Key Highlights
- International law enforcement coalition spanning 11 nations successfully dismantled the AudiA6 cryptocurrency laundering operation
- The criminal network facilitated the movement of approximately 10,333 BTC, with a historical value approaching $389 million, beginning in 2021
- Georgian authorities apprehended two key operators — individuals from Ukraine and Russia — with US extradition proceedings underway
- The operation exploited more than 6,000 fraudulent KYC-verified accounts to channel illicit cryptocurrency through legitimate trading platforms
- Law enforcement simultaneously seized Dark2Web, a marketplace facilitating criminal service advertisements
A coordinated international law enforcement effort has successfully dismantled AudiA6, a sophisticated cryptocurrency laundering operation that facilitated approximately $390 million in illegal transactions spanning four years. The operation simultaneously neutralized Dark2Web, an associated darknet platform serving the criminal ecosystem.
Georgian law enforcement detained two primary suspects believed to be running the operation — a 37-year-old Ukrainian citizen and a 25-year-old Russian national. American prosecutors are currently pursuing extradition proceedings for both individuals.
The multinational operation was orchestrated through Eurojust and Europol, bringing together investigative resources from the United States, Australia, France, Germany, the United Kingdom, Canada, Japan, Switzerland, Iceland, Poland, and the Republic of Georgia.
The Mechanics Behind AudiA6’s Operation
AudiA6 functioned as a commercial mixing service for cryptocurrency. The platform accepted tainted digital assets from ransomware operators and various cybercriminal entities, returning sanitized funds — typically within 60 minutes — while collecting fees ranging from 3% to 10% per transaction.
Blockchain intelligence provider Chainalysis determined that the network processed roughly 10,333 Bitcoin from its 2021 inception, representing a historical valuation of approximately $389 million.
Forensic analysis identified at least 393 [[LINK_START_0]]BTC[[LINK_END_0]] — currently valued above $19 million — originating directly from confirmed ransomware operations and darknet marketplaces. More than $16 million specifically connected to ransomware campaigns and theft was sanitized through the platform.
The criminal enterprise compromised legitimate cryptocurrency exchanges by channeling funds through an extensive network of over 6,000 fraudulent KYC-verified accounts. These compromised “money mule” profiles had successfully cleared identity verification protocols, significantly complicating detection efforts.
Chainalysis investigators additionally established connections between AudiA6’s withdrawal infrastructure and sanctioned Russian cryptocurrency platforms, including Bitzlato and Garantex, along with Exploit.in, a Russian-language cybercrime community.
Dark2Web Marketplace Eliminated
Concurrent with the AudiA6 takedown, authorities eliminated Dark2Web — a marketplace platform facilitating connections between cybercriminals and promoting illegal services internationally.
Both clearnet and darknet iterations of these platforms now display official law enforcement seizure notifications. The operation resulted in the confiscation of 25 domain names, over 30 servers, and 80 vehicles. Approximately $900,000 in cryptocurrency assets was frozen.
According to Australian Federal Police, AudiA6 also processed portions of ransom payments made by an Australian corporation following a 2024 ransomware incident.
This enforcement action arrives amid sustained ransomware activity globally. Ransomware incidents were documented across 97 nations during the first quarter of 2026. American organizations represented 64.7% of all documented victims, per Emsisoft data.
Check Point Research revealed in May that the ten most active ransomware operations accounted for 71% of all victims during Q1 2026, indicating increasing concentration among fewer but more prolific criminal groups.
The AudiA6 investigation demonstrates that authorities are now systematically targeting the financial infrastructure supporting cybercrime operations — extending beyond the attacks themselves.
Investigators employed blockchain forensics to map transaction flows, associate digital wallets with physical operators, and connect exchange profiles to criminal networks — techniques that have become increasingly standard in cryptocurrency-related enforcement operations.





