The Cybercrime Supply Chain & Laundering
Cybercrime operates as a supply chain rather than a set of individual hackers. No modern criminal operation builds malware, breaks in, exfiltrates data, extorts the victim, and launders the proceeds itself; each of those is a specialized firm selling a service to the next link, as a manufacturing economy decomposes into component suppliers, assemblers, distributors, and financiers. Chainalysis's 2026 Crypto Crime Report (covering calendar 2025) put a number on the financial tail: illicit crypto addresses received at least $154B in 2025, a 162% jump driven overwhelmingly by sanctioned entities, with stablecoins now 84% of illicit transaction volume. Reading the chain link-by-link is what lets any single threat headline be read as a demand signal for a specific defensive sub-segment. The sections below walk the chain from the first intrusion to the final cash-out, name the actors at each stage, and map each link to the defensive market it funds.
The chain: specialization is the point
The chain has five recurring stages, and the durable insight is that the labor and the relationships — not any single brand — are the assets. When law enforcement seizes an operator (LockBit, 15a), the developers, access brokers, mule networks, and launderers simply re-contract with the next brand. Decapitating one firm degrades a firm; it does not remove the capability stack the next entrant can rent on day one.
1 — Developers (Malware-as-a-Service). The product layer: ransomware kits, infostealers, loaders, and phishing kits sold by subscription. Infostealer MaaS is the breakout franchise — Lumma Stealer subscriptions start around $250/month, and the category drove an estimated 1.8B+ stolen credentials in 2025 (KELA tracked ~2.86B compromised credentials circulating; the "Synthient" dataset aggregated ~23B rows). Developers rarely break into anything; they sell tools to those who do.
2 — Initial-access brokers (IABs). The wholesalers of entry, covered in depth in 15b. They harvest the developers' infostealer output, validate which logs contain corporate access, and resell that access — stealer logs go for $1–100+, while curated network access sells for hundreds to thousands of dollars. Verizon's 2025 DBIR found 54% of ransomware-extortion victims had prior infostealer logs containing their domain credentials — the cleanest evidence that the credential supply chain feeds the extortion supply chain, sometimes in under 48 hours.
3 — Operators (the brand). The assemblers who run the actual intrusion and monetization — ransomware crews, BEC rings, fraud operations. They buy access from IABs, deploy developer tooling, and own the customer-facing "brand" (the leak site, the negotiation portal). This is the link that appears in headlines and the link law enforcement targets — and the one most easily replaced.
4 — Cash-out crews. Negotiators, "customer support," and money mules who convert access into realized funds — the people who move a fraudulent wire through layered accounts or extract a ransom payment. In BEC (15d), this is the mule network; in ransomware, the negotiation and payment-handling staff.
5 — Launderers. The financiers who clean the proceeds — the focus of the rest of this page.
The marketplace layer: guarantee escrow markets
The links of the chain transact with one another through "guarantee" marketplaces — Telegram-based escrow markets, largely Chinese-language and centered on Southeast Asia's scam economy, where merchants sell stolen personal data, money-laundering services, pre-built scam infrastructure, and deception tooling (face-swap software, AI voice cloning, deepfakes). The marketplace's escrow function is what makes arms-length trade between criminal specialists possible: buyers are assured delivery, sellers are assured payment. The scale is banking-sized. Huione Guarantee processed over $27B before Telegram shut it down in May 2025 following Elliptic's research exposing its operations — the largest illicit marketplace ever recorded. Its designated successor, Tudou Guarantee (Huione had acquired a 30% stake in Tudou in December 2024), absorbed the migrating merchant base within weeks and went on to process over $12B — the third-largest illicit marketplace of all time — before it, too, ceased transacting through its public Telegram groups in January 2026. Elliptic's wallet monitoring ties the wind-down to enforcement against the Prince Group: US Treasury and UK sanctions on the group and its chairman Chen Zhi in October 2025, then Chen Zhi's arrest and extradition to China on January 6, 2026, with Tudou's central administrative wallets going quiet in the days that followed.
The aftermath illustrates the chain's resilience logic. Three successor platforms — Ouyi, Tiancheng, and Timi — each publicly claimed to have acquired Tudou's infrastructure; blockchain and Telegram analysis reported in July 2026 indicates they operate independently, with separate administrators and escrow wallet clusters, and that Tiancheng inherited the most valuable assets, including Tudou's primary Telegram channels with more than 570,000 members. Each takedown has so far produced fragmentation rather than elimination — the merchants, customer relationships, and escrow mechanics reconstitute on the next venue. Enforcement is nonetheless compounding: the US Department of Justice's Scam Center Strike Force (launched late 2025) had seized over $400M in cryptoassets, and every marketplace transaction leaves a permanent on-chain record — the data layer the blockchain-analytics vertical monetizes.
