The U.S. Treasury sanctioned Russia-based cryptocurrency OTC broker Suex and added it to the SDN List, barring U.S. persons from transacting with the firm as Washington intensified efforts to disrupt ransomware financing. Treasury said Suex facilitated illicit transactions for at least eight ransomware variants and was used to launder proceeds from ransomware, scams, darknet markets, and activity linked to BTC-e. Chainalysis reported that Suex had received more than $481 million in Bitcoin since 2018, including over $160 million tied to criminal sources, and described the broker as a nested service that converted cryptocurrency to cash through operations in Moscow and St. Petersburg.
The designation came alongside updated U.S. ransomware guidance and reflected a broader strategy of targeting the financial infrastructure behind attacks rather than only the malware brands, which frequently rebrand or share affiliates and laundering channels. Blockchain-tracing firms and law enforcement had already shown how ransomware groups such as DarkSide, Maze, Egregor, and DoppelPaymer relied on common cash-out pathways, while the DOJ separately recovered 63.7 BTC from the Colonial Pipeline ransom and later monitoring showed DarkSide-linked funds moving through laundering patterns toward exchanges. The action underscored that ransomware-as-a-service operations depend on OTC brokers, exchanges, and service deposit addresses to turn extortion payments into usable cash.

See the reporting duties and controls this puts on the clock.
37 events from the most recent confirmed update back to the earliest known activity.
Trend Micro reported that from January 1 to March 31, 2022 it blocked 4,439,903 ransomware threats and observed a 63.2% year-over-year increase in active RaaS and extortion groups.
Trend Micro reported that LockBit claimed an attack on France's Ministry of Justice in January 2022 and threatened to publish sensitive data if unpaid.
Trend Micro cited an FBI estimate from January 2022 that the group behind Conti had amassed more than 1,000 victims and over $150 million in payouts.
Trend Micro said MalwareHunterTeam researchers first reported the BlackCat ransomware family in November 2021.
Elliptic and BleepingComputer reported that DarkSide-linked Bitcoin dormant since May began moving on October 21, 2021 in a peeling-chain pattern consistent with laundering, with some funds sent to known exchanges.
The U.S. Treasury's OFAC sanctioned Russia-based OTC broker Suex and added it to the SDN List, barring Americans from doing business with it. Chainalysis said Suex had received over $160 million from ransomware actors, scammers, and darknet markets.
CSO Online reported that on September 2, 2021, Russia's Roskomnadzor blocked six VPN providers, citing illegal activities.
CSO Online said Biden again told Putin in a July 2021 phone call that the United States expected Russia to act on ransomware actors operating from Russian territory.
BleepingComputer reported that in July 2021, the BlackMatter ransomware group was seeking to buy access to corporate networks.
The Record reported the launch of Ransomwhere in July 2021 as a public, crowdsourced database for past ransomware payments created by Jack Cable.
On June 7, 2021, the U.S. Department of Justice announced it had seized 63.7 bitcoins, valued at about $2.3 million, tied to the Colonial Pipeline ransom payment.
CSO Online said President Joe Biden told Vladimir Putin at a June 2021 summit that Russia was expected to act against ransomware operators on its soil.
Elliptic reported that on May 13, 2021, DarkSide said its infrastructure and wallet had been seized by an unknown third party, and 107.8 BTC were transferred from its wallet to a new address.
The DOJ said Colonial Pipeline paid approximately 75 bitcoins to DarkSide-associated actors on May 8, 2021 after the attack.
The DOJ said Colonial Pipeline was the victim of a DarkSide ransomware attack on or about May 7, 2021, causing portions of its infrastructure to be taken offline. Multiple sources describe the incident as DarkSide's most prominent attack.
Deutsche Telekom Security said it had known of the LOCKDATA Auction leak marketplace since May 2021.
BleepingComputer said threat actors launched the Marketo stolen-data marketplace in the month before the article was published.
BleepingComputer reported that the File Leaks stolen-data marketplace was launched in April 2021 and published stolen data while offering victims removal for payment.
CSO Online said the United States imposed sanctions on Russia and expelled Russian diplomatic or intelligence personnel in April 2021 after ransomware attacks affected U.S. infrastructure.
Chainalysis said Maze operators announced in early November 2020 that the ransomware strain was shutting down, after which many affiliates migrated to Egregor.
Unit 42 said its responders began seeing DarkSide activity around October 2020, indicating the group's operational emergence.
Chainalysis said Egregor became active in mid-September 2020, shortly before Maze went inactive.
Trend Micro's report said the first version of Nefilim was spotted in the wild in March 2020, marking the emergence of the ransomware family.
Deutsche Telekom Security said the Crykal ransomware family was rebranded as CryLock in 2020.
CSO Online reported that Sergey Mikhailov was sentenced by Russian courts to 22 years in prison in 2019.
Chainalysis said Suex appeared in its Rogue 100 list of major OTC money-laundering facilitators in 2019.
BleepingComputer reported that Dark Leak Market appears to have been created in 2019 and has sold stolen data since then.
BleepingComputer said the Maze ransomware group popularized double extortion in 2019 by threatening to leak stolen data if victims did not pay.
Chainalysis said Suex became active in February 2018 and went on to receive over $481 million in Bitcoin.
Deutsche Telekom Security said Crykal infrastructure was taken down in 2018 and a decryptor was subsequently released.
Chainalysis noted that BTC-e was shut down by U.S. authorities in 2017 for facilitating large-scale money laundering on behalf of cybercriminals.
CSO Online said multiple arrests tied to the FSB Information Security Center began between December 2016 and January 2017, including deputy director Sergey Mikhailov and Kaspersky manager Ruslan Stoyanov.
Krebs on Security reported that in 2015 the FBI offered a $3 million reward for information leading to the capture of Business Club leader Evgeniy Mikhailovich Bogachev.
Krebs on Security cited CrowdStrike as saying Indrik Spider was formed in 2014 by former affiliates of the GameOver Zeus criminal network.
Deutsche Telekom Security said the ransomware family later known as CryLock was first publicly referenced under the name Crykal in 2014.
Elliptic reported in May 2021 that DarkSide had received just over $90 million in Bitcoin ransom payments over the prior nine months and had at least 99 victims.
In a February 2021 report, Chainalysis described blockchain evidence suggesting operational or financial links among Maze, Egregor, SunCrypt, and DoppelPaymer, including shared affiliates and OTC cash-out infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See what this changes for your reporting obligations and which controls it puts on the clock.
23 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourcetrendmicro.com
Open sourcebleepingcomputer.com
Open sourceelliptic.co
Open sourcemcafee.com
Open sourcechainalysis.com
Open sourcedocuments.trendmicro.com
Open sourcego.chainalysis.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.