Law Enforcement Disrupts AudiA6 Crypto Laundering Service Used by Ransomware
Key Takeaways An international law enforcement operation successfully dismantled “AudiA6,” a prominent cryptocurrency laundering service. The service facilitated the obfuscation and...
Key Takeaways
- An international law enforcement operation successfully dismantled “AudiA6,” a prominent cryptocurrency laundering service.
- The service facilitated the obfuscation and cashing out of over EUR 336 million in illicit funds for ransomware groups and other cybercriminals between 2022 and 2025.
- Two suspected administrators were arrested, critical infrastructure seized, and significant cryptocurrency assets, along with other properties, were confiscated.
- The operation significantly impacts the financial infrastructure supporting ransomware and other large-scale cybercrime activities.
Global Law Enforcement Shuts Down Major Crypto Laundering Service “AudiA6”
In a significant blow to the global cybercrime ecosystem, an international coalition of law enforcement agencies has successfully dismantled “AudiA6,” a sophisticated cryptocurrency laundering service. This platform was a crucial financial enabler for numerous ransomware gangs and other cybercriminal networks, facilitating the conversion and concealment of illicit digital assets.
Table Of Content
Investigators characterized AudiA6 as an industrial-scale operation that processed an astounding EUR 336 million in dirty money between 2022 and 2025. Its services were vital for threat actors seeking to move and cash out stolen funds while circumventing anti-money laundering (AML) controls and detection by authorities.
Coordinated International Takedown
The decisive action took place on June 10, involving a broad collaboration of international partners. Key agencies included the United States Secret Service, IRS Criminal Investigation, and Polish law enforcement, with operational assistance from Europol and Eurojust. This multi-national effort underscores the increasing global cooperation required to combat sophisticated cyber financial crime.
During the operation, authorities apprehended two individuals of Ukrainian and Russian nationality in Georgia, believed to be the administrators of AudiA6. Extensive property searches were conducted, and essential infrastructure supporting the laundering network was systematically dismantled. The takedown also targeted the associated “Dark2Web” forum, a known marketplace for illicit services.
The enforcement actions resulted in the seizure of over 30 servers and the shutdown of 25 domains. Furthermore, cryptocurrency assets valued at hundreds of thousands of euros were frozen and confiscated. Beyond digital assets, investigators also seized physical assets, including vehicles and properties linked to the suspects, and blocked communication channels such as Telegram accounts used by the group.
How AudiA6 Operated
AudiA6 operated as a professional-grade crypto laundering service, openly advertised on various underground forums. Cybercriminals, including ransomware affiliates, would transfer their stolen cryptocurrency to wallets managed by AudiA6. The service then promised to return “cleaned” funds, often within approximately one hour, after executing rapid and complex transaction chains designed to obscure the original source of the money across multiple wallets and exchanges.
The operators charged commissions ranging from 3 to 10 percent, making the service highly profitable. The investigation uncovered an extensive network of fraudulent accounts, many of which were created using stolen or purchased identities. Over 6,000 Know Your Customer (KYC) records were linked to these money mule accounts, which were frequently managed by intermediaries, often Russian-speaking, to facilitate the movement of funds across various cryptocurrency exchanges.
To register these accounts and bypass compliance checks, the group utilized a combination of commercial email services and custom domains. Authorities have since released several domains associated with this activity to help cryptocurrency exchanges identify and block suspicious accounts proactively.
Further analysis indicated a strong likelihood that the individuals behind AudiA6 were also operating the “Dark2Web” cybercrime forum. This platform served as a central hub for connecting threat actors globally and facilitating the exchange of illicit services.
Impact and Future Outlook
Europol has directly linked the AudiA6 laundering platform to more than 15 active investigations involving significant ransomware campaigns and large-scale cryptocurrency thefts. This connection highlights the critical role AudiA6 played as a central financial enabler within the broader cybercrime ecosystem.
This operation aligns with trends identified in Europol’s 2026 Internet Organized Crime Threat Assessment, which emphasizes the increasing professionalization of cryptocurrency laundering services. Cybercriminal groups are continually evolving their techniques, employing methods such as chain-hopping, decentralized exchanges, and mixer-based services to rapidly move funds across blockchains and evade anti-money laundering controls.
While the takedown of AudiA6 significantly disrupts a major financial pipeline for ransomware groups, law enforcement agencies acknowledge that similar services continue to emerge and evolve, sustaining the global cybercrime economy. The ongoing battle against illicit financial flows in the digital realm remains a priority.
What You Should Do
- Financial Institutions and Crypto Exchanges: Review the domains and indicators of compromise (IoCs) released by authorities to identify and block suspicious accounts linked to AudiA6 or similar laundering activities. Enhance KYC/AML procedures to detect and prevent the use of stolen or purchased identities.
- Organizations and Individuals: Implement robust cybersecurity measures, including strong passwords, multi-factor authentication, and regular backups, to protect against ransomware attacks that fuel these laundering operations.
- Law Enforcement and Intelligence Agencies: Continue fostering international collaboration and sharing intelligence to track and dismantle emerging crypto laundering services and their associated cybercriminal networks.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.