[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fZBEx2UcY0wARAuNW0C9we3nC_ULv9SGrmZ7T_8r8YFw":3},{"article":4,"iocs":54},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":31,"category":32,"article_tags":36},"2feedccf-cbf9-4446-9628-c06b922b5213","Authorities dismantle 'AudiA6' ransomware crypto-laundering service","authorities-dismantle-audia6-ransomware-crypto-laundering-service-f6e3c1","Law enforcement has dismantled the “AudiA6” cryptocurrency service allegedly used by ransomware actors and other cybercriminals to launder more than $380 million. [...]","Law enforcement agencies have dismantled the 'AudiA6' cryptocurrency service, which allegedly facilitated the laundering of over $380 million for ransomware actors and other cybercriminals. The platform, active between 2022 and 2025, acted as a money laundering hub, processing illicit funds through complex transaction routes. The operation involved authorities from 11 countries and led to the arrest of two alleged administrators.","Authorities dismantle 'AudiA6' crypto-laundering service used by ransomware actors.","Authorities dismantle 'AudiA6' ransomware crypto-laundering service By Bill Toulas June 11, 2026 11:55 AM 0 Law enforcement has dismantled the “AudiA6” cryptocurrency service allegedly used by ransomware actors and other cybercriminals to launder more than $380 million. Europol says that the service has been linked to more than 15 distinct international investigations of ransomware attacks. It is believed that the platform acted as a central money laundering hub between 2022 and 2025. “Investigators uncovered what they describe as an industrial-scale cryptocurrency laundering operation built around thousands of fraudulent exchange accounts opened using stolen or purchased identities,” describes Europol says. “Analysis conducted by Europol linked the criminal service to more than 15 investigations worldwide involving ransomware attacks and large-scale cryptocurrency theft.” The service was marketed as a “professional cryptocurrency mixing service,” but all it did was accept cybercrime proceeds, move the money around through complex transaction routes that obscured its origin, and return it “cleaned” to the holders in about an hour, minus a 3-10% service commission. Past reports from Intel471 and blockchain investigator ZachXBT exposed AudiA6 for facilitating illegal activity. The investigation involved authorities from 11 countries across Europe, America, and Asia, who were supported by Europol and Eurojust. Europol states that the action was possible due to the arrest in Poland in September 2025 of a Ukrainian national linked to AudiA6. The forensic examination of the suspect’s devices helped investigators identify key individuals behind the operation and eventually locate and arrest them in Georgia. As a result of the action from yesterday, the authorities have: Arrested 2 individuals in Georgia Searched 3 properties Seized 25 domains Seized 80 vehicles and properties Seized €86,000 ($99k) in cryptocurrency Froze €692,000 ($798k) in cryptocurrency Blocked Telegram accounts used by the network The two arrested individuals, a Ukrainian and a Russian national, are believed to be administrators of AudiA6, as well as of the underground forum “Dark2Web,” which cybercriminals used to advertise illicit services. Both AudiA6 and Dark2Web websites now display a seizure notice to visitors. Seizure bannerSource: Europol The U.S. Department of Justice named Ruslan Igorevich Tkachuk, aged 37, and Alexander Vladimirovich Ledenev, aged 25, as senior members of the AudiA6 platform. The two individuals are currently in the custody of Georgian authorities and are facing sentences of up to 20 years in prison for facilitating cybercrime laundering operations. \"Out of the approximately 10,333 bitcoin deposited, approximately 393.39 BTC (valued at around $19,234,331 at the time of the transactions) were received directly from known darknet markets, ransomware organizations, cybercrime services, and other illicit sources, while additional funds were deposited indirectly from illicit sources into AudiA6 wallets,\" the DoJ states. Apart from the two administrators, authorities also retrieved 6,000 ‘Know-Your-Customer’ (KYC) records linked to money mule accounts. Europol says these accounts were created using stolen or purchased identities, and many are connected to Russian-speaking intermediaries that recruited them specifically for this purpose. This massive network of money mules used multiple domains to register accounts on cryptocurrency exchanges, a fact Europol published to raise awareness and help platforms block them. Test every layer before attackers do Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Get the whitepaper Related Articles: Dark web Nemesis Market vendor gets 26 years for selling drugsPolice dismantles fake ID marketplace used by migrant smugglersSpain arrests doxer leaking sensitive data of govt employeesUkraine identifies infostealer operator tied to 28,000 stolen accountsINTERPOL ‘Operation Ramz’ seizes 53 malware, phishing servers","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Flegal\u002Fauthorities-dismantle-audia6-ransomware-crypto-laundering-service\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2026\u002F06\u002F11\u002Farrest.jpg","2026-06-11T15:55:41+00:00","2026-06-11T16:00:09.275229+00:00",8,[18,21,24,26,28],{"name":19,"type":20},"AudiA6","threat_actor",{"name":22,"type":23},"Europol","vendor",{"name":25,"type":23},"Eurojust",{"name":27,"type":23},"U.S. Department of Justice",{"name":29,"type":30},"Telegram","product","7d8b5ab8-ea0b-4ced-ae97-ec251b86993a",{"id":31,"icon":33,"name":34,"slug":35},null,"Ransomware","ransomware",[37,42,44,49],{"category":38},{"id":39,"icon":33,"name":40,"slug":41},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":43},{"id":31,"icon":33,"name":34,"slug":35},{"category":45},{"id":46,"icon":33,"name":47,"slug":48},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",{"category":50},{"id":51,"icon":33,"name":52,"slug":53},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]