{"id":1497,"date":"2025-01-13T18:33:20","date_gmt":"2025-01-13T18:33:20","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=1497"},"modified":"2025-01-13T18:33:20","modified_gmt":"2025-01-13T18:33:20","slug":"us-attacks-ransomware-supply-chain-with-indictment-of-three-cryptocurrency-mixer-operators","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=1497","title":{"rendered":"US attacks ransomware supply chain with indictment of three cryptocurrency mixer operators"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p>The US Department of Justice indicted three Russian citizens on Friday for allegedly running services that helped criminals launder cryptocurrency; the services are suspected to have been used to hide the proceeds of ransomware attacks.<\/p>\n<p>The US Department of Treasury\u2019s Office of Foreign Assets Control (OFAC) had previously sanctioned the two cryptocurrency mixer services the accused are alleged to have operated, <a href=\"https:\/\/home.treasury.gov\/news\/press-releases\/jy0768\">Blender.io<\/a> and <a href=\"https:\/\/home.treasury.gov\/news\/press-releases\/jy1933\">Sinbad.io<\/a>, charging that they were used to launder virtual currencies.<\/p>\n<p>\u201cBy allegedly operating these mixers, the defendants made it easier for state-sponsored hacking groups and other cybercriminals to profit from offenses that jeopardized both public safety and national security,\u201d said the head of the Justice Department\u2019s Criminal Division, principal deputy assistant attorney general Brent Wible, in a <a href=\"https:\/\/www.justice.gov\/opa\/pr\/operators-cryptocurrency-mixers-charged-money-laundering\">statement<\/a>.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Part of ransomware takedown<\/h2>\n<p>The now-defunct platforms, Blender.io and Sinbad.io, enabled users to obscure the origins of their cryptocurrency funds for a fee, according to court documents and public records. They became a go-to for criminals, particularly those involved in ransomware attacks, to hide that their illicit gains stemmed from such cybercrimes.<\/p>\n<p>The earlier sanctions on the mixers, and now the indictments of those accused of operating them, appear to be part of a wider global law enforcement campaign against <a href=\"https:\/\/www.csoonline.com\/article\/2067614\/no-easy-solutions-to-the-ransomware-threat-despite-takedowns.html\">ransomware operators and those that enable them<\/a>.<\/p>\n<p>OFAC\u2019s announcement of sanctions on Blender.io had highlighted that the mixer was found facilitating money-laundering for Russian-linked ransomware groups including<a href=\"https:\/\/www.csoonline.com\/article\/570169\/trickbot-explained-a-multi-purpose-crimeware-tool-that-haunted-businesses-for-years.html\"> Trickbot<\/a>,<a href=\"https:\/\/www.csoonline.com\/article\/571503\/conti-ransomware-explained-and-why-its-one-of-the-most-aggressive-criminal-groups.html\"> Conti<\/a>,<a href=\"https:\/\/www.csoonline.com\/article\/569343\/ryuk-explained-targeted-devastatingly-effective-ransomware.html\"> Ryuk<\/a>,<a href=\"https:\/\/www.csoonline.com\/article\/567851\/gandcrab-cousin-sodinokibi-made-a-fortune-for-ransomware-pushers.html\"> Sodinokibi, and Grandcrab<\/a>.<\/p>\n<p>Active from 2018 to 2022, Blender.io advertised itself as a no-logs cryptocurrency mixer requiring no user details, ensuring anonymity. After Blender\u2019s shutdown, Sinbad.io offered similar services until law enforcement took it down on November 27, 2023.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Still at large<\/h2>\n<p>Roman Vitalyevich Ostapenko, 55, faces charges of one count of conspiracy to commit money laundering and two counts of operating an unlicensed money transmitting business. Alexander Evgenievich Oleynik, 44, and Anton Vyachlavovich Tarasov, 32, are charged with one count each of conspiracy to commit money laundering and operating an unlicensed money transmitting business.<\/p>\n<p>If found guilty, each defendant could receive up to 20 years in prison for the money laundering conspiracy and five years for each count of operating an unlicensed money transmitting business, according to Justice Department.<\/p>\n<p>While Ostapenko and Oleynik were reportedly arrested on Dec. 1, 2024, Tarasov remains at large.<\/p>\n<p>The US Justice Department said the Netherlands\u2019 Public Prosecution Service and Fiscal Information and Investigative Service played a key role in the case, contributing to the disruption of the Sinbad mixer and offering other valuable assistance.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>The US Department of Justice indicted three Russian citizens on Friday for allegedly running services that helped criminals launder cryptocurrency; the services are suspected to have been used to hide the proceeds of ransomware attacks. The US Department of Treasury\u2019s Office of Foreign Assets Control (OFAC) had previously sanctioned the two cryptocurrency mixer services the [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":1498,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-1497","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/1497"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1497"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/1497\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/1498"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1497"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1497"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1497"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}