International Operation Dismantles Major Cryptocurrency Laundering Network That Processed Millions in Criminal Proceeds
- Jun 16
- 5 min read
An extensive international law enforcement operation backed by Eurojust and Europol has dismantled a major digital asset laundering network accused of helping cybercriminals move millions of euros in illicit proceeds. The coordinated action focused on a service known as AudiA6, which investigators believe handled substantial volumes of criminal cryptocurrency transactions for global threat actors between 2022 and 2025. Authorities carried out synchronized enforcement measures across several jurisdictions, targeting both the people behind the operation and the technical infrastructure that supported it. The successful intervention reflects the increasing ability of international judicial and policing agencies to trace complicated virtual asset transactions and disrupt the financial facilitators that underpin the global cybercrime economy.

According to investigators, AudiA6 served as a central financial gateway for ransomware groups and other cybercriminal organizations seeking to conceal the origins of their digital assets. The platform enabled users to deposit compromised cryptocurrency into wallets controlled by the operators, triggering a rapid laundering process that allegedly returned sanitized funds in approximately one hour. To accomplish this, the administrators maintained an advanced transactional structure specifically designed to break the chain of custody relied upon by financial intelligence agencies and blockchain investigators. In return for providing this anonymity, the operators charged fees ranging from three percent to ten percent of the value of each transaction processed.
The organization expanded its criminal ecosystem by operating a second platform known as Dark2Web, which functioned as an international cybercrime forum and online marketplace. Through this service, malicious actors could advertise illegal services, exchange stolen information, and build criminal partnerships. By integrating a widely used underground marketplace with a fast cryptocurrency laundering utility, the network established a complete service environment for cybercriminals operating across borders. This business model enabled the syndicate to generate profits from several stages of the criminal process, benefiting both from the underlying illegal trade and from the laundering of the proceeds generated by those activities.
Although the group's physical presence was concentrated primarily in Eastern Europe, its technological infrastructure extended across numerous countries and continents. During a coordinated international action day, law enforcement agencies executed searches and arrests aimed at dismantling the network's core leadership. The operation resulted in the seizure of an extensive technical infrastructure that included dozens of servers as well as the takeover of multiple internet domains used to host the illegal services. Authorities also targeted the assets accumulated by the alleged operators, freezing significant holdings of cryptocurrency and confiscating valuable physical property, including luxury real estate and a substantial fleet of vehicles.
Officials said that dismantling the AudiA6 operation required an exceptional degree of judicial and operational cooperation between multiple countries. Eurojust acted as the central platform for international legal coordination, using its liaison system to facilitate communication between prosecutors in Europe and North America. The United States Secret Service and the Internal Revenue Service Criminal Investigation Division worked alongside their European counterparts through dedicated agency channels. This collaborative structure enabled investigators to overcome differing national legal requirements and quickly obtain mutual legal assistance orders needed to secure digital evidence and freeze assets located across international borders.
Planning for the final enforcement stage also involved close cooperation between prosecutors in Central Europe and authorities operating in the Caucasus region. The Regional Prosecutor's Office in Lodz and the Polish Central Cybercrime Bureau directed the primary investigative effort, building on evidence obtained after the arrest of an important co-conspirator in late 2025. Information gathered during that detention allowed investigators to map the broader structure of the organization and ultimately led to the issuance of international arrest warrants. Those warrants created the legal basis for the later arrests of the platform's principal administrators during the concluding phase of the global investigation.
At the same time, specialized cybercrime experts examined the network's digital financial trails to uncover the movement of criminal proceeds. Analysts from the European Cybercrime Centre used advanced blockchain analysis techniques to monitor the transfer of virtual assets through complex chains of intermediary wallets. Their work helped investigators reconstruct the international infrastructure used by the network, demonstrating how funds flowed from ransomware victims into the laundering platform before being transferred to cryptocurrency exchanges around the world. This intelligence was instrumental in locating the physical servers that hosted the operation, enabling simultaneous enforcement actions in jurisdictions that included France, Iceland, and Georgia.
Investigators also determined that the success of the laundering service depended heavily on the large-scale abuse of commercial cryptocurrency exchanges through identity fraud. To move hundreds of millions of euros without triggering automated compliance systems, the network allegedly created thousands of fraudulent accounts using stolen or purchased personal information. Authorities identified more than 6,000 separate know your customer profiles directly connected to money mule accounts controlled by the organization. These accounts acted as the interface between the illicit operation and the legitimate financial system, allowing the syndicate to deposit, exchange, and withdraw virtual assets on a large scale.
Managing this extensive network of fraudulent accounts required the recruitment of Russian-speaking intermediaries who served as money mules and account operators. Their role involved maintaining account functionality and carrying out transactions according to instructions from the organization's leadership. Investigators found that the network relied on a combination of well-known commercial email services and a collection of proprietary internet domains to register the fraudulent profiles across numerous cryptocurrency trading platforms. By controlling the registration domains, the administrators were able to automate account management and more easily bypass standard verification procedures.
Law enforcement agencies have made many of these registration domains public to assist regulators, compliance departments, and financial institutions in identifying accounts potentially linked to the operation. Among the domains disclosed by investigators are designli.pictures, pheontx.eu, smplfy.in, and sumato-soft.org, as well as communication-oriented domains including technobrains.dev, lett.email, trayo.app, deliverly.top, and inboxly.top. Additional infrastructure was reportedly hosted through domains such as postfast.eu, postino.click, inboxally.agency, mailora.eu, postify.email, quix.express, flowcomm.click, qube.black, deliverlett.com, and lettermail.eu. Authorities believe that comparing historical transaction records against these domain profiles may help financial institutions uncover previously undetected exposure to the AudiA6 network.
The investigation has also provided anti-money laundering professionals with valuable insight into the methods used by sophisticated digital asset laundering organizations. Compliance specialists are encouraged to monitor for the mass creation of financial accounts using newly registered or highly specialized corporate domains that feature technology or logistics-oriented naming conventions, as these may indicate coordinated criminal activity.
Another significant warning sign is the rapid movement of digital assets, where accounts receive large cryptocurrency transfers and then distribute the entire balance to unrelated wallets within a very short period, often less than an hour. Such high-velocity transactional behavior may signal the presence of an organized laundering platform.
Investigators further highlighted the importance of monitoring for concentrated networks of Russian-speaking intermediaries managing large numbers of customer profiles, as this can indicate organized money mule operations. Analysts should also pay close attention to infrastructure overlaps where cryptocurrency wallets regularly interact with both underground online marketplaces and high-volume trading platforms, suggesting a connection between illicit commerce and financial laundering services.
Finally, authorities emphasized the continuing threat posed by the repeated use of stolen know your customer documentation. The appearance of multiple accounts using identical or slightly modified identity records across different jurisdictions, particularly when they share similar digital characteristics or access locations, remains a key indicator of organized virtual asset laundering activity. Detecting these patterns early through enhanced due diligence and advanced monitoring systems is considered essential for disrupting increasingly sophisticated international cybercrime networks.
By fLEXI tEAM





Comments