The Cybercrime Supply Chain & Laundering
Cybercrime operates as a supply chain rather than a set of individual hackers. No modern criminal operation builds malware, breaks in, exfiltrates data, extorts the victim, and launders the proceeds itself; each of those is a specialized firm selling a service to the next link, as a manufacturing economy decomposes into component suppliers, assemblers, distributors, and financiers. Chainalysis's 2026 Crypto Crime Report (covering calendar 2025) put a number on the financial tail: illicit crypto addresses received at least $154B in 2025, a 162% jump driven overwhelmingly by sanctioned entities, with stablecoins now 84% of illicit transaction volume. Reading the chain link-by-link is what lets any single threat headline be read as a demand signal for a specific defensive sub-segment. The sections below walk the chain from the first intrusion to the final cash-out, name the actors at each stage, and map each link to the defensive market it funds.
The chain: specialization is the point
The chain has five recurring stages, and the durable insight is that the labor and the relationships — not any single brand — are the assets. When law enforcement seizes an operator (LockBit, 15a), the developers, access brokers, mule networks, and launderers simply re-contract with the next brand. Decapitating one firm degrades a firm; it does not remove the capability stack the next entrant can rent on day one.
1 — Developers (Malware-as-a-Service). The product layer: ransomware kits, infostealers, loaders, and phishing kits sold by subscription. Infostealer MaaS is the breakout franchise — Lumma Stealer subscriptions start around $250/month, and the category drove an estimated 1.8B+ stolen credentials in 2025 (KELA tracked ~2.86B compromised credentials circulating; the "Synthient" dataset aggregated ~23B rows). Developers rarely break into anything; they sell tools to those who do.
2 — Initial-access brokers (IABs). The wholesalers of entry, covered in depth in 15b. They harvest the developers' infostealer output, validate which logs contain corporate access, and resell that access — stealer logs go for $1–100+, while curated network access sells for hundreds to thousands of dollars. Verizon's 2025 DBIR found 54% of ransomware-extortion victims had prior infostealer logs containing their domain credentials — the cleanest evidence that the credential supply chain feeds the extortion supply chain, sometimes in under 48 hours.
3 — Operators (the brand). The assemblers who run the actual intrusion and monetization — ransomware crews, BEC rings, fraud operations. They buy access from IABs, deploy developer tooling, and own the customer-facing "brand" (the leak site, the negotiation portal). This is the link that appears in headlines and the link law enforcement targets — and the one most easily replaced.
4 — Cash-out crews. Negotiators, "customer support," and money mules who convert access into realized funds — the people who move a fraudulent wire through layered accounts or extract a ransom payment. In BEC (15d), this is the mule network; in ransomware, the negotiation and payment-handling staff.
5 — Launderers. The financiers who clean the proceeds — the focus of the rest of this page.
The marketplace layer: guarantee escrow markets
The links of the chain transact with one another through "guarantee" marketplaces — Telegram-based escrow markets, largely Chinese-language and centered on Southeast Asia's scam economy, where merchants sell stolen personal data, money-laundering services, pre-built scam infrastructure, and deception tooling (face-swap software, AI voice cloning, deepfakes). The marketplace's escrow function is what makes arms-length trade between criminal specialists possible: buyers are assured delivery, sellers are assured payment. The scale is banking-sized. Huione Guarantee processed over $27B before Telegram shut it down in May 2025 following Elliptic's research exposing its operations — the largest illicit marketplace ever recorded. Its designated successor, Tudou Guarantee (Huione had acquired a 30% stake in Tudou in December 2024), absorbed the migrating merchant base within weeks and went on to process over $12B — the third-largest illicit marketplace of all time — before it, too, ceased transacting through its public Telegram groups in January 2026. Elliptic's wallet monitoring ties the wind-down to enforcement against the Prince Group: US Treasury and UK sanctions on the group and its chairman Chen Zhi in October 2025, then Chen Zhi's arrest and extradition to China on January 6, 2026, with Tudou's central administrative wallets going quiet in the days that followed.
The aftermath illustrates the chain's resilience logic. Three successor platforms — Ouyi, Tiancheng, and Timi — each publicly claimed to have acquired Tudou's infrastructure; blockchain and Telegram analysis reported in July 2026 indicates they operate independently, with separate administrators and escrow wallet clusters, and that Tiancheng inherited the most valuable assets, including Tudou's primary Telegram channels with more than 570,000 members. Each takedown has so far produced fragmentation rather than elimination — the merchants, customer relationships, and escrow mechanics reconstitute on the next venue. Enforcement is nonetheless compounding: the US Department of Justice's Scam Center Strike Force (launched late 2025) had seized over $400M in cryptoassets, and every marketplace transaction leaves a permanent on-chain record — the data layer the blockchain-analytics vertical monetizes.
Sanctions reach the chain's suppliers
Enforcement is also moving up the chain from operators to their commercial vendors. On July 13, 2026, OFAC designated First VPN Service (1VPNS) — a VPN provider whose principal clients include ransomware groups, advertised on cybercriminal forums since 2014 — along with its administrator Dmytro Rashevskyi, and Yegeniy Vladimirovich Silayev, a seller of "cryptors" (tools that disguise ransomware as safe programs to evade detection). Victims of attacks that used 1VPNS infrastructure included US businesses, hospitals, financial-services firms, and municipal governments. The action was coordinated with the UK's Foreign, Commonwealth & Development Office, which sanctioned other cybercriminal enablers the same day, and followed a May 2026 takedown of 1VPNS's website and infrastructure by European law enforcement with FBI support. The pattern reads directly onto the supply-chain frame: rather than pursuing only the ransomware "brand" (the most replaceable link), sanctions now target the infrastructure and obfuscation-tool suppliers whose services many brands rent — an attempt to degrade the capability stack itself rather than a single firm.
