, and more than 6,000 KYC records tied to money mule accounts.
The crackdown included coordinated arrests, searches, domain takedowns, server seizures, cryptocurrency freezes, and the seizure of vehicles, properties, and Telegram accounts across multiple jurisdictions. Investigators said the case advanced after Polish authorities arrested a Ukrainian suspect in September 2025, with forensic analysis leading to additional arrests in Georgia; the U.S. Department of Justice identified Ruslan Igorevich Tkachuk and Alexander Vladimirovich Ledenev as senior AudiA6 members now in Georgian custody. Europol also said the same suspects were tied to administration of the Dark2Web cybercrime forum, underscoring the role of specialized laundering services in sustaining the ransomware ecosystem.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
In September 2025, Polish authorities arrested a Ukrainian suspect tied to AudiA6. Forensic analysis of his devices helped investigators identify key operators later arrested in Georgia.
Authorities said the AudiA6 cryptocurrency laundering service processed more than EUR 336 million between 2022 and 2025 for ransomware groups and other cybercriminal networks. Investigators linked the service to over 15 international ransomware and major cryptocurrency theft investigations.
On 2026-06-10, the U.S. Department of Justice announced charges against Ruslan Igorevich Tkachuk and Alexander Vladimirovich Ledenev for allegedly operating the AudiA6 cryptocurrency laundering service. Prosecutors said the defendants were arrested in Georgia and face extradition to the Eastern District of Pennsylvania.
On 2026-06-10, coordinated law enforcement actions led to arrests, searches, domain takedowns, server seizures, cryptocurrency freezes, and asset seizures across multiple jurisdictions targeting AudiA6. Authorities also said suspects were linked to administration of the Dark2Web cybercrime forum.
In December 2025, TRM Labs said its on-chain analysis independently identified AudiA6 as a ransomware off-ramp. The firm traced about USD 7 million in funds stolen in the LastPass breach from Wasabi Wallet to the service.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 19 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See what this changes for your reporting obligations and which controls it puts on the clock.
14 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcesecurityonline.info
Open sourceinfosecurity-magazine.com
Open sourcecybersecuritynews.com
Open sourceeuropol.europa.eu
Open sourcebleepingcomputer.com
Open sourcejustice.gov
Open sourcepog.gov.ge
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.