Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Location-Based Gaming NFTs: How GPS and Blockchain Are Changing the Way We Play

May 2, 2026

ZachXBT Exposes US Law Firm Gerstein Harrow’s $71M Grab of Stolen Lazarus Funds

May 2, 2026

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Three-Quarters of Ransomware Payments Linked to Russia
Three-Quarters of Ransomware Payments Linked to Russia
Security

Three-Quarters of Ransomware Payments Linked to Russia

November 7, 2023No Comments3 Mins Read

Around three-quarters (74%) of ransomware revenue resulted from attacks associated with Russia in 2021, according to a new report by blockchain investigations and analytics company Chainalysis.

The researchers found that more than $400m worth of cryptocurrency went to ransomware strains “highly likely” to be affiliated with Russia in some way last year. These connections were made based on three criteria:

  1. The attack was conducted by the notorious Russian-based Evil Corp gang, whose leadership is believed to have ties to the Russian government.
  2. The ransomware strain avoided countries in the Commonwealth of Independent States (CIS), an intergovernmental organization of Russian-speaking, former Soviet countries. These ransomware strains contain code that prevents the encryption of files if it detects the victim’s operating system is located in a CIS country.
  3. Others characteristics that indicated the strain was based in Russia. These include strains that share documents and announcements in the Russian language or whose affiliates are located in Russia.

In addition, Chainalysis revealed that most of the extorted funds arising from ransomware attacks are laundered through services primarily catering to Russian users. For example, it estimated that 13% of funds sent from ransomware addresses to services went to users thought to be located in Russia. This is more than any other region.

The researchers also provided an analysis of several dozen cryptocurrency businesses operating in Moscow City, Russia’s financial district. They claimed these businesses are heavily involved in laundering digital currencies, with illicit and risky addresses accounting for between 29% and 48% of all funds they received in any given quarter.

See also  SafeMoon hacker’s use of centralized exchanges could help law enforcement: Match System

In the three years from 2019-2021, these firms received nearly $700m from illicit and risky addresses. This was primarily comprised of scams ($313m) and darknet markets ($296m), with ransomware extortion payments making up $38m.

The researchers noted that illicit funds make up as much as 30% of all cryptocurrency received by some of these companies, “which suggests those businesses may be making a concerted effort to serve a cyber-criminal clientele.” Interestingly, over half of the cryptocurrency businesses analyzed reportedly operate in the same Moscow City skyscraper, Federation Tower.

The report acknowledged that Russian authorities arrested 14 affiliates of the REvil ransomware gang last month, suggesting that “change may be on the way for Russia’s cryptocurrency ecosystem.”

Chainalysis stated: “Regardless of what the future holds, it’s important to understand where things stand now: Russian cyber-criminal organizations are some of the biggest perpetrators of cryptocurrency-based crime – especially ransomware – and local cryptocurrency businesses provide money laundering services that enable this activity. 2021 saw positive momentum against this issue, from the seizure of funds from ransomware organization DarkSide to the sanctioning of Suex and Chatex.”

Last week, Chainalysis revealed it had observed the average ransomware payment size to have surged in recent years, from $25,000 in 2019 to $88,000 a year later and $118,000 in 2021.

Source link

Linked Payments ransomware Russia ThreeQuarters

Related Posts

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026

US seized $500M in Iranian crypto assets, Treasury secretary says

May 2, 2026

Wasabi Protocol drained for $4.5 million in apparent admin key compromise

May 2, 2026

Tax season fuels rise in crypto wallet scams, Kaspersky reports

May 2, 2026
Top Posts

Black Gold, Bond Yields, & The Buck Tumble Amid Macro Miasma

October 4, 2023

How Mobile Apps Are Quietly Adopting Web3 Tech

May 2, 2026

SEC Asks Court for Summary Judgement Against Do Kwon, Terraform

November 3, 2023

Type above and press Enter to search. Press Esc to cancel.