PULSE NAME
Anatomy of a Russian Crypto Drainer Operation
WHITE Rublevka Team AlienVault 2026-02-04 Modified: 2026-03-06
48
IOCs
MEDIUM VOLUME
A major cybercriminal operation called Rublevka Team has generated over $10 million through cryptocurrency theft since 2023. The group employs a network of social engineering specialists who direct victims to malicious pages impersonating legitimate crypto services. Using custom JavaScript scripts, they trick users into connecting wallets and authorizing fraudulent transactions. Rublevka Team's infrastructure is fully automated, offering affiliates access to tools for launching high-volume scams. Their model poses a growing threat to cryptocurrency platforms and brands, with potential for reputational and legal risks. The group's agility in rotating domains and targeting lower-cost chains like Solana undermines traditional fraud detection efforts.
Indicators of Compromise (1 / 48 total)
All URL FileHash-MD5 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 730eede4c040eafa7a928a503b6cd650 2026-02-04