Sanctions reach the chain's suppliers
Enforcement is also moving up the chain from operators to their commercial vendors. On July 13, 2026, OFAC designated First VPN Service (1VPNS) — a VPN provider whose principal clients include ransomware groups, advertised on cybercriminal forums since 2014 — along with its administrator Dmytro Rashevskyi, and Yegeniy Vladimirovich Silayev, a seller of "cryptors" (tools that disguise ransomware as safe programs to evade detection). Victims of attacks that used 1VPNS infrastructure included US businesses, hospitals, financial-services firms, and municipal governments. The action was coordinated with the UK's Foreign, Commonwealth & Development Office, which sanctioned other cybercriminal enablers the same day, and followed a May 2026 takedown of 1VPNS's website and infrastructure by European law enforcement with FBI support. The pattern reads directly onto the supply-chain frame: rather than pursuing only the ransomware "brand" (the most replaceable link), sanctions now target the infrastructure and obfuscation-tool suppliers whose services many brands rent — an attempt to degrade the capability stack itself rather than a single firm.
Criminal prosecution is following the same path. On July 14, 2026, the US Department of Justice unsealed a 13-count indictment in the Northern District of Ohio against three Russian nationals — Alexander Volosovik, Kirill Zatolokin, and Yulia Pankova — and two St. Petersburg companies, Media Land and ML.Cloud, which operated "bulletproof hosting" services: leased internet infrastructure marketed to criminals as beyond the reach of law enforcement. The infrastructure allegedly supported ransomware, malware, phishing, and brute-force attacks against US banks, hospitals, schools, government agencies, and media companies, causing more than $62 million in losses across 44 identified victims in 21 states; charges include conspiracy to commit computer fraud, wire fraud (10 counts), and money-laundering conspiracy (DOJ, Jul 14 2026 · TechCrunch). Taken with the 1VPNS designations announced the previous day, the two actions mark a coordinated week in which both sanctions and criminal indictments targeted the rented infrastructure layer — hosting, VPN, and obfuscation tooling — that multiple criminal brands depend on simultaneously.
West African fraud networks and their outsourced suppliers
The sections above draw on Russian-speaking ransomware and the Chinese-language scam economy of Southeast Asia. Interpol's Operation Jackal IV documents the same division of labour in a third criminal ecosystem. The operation ran from November 2025 to June 2026 — eight months — and brought together 22 countries across six continents against West African criminal networks, among them Black Axe, which Interpol describes as responsible for a significant share of the world's cyber-enabled financial fraud, typically romance scams, cryptocurrency and investment scams, and business email compromise (15d). Results were published on August 25, 2026: 263 suspects identified and 58 arrests (Interpol, Aug 25 2026 · Infosecurity Magazine, Aug 26 2026).
Interpol presents the national results as preliminary outcomes, with many cases still under investigation, and they do not sum to the headline figure: the three itemized actions reporting arrests — 39 in South Africa, 17 in Argentina and 11 in Romania — total 67, which exceeds the stated 58 by nine. No reconciliation is published. The national figures below are recorded as stated, and no operation-wide total is derived from them.
- Argentina. Investigators identified 196 individuals in a Crime-as-a-Service network suspected of supplying website domains and money-laundering support to West African groups, and arrested 17. Whether these 196 fall within the 263 suspects identified operation-wide is not stated, and the two counts are not combined here.
- South Africa. Seven locations in Johannesburg were raided in connection with a syndicate running romance and investment scams against retirees in English-speaking countries. Authorities seized USD 2.67 million, blocked 257 bank accounts and arrested 39 people. Interpol notes the syndicate assigned members to distinct stages of the scam as "conversion" or "retention" agents.
- Romania. A call-centre operation promoting high returns in stocks or cryptocurrencies was dismantled, with victim funds diverted to wallets the perpetrators controlled. Interpol puts the sum stolen and laundered globally at an estimated EUR 143 million; 11 people were arrested and approximately EUR 330,000 in cash and cryptocurrency, six properties and several luxury watches were seized. The seizure is roughly 0.2% of the estimated flow — about one part in 430.
- Italy. One individual was identified in a pan-European laundering network using shell companies, remittance services and cash withdrawals. A single account moved EUR 845,000 across 560 transactions through 20 different financial instruments — an average near EUR 1,500 per transaction, and roughly 28 transactions per instrument.
Two of these describe the chain rather than the caseload. The South African structure divides a single scam into specialist roles, so that no individual performs the whole fraud — the same logic that separates access brokers from operators in the ransomware economy, applied inside one firm rather than across a market. The Argentine network describes the market form: infrastructure and laundering sold as a service, from a fourth jurisdiction, to operators in another region. Interpol records separately that some of these syndicates procured Crime-as-a-Service from external providers, often through the dark web, to outsource money laundering and other core activities. The specialization thesis of this page therefore holds in a criminal economy built on fraud rather than on ransomware, and it again locates the durable capability in the supplier tier rather than in the operators whose arrests are counted.