Criminal prosecution is following the same path. On July 14, 2026, the US Department of Justice unsealed a 13-count indictment in the Northern District of Ohio against three Russian nationals — Alexander Volosovik, Kirill Zatolokin, and Yulia Pankova — and two St. Petersburg companies, Media Land and ML.Cloud, which operated "bulletproof hosting" services: leased internet infrastructure marketed to criminals as beyond the reach of law enforcement. The infrastructure allegedly supported ransomware, malware, phishing, and brute-force attacks against US banks, hospitals, schools, government agencies, and media companies, causing more than $62 million in losses across 44 identified victims in 21 states; charges include conspiracy to commit computer fraud, wire fraud (10 counts), and money-laundering conspiracy (DOJ, Jul 14 2026 · TechCrunch). Taken with the 1VPNS designations announced the previous day, the two actions mark a coordinated week in which both sanctions and criminal indictments targeted the rented infrastructure layer — hosting, VPN, and obfuscation tooling — that multiple criminal brands depend on simultaneously.
Laundering: where the money gets clean
Once funds are realized, the proceeds must be placed, layered, and integrated back into the legitimate economy. The 2025 data reshaped what this looks like:
- Stablecoins dominate. They are now 84% of all illicit transaction volume — criminals prefer them for cross-border transferability, low volatility, and broad acceptance. The irony for defenders is that stablecoins are also more traceable and freezable than cash, which is why issuer freezes and on-chain analytics have become a meaningful disruption tool.
- Sanctions evasion is the new center of gravity. Value received by sanctioned entities surged 694% to $104B in 2025. Russia's ruble-backed A7A5 token alone facilitated an estimated $93.3B in sanctions-related flows — a state-scale laundering rail, not a criminal-scale one. North Korean actors stole ~$2B in 2025 (the state-criminal blur detailed in 15c).
- The laundering toolkit: mixers/tumblers (e.g., the Tornado Cash precedent), cross-chain bridges and chain-hopping, OTC brokers and "nested" exchange accounts, no-KYC and high-risk exchanges, and increasingly DeFi protocols used as layering venues. The defender's countermeasure is blockchain analytics and crypto-compliance tooling (Chainalysis, TRM Labs, Elliptic) sold to exchanges, banks, and governments — a defensive sub-segment that exists only because of this link in the chain.
The strategic point: the traceability of crypto cuts against the launderer. Unlike physical cash, on-chain value leaves a permanent ledger, which is why seizures and freezes have become a credible disruption lever and why illicit activity remains under 1% of total crypto volume. The arms race here is laundering technique vs. on-chain forensics — a self-funding defensive market.
Why this matters: the chain is the demand schedule
| Supply-chain link | Criminal product | Defensive counter-market | M&A read |
|---|---|---|---|
| Developers (MaaS) | Malware, infostealers, kits | EDR/XDR, sandboxing, malware analysis | Endpoint consolidation (03c); AI-security (03l) |
| Access brokers | Validated corporate access | Identity, MFA, ITDR, exposure mgmt | Identity wave (03a); CTEM (03k) |
| Operators | Intrusion + extortion brand | Backup/recovery, MDR, IR | Rubrik/Cohesity; MDR roll-ups (04b); DFIR (04e) |
| Cash-out crews | Mule + fraud monetization | Fraud detection, payment verification, DLP | BEC defense (15d); data security (03g) |
| Launderers | Mixing, bridging, sanctions rails | Blockchain analytics, crypto compliance | Chainalysis/TRM/Elliptic — a distinct, fundable vertical |
Falsifiable bear case
(1) The crypto cash-out could be regulated into friction. If stablecoin issuers, exchanges, and bridges are pushed under hard KYC/AML enforcement faster than launderers can adapt, the monetization link narrows — degrading the unit economics of the whole chain and rotating demand away from the categories tied to today's extortion tactics. (2) On-chain forensics could commoditize. Blockchain-analytics value depends on proprietary attribution data; if attribution becomes a shared utility (or stablecoin issuers build native freezing), the standalone analytics premium compresses. (3) The chain could re-bundle. A sufficiently capable, well-capitalized actor (a nation-state proxy) could vertically integrate the chain, reducing the number of independent links — which would change which defensive categories the threat funds, even if total demand holds. The bear case is not "crime ends"; it is "the cash-out and laundering links get squeezed, repricing the extortion-linked defensive pools" — which is exactly why reading the chain is an investment discipline.
/ angle
→ The supply chain is a sub-segment map. Each link is a defensive vertical with its own consolidation clock. For buy-side mandates, the chain tells you where in the kill-chain a target sits and therefore which acquirers structurally need it — endpoint buyers want the developer-link counters, identity buyers want the access-link counters, and so on. It turns "is this a good company?" into "which link does it defend, and who must own that link?"
→ Crypto-compliance/blockchain-analytics is an under-covered adjacency. It is a defensive vertical funded entirely by the laundering link, with a small named set (Chainalysis, TRM Labs, Elliptic) and growing government/financial-institution demand — a coherent thesis for a specialist mandate distinct from the core security stack.
Sources: Elliptic — Tudou Guarantee winds down after $12B in transactions (Jan 19 2026) · eSecurity Planet — Tudou Guarantee successors expand cybercrime marketplace (Jul 2026) · US Treasury — sanctions on malware and infrastructure providers supporting ransomware (Jul 13 2026) · Chainalysis — 2026 Crypto Crime Report introduction · The Block — crypto crime topped $150B in 2025 · CoinDesk — sanctions evasion via crypto +694% in 2025 · DeepStrike — stealer log statistics 2025 · Shattered.io — infostealers stole 1.8B credentials in 2025 · Constella — 48 hours between infection and dark-web sale
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.