PULSE NAME
IOC - Rublevka Team: Anatomy of a Russian Crypto Drainer Operation
WHITE celestre 2026-02-05 Modified: 2026-03-07
33
IOCs
MEDIUM VOLUME
Insikt Group has identified a major cybercriminal operation specializing in large-scale cryptocurrency theft, operating under the moniker “Rublevka Team”. Since its inception in 2023, the threat group has generated over $10 million through affiliate-driven wallet draining campaigns. Rublevka Team is an example of a “traffer team,” composed of a network of thousands of social engineering specialists tasked with directing victim traffic to malicious pages. Unlike traditional malware-based approaches such as those used by the traffer teams Marko Polo and CrazyEvil (previously identified by Insikt Group, both of which distributed infostealer malware), Rublevka Team deploys custom JavaScript scripts via spoofed landing pages that impersonate legitimate crypto services, tricking victims into connecting their wallets and authorizing fraudulent transactions.
Indicators of Compromise (1 / 33 total)
All URL FileHash-MD5 FileHash-SHA256 domain email hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 730eede4c040eafa7a928a503b6cd650 2026-02-05