Listen to this Post

Introduction: A New Chapter in Crypto Crime Enforcement
The U.S. Treasury has once again sharpened its stance against Russian-linked cryptocurrency crime, striking at the heart of a major player in illicit digital finance. In a sweeping crackdown, the Office of Foreign Assets Control (OFAC) renewed sanctions on Garantex, a crypto exchange accused of processing over \$100 million in illicit transactions since 2019. But this isn’t just about one platform—it’s about a sophisticated network of rebranding, shell companies, and global cybercriminal ties. The sanctions also target Grinex, Garantex’s alleged successor, along with key executives and associated entities in Russia and Kyrgyzstan. This move signals Washington’s determination to dismantle the infrastructure enabling ransomware attacks, darknet market trade, and sanctions evasion.
the Original Report
The U.S. Treasury’s OFAC has renewed sanctions on Garantex for facilitating ransomware actors and other cybercriminals, with over \$100 million in illicit transactions since 2019. Also sanctioned is Grinex, believed to be Garantex’s rebranded operation, plus three co-founders—Sergey Mendeleev, Aleksandr Mira Serda, and Pavel Karavatsky—and six associated firms, including InDeFi Bank, Exved, Old Vector, A7 LLC, A71 LLC, and A7 Agent LLC.
Under Secretary John K. Hurley condemned the abuse of digital assets for cybercrime, warning that laundering funds through crypto exchanges undermines both U.S. security and legitimate blockchain businesses.
Originally sanctioned in April 2022 for darknet market ties, Garantex’s domain was seized in March 2025, and co-founder Aleksej Besciokov was arrested in India. Yet, TRM Labs reported that just months later, Garantex re-emerged as Grinex, processing billions in cryptocurrency, with 82% of transactions linked to sanctioned entities.
Telegram channels promoted Grinex almost immediately after Garantex’s takedown, revealing it was registered in Kyrgyzstan in late 2024. Criminal clients used Garantex and Grinex to launder funds connected to ransomware groups such as Conti, LockBit, Black Basta, NetWalker, and Phoenix Cryptolocker.
The exchanges utilized the A7A5 stablecoin, issued by Old Vector in Kyrgyzstan, to help users regain account access post-takedown. This stablecoin reportedly moved \$1 billion per day, totaling \$41.2 billion in transactions.
Garantex was also linked to prolific money launderer Ekaterina Zhdanova, who converted \$2 million in Bitcoin to Tether (USDT) through the platform. The U.S. has placed a \$5 million bounty on Serda and \$1 million on other Garantex leaders. A7 has been sanctioned by both the U.K. and the EU.
Despite the March 2025 multinational crackdown, Garantex’s leadership swiftly activated a contingency plan, continuing illicit finance operations. The U.S. Department of Justice also seized \$2.8 million in cryptocurrency, \$70,000 in cash, and a luxury car tied to Zeppelin ransomware operator Ianis Aleksandrovich Antropenko. Additionally, over \$300 million in cybercrime-related crypto assets have been frozen in a broader global effort.
📊 What Undercode Say:
The renewed sanctions against Garantex and Grinex are a textbook example of sanctions evasion adaptation in the crypto space. The U.S. has been battling a rising wave of Russian-linked ransomware and darknet market activity, with cryptocurrency playing a central role.
Garantex’s resilience post-2022 sanctions demonstrates the cat-and-mouse dynamic between regulators and cybercriminals. By rebranding to Grinex, shifting operations to Kyrgyzstan, and deploying the A7A5 stablecoin, the network effectively insulated itself from immediate operational collapse. This highlights a troubling pattern: enforcement actions disrupt but do not permanently dismantle such networks unless global cooperation is airtight.
The A7A5 token’s reported \$1 billion daily movement is staggering—especially when we consider that such volume rivals legitimate stablecoins used in mainstream crypto trading. This suggests not just a tool for small-scale laundering, but a high-capacity illicit liquidity channel.
The U.S. Treasury’s bounty program targeting individuals like Serda reflects a pivot toward human intelligence and whistleblower-driven leads. This approach is critical because technical takedowns alone cannot eliminate the adaptive infrastructure that supports cybercrime.
The role of Zhdanova also underscores how individual actors can act as financial hubs for multiple ransomware and cybercrime syndicates. By offering conversion and off-ramping services (BTC to USDT), she provided criminals a bridge from blockchain anonymity to fiat liquidity—often the hardest part of laundering.
The seizure of Antropenko’s assets by the DOJ shows how parallel criminal investigations—targeting both service providers like Garantex and actual ransomware operators—can squeeze illicit ecosystems from multiple angles.
Yet, the fact that Grinex’s operations continued almost seamlessly after the takedown suggests that regulatory gaps in smaller jurisdictions like Kyrgyzstan remain a key vulnerability. Without regional buy-in, U.S. and EU sanctions will only push these platforms deeper into alternative legal havens.
From an economic standpoint, the billions moving through Garantex and Grinex reveal how ransomware is no longer a fringe criminal economy—it’s a parallel shadow economy with its own liquidity, exchanges, and banking systems. The intertwining of decentralized finance (DeFi) concepts with criminal operations, as seen in InDeFi Bank’s involvement, is a troubling evolution.
Ultimately, the Garantex saga serves as a case study in the resilience of illicit finance in the digital age. The integration of alternative stablecoins, offshore registration, and high-volume laundering mechanisms is becoming more sophisticated. The sanctions may slow operations, but the underlying structures remain intact—and unless there’s multi-jurisdictional enforcement combined with blockchain forensics, similar cases will continue to surface.
✅ Fact Checker Results
True: Garantex processed over \$100 million in illicit transactions since 2019.
True: Grinex is operational and processing billions despite sanctions.
True: A7A5 stablecoin moves around \$1 billion daily, per Elliptic reports.
🔮 Prediction
Given the sophistication of Garantex’s adaptation strategies, it is likely that more rebranded or proxy platforms will emerge over the next 12–18 months. Stablecoins like A7A5 could become a central laundering tool, and unless international regulators close jurisdictional loopholes, these networks will thrive under new names and corporate fronts. The next wave may focus on AI-driven transaction obfuscation and decentralized autonomous laundering platforms to further evade detection.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: thehackernews.com
Extra Source Hub:
https://www.quora.com/topic/Technology
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




