Major Crackdown on Cybercriminals Linked to UAPS and Cryptex
Russian authorities have executed a significant operation, arresting nearly 100 individuals connected to the anonymous payment system UAPS and the cryptocurrency exchange Cryptex.
The Investigative Committee of Russia (ICRF) reported that these arrests follow a coordinated action by U.S. and Dutch law enforcement, which recently seized web domains and disrupted infrastructure linked to these exchanges.
Notably, the U.S. government has imposed sanctions on Cryptex and a Russian individual associated with the platform, signalling an intensified effort to combat cybercrime.
What Led to the Arrests?
The extensive operation involved 148 searches across various regions of Russia, resulting in the transportation of 96 suspects to Moscow for further investigation.
A video shared by Russia’s state news agency TASS captures law enforcement officials escorting suspects from a bus to an investigator’s office for interrogations.
During the searches, authorities reported seizing an impressive 1.5 billion rubles (approximately $16 million) from the apartments of suspects in St. Petersburg.
Officials from the ICRF revealed to the local news agency Interfax that these suspects were not just ordinary criminals; they allegedly owned luxury items, including Robinson helicopters, high-end cars such as Bentley, Rolls Royce, Porsche, and the Tesla Cybertruck, as well as boats, snowmobiles, and substantial amounts of cash.
This display of wealth indicates the scale of their operations.
What Crimes Are the Suspects Facing?
The individuals arrested are likely to face multiple charges, including participation in a criminal organisation, unauthorised access to computer information, and engaging in unlawful banking operations.
Some of these charges could carry penalties of up to 20 years in prison.
According to the ICRF, these alleged criminals were involved in various illegal activities, such as cryptocurrency exchange, money transfers, and the sale of bank cards and personal accounts.
Their primary clientele included other cybercriminals and hackers who utilised Cryptex and UAPS to launder their illicit gains.
How Extensive Was Their Operation?
The investigation revealed that in 2023 alone, these services processed an astounding 112 billion rubles (around $1.2 billion), with the suspected criminals allegedly pocketing approximately 3.7 billion rubles (about $38 million).
The U.S. Treasury Department provided additional context, stating that Cryptex has received over $51.2 million since 2013 from ransomware attacks.
Moreover, it noted that transactions amounting to over $720 million were linked to services commonly used by Russia-based ransomware actors and cybercriminals, including fraud shops and mixing services.
Who Are the Key Figures in This Case?
One of the central figures in this investigation is Sergey Ivanov, a Russian national sanctioned by the U.S. last week due to his connections with illegal crypto services, particularly Cryptex and UAPS.
The U.S. Treasury accused Ivanov of laundering hundreds of millions of dollars’ worth of virtual currency for various criminal actors, including ransomware operatives, initial access brokers, and darknet marketplace vendors for nearly two decades.
“He has provided payment processing support to carding websites Rescator and Joker’s Stash,” the Treasury's allegations state.
Timur Shakhmametov, another Russian suspect known by the aliases “JokerStash” and “Vega,” has also been charged for his involvement as an operator of Joker’s Stash, a notorious online marketplace for stolen credit card information that was shut down in 2021.
In response to their significant roles in cybercrime, the Department of State has announced a reward of up to $10 million for information leading to the arrest or conviction of both Ivanov and Shakhmametov.
What’s Next for the Arrested Suspects?
An anonymous source within Russian law enforcement disclosed to Interfax that Ivanov is expected to be transported to Moscow for further investigative proceedings.
However, the specifics of his current location remain unspecified, raising questions about the effectiveness of international cooperation in such cases.
Historically, collaboration between Russia and the U.S. on cybercrime investigations has been scarce, leaving many to wonder if this situation will mark a turning point.
The Largest Crackdown on Cybercrime in Russia?
Russian media have characterised the operation against Cryptex and UAPS as potentially “the largest” crackdown in the country's crypto industry to date.
This unprecedented action reflects a growing acknowledgment of the pervasive threat posed by cybercriminals operating within Russia and highlights the shifting landscape in the fight against online crime.
Overview of Cryptex and UAPS
Cryptex is a Russian-language instant exchange service that operates both a trading platform and an exchange platform.
In January 2022, it launched CryptexPay, a payment processing service that supports Bitcoin (BTC) and Litecoin (LTC) transactions for online businesses, particularly those deemed high-risk.
CryptexPay is notably attractive to criminals due to its explicit advertising of non-compliance with Anti-Money Laundering (AML) and Know Your Customer (KYC) regulations.
UAPS, or Universal Anonymous Payment System, began in 2013 as an invite-only underground payment processor launched on a dark web forum.
It facilitates payments for various fraud shops, including well-known entities like Genesis Market and BriansClub.
Its API integration feature made it appealing for criminal enterprises seeking to finance their activities anonymously.
Following its inception, many fraud shops migrated to PinPays, a now-defunct service, indicating an effort to rebrand while retaining similar functionalities.
Currently, UAPS primarily functions as a payment processor for fraud-related activities, with minimal exchange capabilities in recent years.