Authorities Dismantle “AudiA6” Crypto-Laundering Service Linked to Ransomware Operations
Authorities dismantled the AudiA6 cryptocurrency laundering service, which was allegedly used by ransomware groups and cybercriminals to move more than $380 million through fraudulent exchange accounts, complex transaction routes, and money mule networks.
International law enforcement agencies have dismantled AudiA6, a cryptocurrency laundering service allegedly used by ransomware groups and other cybercriminals to move more than $380 million in illicit funds.
According to Europol, AudiA6 operated as a large-scale money laundering hub between 2022 and 2025 and has been linked to more than 15 international investigations involving ransomware attacks and major cryptocurrency theft.
Investigators described the platform as an industrial-scale laundering operation built around thousands of fraudulent cryptocurrency exchange accounts. Many of those accounts were reportedly opened using stolen or purchased identities, allowing cybercriminals to obscure the origin of stolen funds and move money through legitimate-looking financial channels.
Although AudiA6 was marketed as a professional cryptocurrency mixing service, authorities say it functioned as a laundering platform for cybercrime proceeds. The service allegedly accepted funds from ransomware actors, darknet markets, cybercrime services, and other illicit sources, routed the assets through complex transaction paths, and returned the money to customers after taking a commission of roughly 3% to 10%.
Europol said the service could complete laundering transactions in about an hour, making it attractive to ransomware operators and other threat actors seeking fast access to “cleaned” cryptocurrency.
Past reporting from threat intelligence firm Intel471 and blockchain investigator ZachXBT had previously identified AudiA6 as a service used to support illicit cryptocurrency activity.
The takedown involved authorities from 11 countries across Europe, the Americas, and Asia, with coordination support from Europol and Eurojust. Investigators said the operation accelerated after the September 2025 arrest in Poland of a Ukrainian national linked to AudiA6. Forensic analysis of the suspect’s devices reportedly helped identify key individuals behind the laundering network and led authorities to additional suspects in Georgia.
As part of the coordinated enforcement action, authorities arrested two individuals in Georgia, searched three properties, seized 25 domains, seized 80 vehicles and properties, seized approximately €86,000 in cryptocurrency, froze another €692,000 in cryptocurrency, and blocked Telegram accounts used by the network.
The two arrested suspects, identified by the U.S. Department of Justice as Ruslan Igorevich Tkachuk, 37, and Alexander Vladimirovich Ledenev, 25, are accused of being senior members of the AudiA6 platform. Authorities also allege that they helped administer Dark2Web, an underground forum used by cybercriminals to advertise illicit services.
Both AudiA6 and Dark2Web now display law enforcement seizure notices.
The suspects are currently in Georgian custody and face potential prison sentences of up to 20 years for their alleged roles in facilitating cybercrime laundering operations.
According to the Justice Department, AudiA6 received approximately 10,333 bitcoin in deposits. Of that amount, around 393.39 BTC, valued at approximately $19.2 million at the time of the transactions, was allegedly received directly from known darknet markets, ransomware organizations, cybercrime services, and other illicit sources. Authorities said additional funds were also deposited indirectly from illicit sources into AudiA6-controlled wallets.
Investigators also recovered roughly 6,000 Know-Your-Customer records connected to money mule accounts. Europol said the accounts were created using stolen or purchased identities, with many tied to Russian-speaking intermediaries who recruited people specifically to support the laundering operation.
Money mule networks are a key component of modern cybercrime finance. By creating or controlling accounts at cryptocurrency exchanges and financial platforms, criminals can move funds through layers of seemingly legitimate accounts, making blockchain tracing and asset recovery more difficult.
Europol published information about the domains used by the laundering network to help cryptocurrency exchanges and compliance teams identify and block related accounts.
The takedown is part of a broader law enforcement push against the financial infrastructure that supports ransomware and cybercrime. While arresting ransomware operators remains difficult, disrupting laundering services can make it harder for threat actors to convert stolen cryptocurrency into usable funds.
For ransomware groups, reliable laundering is essential. Without access to mixers, fraudulent exchange accounts, and money mule networks, it becomes more difficult to cash out ransom payments, pay affiliates, fund infrastructure, and continue operations.
The AudiA6 takedown shows that authorities are increasingly targeting the financial layer of cybercrime, not just the malware developers or intrusion teams. By dismantling laundering services and identifying money mule infrastructure, law enforcement can weaken the broader ecosystem that allows ransomware and cryptocurrency theft to remain profitable.
Comments
0 public comments
No comments yet
Be the first to add a comment to this article.
Add a comment
Please sign in to comment on this article.
Sign In