Representatives of the Russian cybercrime group are using a Canadian company with a complex structure to launder money. This is the conclusion reached by blockchain analyst and investigator Richard Sanders, who spent most of the last year in Ukraine investigating the changing landscape of Russian crypto exchanges, as reported by information security journalist Brian Krebs. Sanders spent most of the last year in Ukraine investigating the changing landscape of Russian crypto exchanges.
In total, his material mentions 122 services. Some of them are bulletproof hosting providers, others sell various accounts, and others are SMS services. All of them process their transactions through Cryptomus, a company based in Vancouver, Canada. The data collected by Sanders indicates that 56 other cryptocurrency exchanges use Cryptomus. Among them are services such as casher[.]su, grumbot[.]com, flymoney[.]biz, obama[.]ru and swop[.]is. All of them are aimed at users from Russia.
The small three-story building where Cryptomus is officially registered is officially home to 76 other currency dealers, six exchanges and eight financial services companies. However, in reality, it houses a massage parlor and a co-working space that has never provided any services to the aforementioned organizations.
The parent company for Cryptomus is listed as Xeltox Enterprises, formerly Certa Payments. A firm of the same name was registered in London in December 2023. Its sole shareholder and director is a 25-year-old Czech-born Ukrainian named Vira Krychka. She has also recently been appointed head of several other new UK firms, some of which are nested within each other and also involved in payments.
In total, his material mentions 122 services. Some of them are bulletproof hosting providers, others sell various accounts, and others are SMS services. All of them process their transactions through Cryptomus, a company based in Vancouver, Canada. The data collected by Sanders indicates that 56 other cryptocurrency exchanges use Cryptomus. Among them are services such as casher[.]su, grumbot[.]com, flymoney[.]biz, obama[.]ru and swop[.]is. All of them are aimed at users from Russia.
The small three-story building where Cryptomus is officially registered is officially home to 76 other currency dealers, six exchanges and eight financial services companies. However, in reality, it houses a massage parlor and a co-working space that has never provided any services to the aforementioned organizations.
“We see ransomware, drug dealers, fraudsters, darknet marketplace owners and sanctioned organizations transferring money to Cryptomus to make purchases there, and laundering it using the payment API,” the researchers from Chainanlysis said in a statement.
The parent company for Cryptomus is listed as Xeltox Enterprises, formerly Certa Payments. A firm of the same name was registered in London in December 2023. Its sole shareholder and director is a 25-year-old Czech-born Ukrainian named Vira Krychka. She has also recently been appointed head of several other new UK firms, some of which are nested within each other and also involved in payments.