The AudiA6 ransomware laundering service has been dismantled by authorities from 11 countries, with two individuals arrested in Georgia accused of running a cryptocurrency laundering network that processed more than $380 million in criminal proceeds. The takedown, supported by Europol and Eurojust, culminated in arrests, property searches, domain seizures and the freezing of hundreds of thousands of euros in cryptocurrency.
According to Europol, AudiA6 operated as an industrial-scale laundering hub between 2022 and 2025, built around thousands of fraudulent exchange accounts opened using stolen or purchased identities. Europol linked the service to more than 15 distinct international investigations involving ransomware attacks and large-scale cryptocurrency theft.
How the AudiA6 ransomware laundering service worked
AudiA6 marketed itself as a professional cryptocurrency mixing service. In practice, it accepted cybercrime proceeds, routed the funds through complex transaction chains to obscure their origin, and returned the ‘cleaned’ money to clients within roughly an hour. The report describes a commission of 3-10% charged on each transaction, while Sherwood News reported that the service charged fees of up to 5% of the amount laundered.
Past reporting from Intel471 and blockchain investigator ZachXBT had already flagged AudiA6 for facilitating illegal activity, but the platform continued operating until the international law enforcement action finally shut it down.
The U.S. Department of Justice provided granular detail on the funds flowing through the platform. Of approximately 10,333 bitcoin deposited into AudiA6 wallets, approximately 393.39 BTC, valued at around $19,234,331 at the time of the transactions, were received directly from known darknet markets, ransomware organisations, cybercrime services and other illicit sources. Additional funds arrived indirectly from illicit origins.
Arrests, seizures and the Georgian operation
The breakthrough came in Poland in September 2025, when authorities arrested a Ukrainian national linked to AudiA6. Forensic examination of that suspect’s devices allowed investigators to identify key individuals behind the operation and trace them to Georgia, where the main action took place.
As a result of that action, authorities arrested two individuals in Georgia, searched three properties, seized 25 domains, and seized 80 vehicles and properties. Investigators also seized €86,000 in cryptocurrency and froze a further €692,000, while Telegram accounts used by the network were blocked.
The DoJ named the two arrested individuals as Ruslan Igorevich Tkachuk, aged 37, and Alexander Vladimirovich Ledenev, aged 25, described as senior members of the AudiA6 platform. Europol says the pair are believed to be administrators of AudiA6 and also of the underground forum Dark2Web, which cybercriminals used to advertise illicit services. Both AudiA6 and the Dark2Web website now display seizure notices. The two remain in the custody of Georgian authorities and face sentences of up to 20 years in prison for facilitating cybercrime laundering operations.
A money mule network built on stolen identities
Beyond the two administrators, the investigation recovered 6,000 Know-Your-Customer (KYC) records linked to money mule accounts. Europol says these accounts were created using stolen or purchased identities and that many are connected to Russian-speaking intermediaries who recruited them specifically for this purpose.
The network used multiple domains to register accounts on cryptocurrency exchanges, a detail Europol published specifically to raise awareness and help platforms identify and block the associated accounts. The scale of the KYC record cache underlines how systematically the operation had industrialised its identity fraud, assembling what amounts to a ready roster of false personas to keep funds moving across exchanges without triggering the checks those platforms are required to run.
The investigation involved authorities from 11 countries spanning Europe, America and Asia. With the two administrators now in Georgian custody, the focus will shift to extradition proceedings and the question of what further intelligence the 6,000 recovered KYC records will yield about the broader network of money mules and the ransomware groups that relied on AudiA6 to clean their earnings.

