
Law enforcement has taken down the “AudiA6” cryptocurrency service, which is suspected of being used by ransomware groups and other cybercriminals to launder over $380 million.
According to Europol, the service has been connected to more than 15 separate international investigations into ransomware attacks.
The platform is believed to have functioned as a central hub for money laundering between 2022 and 2025.
“Investigators uncovered what they describe as an industrial-scale cryptocurrency laundering operation built around thousands of fraudulent exchange accounts opened using stolen or purchased identities,” Europol states.
“Analysis conducted by Europol linked the criminal service to more than 15 investigations worldwide involving ransomware attacks and large-scale cryptocurrency theft.”
The service was promoted as a “professional cryptocurrency mixing service,” but in reality, it simply received proceeds from cybercrime, shuffled the funds through complex transaction pathways to hide their source, and returned them “cleaned” to the owners within roughly an hour, after deducting a commission of 3-10%.
Earlier reports from Intel471 and blockchain investigator ZachXBT exposed AudiA6 for its role in enabling illegal activities.
The investigation involved authorities from 11 countries across Europe, the Americas, and Asia, supported by Europol and Eurojust.
Europol notes that the operation was made possible by the arrest in Poland in September 2025 of a Ukrainian national linked to AudiA6.
Forensic analysis of the suspect’s devices enabled investigators to identify key figures behind the operation and eventually track them down and arrest them in Georgia.
As a result of yesterday’s action, authorities have:
- Arrested 2 individuals in Georgia - Searched 3 properties - Seized 25 domains - Seized 80 vehicles and properties - Seized €86,000 ($99,000) in cryptocurrency - Frozen €692,000 ($798,000) in cryptocurrency - Blocked Telegram accounts used by the network
The two arrested individuals, a Ukrainian and a Russian national, are believed to be administrators of both AudiA6 and the underground forum “Dark2Web,” which cybercriminals used to advertise illicit services.
The websites for both AudiA6 and Dark2Web now display a seizure notice to visitors.
The U.S. Department of Justice has identified Ruslan Igorevich Tkachuk, aged 37, and Alexander Vladimirovich Ledenev, aged 25, as senior members of the AudiA6 platform.
The two individuals are currently in the custody of Georgian authorities and face sentences of up to 20 years in prison for facilitating cybercrime money laundering operations.
"Out of the approximately 10,333 bitcoin deposited, approximately 393.39 BTC (valued at around $19,234,331 at the time of the transactions) were received directly from known darknet markets, ransomware organizations, cybercrime services, and other illicit sources, while additional funds were deposited indirectly from illicit sources into AudiA6 wallets," the DoJ states.
In addition to the two administrators, authorities also recovered 6,000 ‘Know-Your-Customer’ (KYC) records linked to money mule accounts.
Europol says these accounts were created using stolen or purchased identities, and many are tied to Russian-speaking intermediaries who recruited them specifically for this purpose.
This extensive network of money mules utilized multiple domains to register accounts on cryptocurrency exchanges, a detail Europol published to raise awareness and assist platforms in blocking them.
Test every layer before attackers do
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Related Articles:
Dark web Nemesis Market vendor gets 26 years for selling drugs
Police dismantles fake ID marketplace used by migrant smugglers
Spain arrests doxer leaking sensitive data of govt employees
Ukraine identifies infostealer operator tied to 28,000 stolen accounts
INTERPOL ‘Operation Ramz’ seizes 53 malware, phishing servers