The U.S. Treasury designated the Russia-linked A7 Network a significant transnational criminal organization under Executive Order 13581, alleging that it enabled sanctions evasion and cross-border illicit finance, including activity connected to Iran. The action, part of Operation Economic Outcast, immediately blocks A7 property and interests in property under U.S. jurisdiction, as well as entities owned 50% or more by designated parties. Treasury said the network used foreign front companies, trade-finance documents and VPN-operated bank accounts to move funds, with alleged connections to the IRGC, Iran-backed terrorist groups, ransomware actors and North Korean cybercrime proceeds.
FinCEN separately found transactions involving non-U.S. companies controlled by A7—known as Sub-Agents—to be of primary money-laundering concern and proposed 31 CFR 1010.668. The measure would bar covered U.S. financial institutions from sending fiat currency or convertible virtual currency to or from designated Sub-Agents, whose identities would primarily be distributed through FinCEN's secure FI Portal. FinCEN estimated Sub-Agents processed more than $17 billion in dollar-denominated transactions between January 2025 and June 2026. Authorities also cited A7A5, a ruble-backed token issued by sanctioned Old Vector LLC on Tron and Ethereum, as an internal accounting mechanism associated with foreign-fiat payments; more than 180 entities processed at least $179.1 billion in A7A5 transactions during a similar period.

See the reporting duties and controls this puts on the clock.
9 events from the most recent confirmed update back to the earliest known activity.
FinCEN issued a finding that transactions involving non-U.S. companies controlled by A7 are a class of transactions of primary money laundering concern. It proposed 31 CFR 1010.668 to prohibit covered U.S. financial institutions from transmitting fiat currency or convertible virtual currency to or from identified A7 Sub-Agents.
OFAC designated the Russia-linked A7 Network as a Significant Transnational Criminal Organization under Executive Order 13581, alleging it facilitated Iranian sanctions evasion. The action requires U.S. persons to block covered A7 property and applies to entities owned 50% or more by blocked persons.
By June 2026, FinCEN assessed that A7 had created or acquired hundreds of controlled Sub-Agents with accounts at approximately 435 financial institutions across at least 83 countries.
Following the reported hack of Grinex, A7A5 supply consolidated into unhosted wallets. FinCEN said A7A5 activity had historically occurred mainly through the sanctioned Garantex and Grinex venues.
The United States imposed sanctions on A7 LLC, A7A5 issuer Old Vector LLC, and other businesses. The later October 2026 action expanded these measures to the broader A7 Network and its intermediaries.
The Russia-linked A7 Network was launched by Ilan Shor and Russia's state-owned defense bank Promsvyazbank. Its core Russia-based companies included A7 LLC, A71 LLC, and A7 Agent LLC.
More than 180 entities processed at least $179.1 billion in transactions involving the ruble-backed A7A5 token. FinCEN characterized the token as part of a mirror-payment system representing corresponding foreign fiat payments.
FinCEN assessed that A7-controlled foreign payment intermediaries, termed Sub-Agents, processed more than $17 billion in dollar-denominated transactions during this period.
A7 clients purchased more than 3,200 bills of exchange, or veksels, valued at more than $25 billion. FinCEN described the instruments as part of a system used to conceal Russian involvement in cross-border payments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.