Law enforcement dismantles AudiA6 laundering network used by ransomware gangs
Police dismantle AudiA6 crypto laundering ring; 10,333 BTC processed since 2021.
Two senior admins were arrested in Georgia. The U.S. seeks extradition. Chainalysis report.
AudiA6 ran as a “mixer‑as‑a‑service” for ransomware and darknet actors. It processed about BTC 10,333 since 2021, historically valued near $389 million. Chainalysis report.
Agencies involved included the U.S. DOJ, U.S. Secret Service, and Europol. Authorities seized U.S. and EU infrastructure. AudiA6 and the Dark2Web forum now show seizure banners. Chainalysis report.
Two suspects were held in Georgia. A 37‑year‑old Ukrainian and a 25‑year‑old Russian. The U.S. is pursuing extradition. Chainalysis report.
Chainalysis says AudiA6 relied on more than 6,000 KYC‑verified mule accounts at centralized exchanges. Illicit funds were blended with normal activity via those accounts. Chainalysis report.
Investigators traced at least 393 BTC from ransomware, darknet markets, and other cybercrime. Over $16 million tied to ransomware and stolen funds moved through AudiA6. Chainalysis report.
The service charged 3%–10% commissions. It returned obfuscated funds in about one hour. Chainalysis report.
Cash‑out links included sanctioned Russian exchanges Bitzlato and Garantex. The network had exposure to the Exploit.in forum. Europol flagged mule‑registration domains: designli.pictures, deliverly.top, inboxly.top. Chainalysis report.
Why it matters. Chainalysis says enforcement is zeroing in on laundering infrastructure. Mule accounts and weak controls at centralized rails can be exploited at scale. Blockchain analytics ties wallets, domains, cash‑out pipelines, and operators. Chainalysis report.