Two cautions on the figures. The release's dollar conversions are mutually inconsistent — EUR 330,000 is given as USD 379,000 and EUR 845,000 as USD 736,000, implying rates of 1.15 and 0.87 dollars to the euro respectively, which cannot both hold. The euro amounts are used above and no dollar equivalent is asserted for either. Separately, the predecessor operation Jackal III produced 300 arrests in 2024; that total is not compared with this one, because the operations differ in duration and scope and the present counts do not internally reconcile.
Laundering: where the money gets clean
Once funds are realized, the proceeds must be placed, layered, and integrated back into the legitimate economy. The 2025 data reshaped what this looks like:
- Stablecoins dominate. They are now 84% of all illicit transaction volume — criminals prefer them for cross-border transferability, low volatility, and broad acceptance. The irony for defenders is that stablecoins are also more traceable and freezable than cash, which is why issuer freezes and on-chain analytics have become a meaningful disruption tool.
- Sanctions evasion is the new center of gravity. Value received by sanctioned entities surged 694% to $104B in 2025. Russia's ruble-backed A7A5 token alone facilitated an estimated $93.3B in sanctions-related flows — a state-scale laundering rail, not a criminal-scale one. North Korean actors stole ~$2B in 2025 (the state-criminal blur detailed in 15c).
- The laundering toolkit: mixers/tumblers (e.g., the Tornado Cash precedent), cross-chain bridges and chain-hopping, OTC brokers and "nested" exchange accounts, no-KYC and high-risk exchanges, and increasingly DeFi protocols used as layering venues. The defender's countermeasure is blockchain analytics and crypto-compliance tooling (Chainalysis, TRM Labs, Elliptic) sold to exchanges, banks, and governments — a defensive sub-segment that exists only because of this link in the chain.
The strategic point: the traceability of crypto cuts against the launderer. Unlike physical cash, on-chain value leaves a permanent ledger, which is why seizures and freezes have become a credible disruption lever and why illicit activity remains under 1% of total crypto volume. The arms race here is laundering technique vs. on-chain forensics — a self-funding defensive market.
Why this matters: the chain is the demand schedule
| Supply-chain link | Criminal product | Defensive counter-market | M&A read |
|---|---|---|---|
| Developers (MaaS) | Malware, infostealers, kits | EDR/XDR, sandboxing, malware analysis | Endpoint consolidation (03c); AI-security (03l) |
| Access brokers | Validated corporate access | Identity, MFA, ITDR, exposure mgmt | Identity wave (03a); CTEM (03k) |
| Operators | Intrusion + extortion brand | Backup/recovery, MDR, IR | Rubrik/Cohesity; MDR roll-ups (04b); DFIR (04e) |
| Cash-out crews | Mule + fraud monetization | Fraud detection, payment verification, DLP | BEC defense (15d); data security (03g) |
| Launderers | Mixing, bridging, sanctions rails | Blockchain analytics, crypto compliance | Chainalysis/TRM/Elliptic — a distinct, fundable vertical |
Falsifiable bear case
(1) The crypto cash-out could be regulated into friction. If stablecoin issuers, exchanges, and bridges are pushed under hard KYC/AML enforcement faster than launderers can adapt, the monetization link narrows — degrading the unit economics of the whole chain and rotating demand away from the categories tied to today's extortion tactics. (2) On-chain forensics could commoditize. Blockchain-analytics value depends on proprietary attribution data; if attribution becomes a shared utility (or stablecoin issuers build native freezing), the standalone analytics premium compresses. (3) The chain could re-bundle. A sufficiently capable, well-capitalized actor (a nation-state proxy) could vertically integrate the chain, reducing the number of independent links — which would change which defensive categories the threat funds, even if total demand holds. The bear case is not "crime ends"; it is "the cash-out and laundering links get squeezed, repricing the extortion-linked defensive pools" — which is exactly why reading the chain is an investment discipline.
/ angle
→ The supply chain is a sub-segment map. Each link is a defensive vertical with its own consolidation clock. For buy-side mandates, the chain tells you where in the kill-chain a target sits and therefore which acquirers structurally need it — endpoint buyers want the developer-link counters, identity buyers want the access-link counters, and so on. It turns "is this a good company?" into "which link does it defend, and who must own that link?"
→ Crypto-compliance/blockchain-analytics is an under-covered adjacency. It is a defensive vertical funded entirely by the laundering link, with a small named set (Chainalysis, TRM Labs, Elliptic) and growing government/financial-institution demand — a coherent thesis for a specialist mandate distinct from the core security stack.
Sources: Elliptic — Tudou Guarantee winds down after $12B in transactions (Jan 19 2026) · eSecurity Planet — Tudou Guarantee successors expand cybercrime marketplace (Jul 2026) · US Treasury — sanctions on malware and infrastructure providers supporting ransomware (Jul 13 2026) · Chainalysis — 2026 Crypto Crime Report introduction · The Block — crypto crime topped $150B in 2025 · CoinDesk — sanctions evasion via crypto +694% in 2025 · DeepStrike — stealer log statistics 2025 · Shattered.io — infostealers stole 1.8B credentials in 2025 · Constella — 48 hours between infection and dark-web sale
Updated 2026-10-04 19:34 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.