The Observatory / Document Library / Ecosystem Disruption Playbook
EDP Corpus · Document 02

Ecosystem Disruption Playbook

ECOSYSTEM DISRUPTION PLAYBOOK

Sustained Degradation of the Russia-Linked Ransomware Ecosystem

Developed by Reno

Version 2.0 | September 2026

The RENO Project | therenoproject.org

Corpus documentDoc 02Version 2.0 | September 2026

OPERATOR SNAPSHOT

Mission. Sustained ecosystem degradation, not episodic takedowns. Success is measured by compounding friction over time: actors spending more on security and reconstitution, Russian institutions treating criminals as internal liabilities, protection relationships dismantled, ransom volume and operational tempo declining across multi-quarter windows.

The 4 Phases

PhaseNameObjectiveKey Outputs
1Ecosystem MappingBuild dependency-linked map across financial, infrastructure, human terrain, protection layer, and state-interaction layersDependency graph, choke point inventory, substitutability assessment, protection relationship map
2Pressure AlignmentIdentify which Russian institutions are susceptible to which levers; align pressure to internal contradictions including manufactured contradictions via the protection layer trackAgency alignment matrix, referral targeting plan, reframing strategy, officer liability candidates
3Cost ImpositionApply coordinated pressure across financial, infrastructure, legal, social, and protection layer vectors to impose compounding costsSanctions actions, infrastructure takedowns, domestic referrals, underground trust disruption, officer exposure operations
4SustainmentMonitor adaptation, prevent reconstitution, reapply pressure to emergent nodes and successor protection relationships (continuous, never ends)Reconstitution tracking, KPI dashboards, updated pressure actions, protection relationship succession map

Critical Do / Don’t Rules

DODON’T
Lead with domestic harm framing (tax fraud, organized crime, harm to Russian citizens)Lead with geopolitical harm framing (activates protection reflexes)
Sequence low-backfire-risk actions first; disrupt protection relationship before or simultaneously with the criminal actorLead with public attribution or extradition requests (hardens protection, not suppression)
Monitor before takedown; use seizure as a data collection event and feed follow-on actionsTreat a takedown as an endpoint: without sustained follow-on pressure, service nodes are replaced in days and brands recover over months
Exploit internal Russian institutional contradictions (MVD vs. FSB; FNS financial exposure; FSB factional competition; CBR 115-FZ friction)Seek coordinated Russian cooperation at the strategic level (not achievable; signals foreign ownership of the case)
Measure every action: define expected effect before acting; log observed results and time-to-reconstitutionRun disruption operations without measurement (narrative without accountability)

SECTION 1 | PURPOSE & SCOPE

What This Document Is

This document proposes a framework for sustained disruption operations targeting the Russia-linked ransomware and cybercrime ecosystem, including the protection infrastructure (Russian state officers and institutional relationships) that insulates top-tier actors from enforcement. It is offered as analytic input for interagency partners with operational or analytic roles.

What This Document Is Not

This document draws on structural analysis of Russian agency behavior, observed enforcement outcomes, and analytic assessments of the ransomware ecosystem. Realpolitik incentives, not normative expectations, drive the analytical framework. Confidence is labelled only where a claim carries operational weight, using three levels. Confirmed means a primary source states it: a court record, a designation notice, an official release. Credible means consistent reporting from sources with relevant access, without a primary document. Analyst inference means the judgement is ours. Unlabelled text is background that is not in dispute.

Scope Limitations

Three categories of actor fall outside this framework's intended scope and should be flagged through separate channels if encountered:

SECTION 2 | CORE THESIS

The Russia-linked ransomware ecosystem is resilient by design. Individual actors, infrastructure nodes, and even ransomware brands reconstitute quickly after episodic disruptions. Takedowns create friction but not degradation unless compounded over time.

Reconstitution runs on two clocks, and conflating them is the most common measurement error in this field. The node clock measures how long a function takes to be restored: a customer base moving from one bulletproof hoster to another, an encryptor reappearing on new infrastructure. It runs in days, and what it measures is displacement, not degradation. The brand and personnel clock measures whether an operation resumes at all, and it runs in months or never. Both are real. Only the second is evidence of degradation. Our own measurement of public pressure episodes reports node-level recovery in days while a substantial population of episodes has never closed at all, and that second population is where durable damage shows up. Every claim about reconstitution speed, in this document or any other, should state which clock it means. Confirmed, on our published series.

The correct strategic model is sustained cost imposition across multiple ecosystem layers simultaneously: financial, infrastructural, human terrain, protection layer, and domestic Russian institutional. When pressure is applied in coordination across these layers, actors face compounding costs that cannot be absorbed through simple reconstitution.

Scope qualification: the compounding friction thesis is structurally sound but rests on an assumption of sustained, coordinated multi-node pressure that has no confirmed historical precedent at this scale. The available evidence is consistent with the model while falling short of validating it. On-chain ransomware payments fell to roughly $820 million in 2025, down about 8 percent from roughly $892 million in 2024, and the victim payment rate reached a record low with non-payment at about 72 percent. Claimed attack volume rose over the same period rather than falling. That divergence is what partial implementation looks like: pressure is reaching the money and doing considerably less to the rate of attack. The thesis should be treated as an operational framework and planning model, not an empirically validated outcome. Confidence in the model's logic is high. Confidence that full coordinated execution is achievable within current interagency and allied coordination constraints is moderate. Analyst inference.

A critical layer absent from many disruption frameworks is the protection infrastructure itself. FSB officers who recruit, co-opt, and shield cybercriminal actors are not passive bystanders. They are load-bearing nodes in the ecosystem. Disrupting the protection relationship is as operationally important as disrupting the criminal infrastructure it shields.

Episodic Takedownsvs.Sustained Disruption
Single actor or infrastructure targetMultiple simultaneous pressure vectors
Node replaced in days, brand recovered in months, nothing actually degradedCompounding costs across financial, infra, human, and protection layers
Creates narrative, not lasting frictionForces tradeoffs between criminal operations and regime stability
No measurable ecosystem effectMeasurable ecosystem health degradation over time
Protection layer untouchedProtection relationships dismantled, not worked around
▶ CORE MISSION The objective is not episodic takedowns. It is sustained ecosystem degradation: increasing operational friction, raising domestic risk for criminal actors, forcing alignment of Russia's internal institutional incentives against cybercrime, and dismantling the protection infrastructure that insulates top-tier actors from enforcement. Success is measured by compounding pressure, not individual arrests.

Defining Success

The strategic principles that follow govern all phases of this framework. Violating them (particularly the engagement triggers) consistently produces the opposite of the intended effect.

SECTION 3 | STRATEGIC PRINCIPLES

3.1 Lead with Domestic Harm Framing

Russian institutions respond to internal threats, not external ones. Cybercriminals must be reframed as threats to Russian financial stability, domestic public trust, and regime legitimacy, not as foreign adversaries. Framing that emphasizes geopolitical harms activates protection reflexes and is counterproductive. Confidence: CREDIBLE

3.2 Exploit Internal Contradictions, Including Within FSB

Russian agencies do not operate in unified alignment. The FSB, GRU, MVD, and FNS frequently have competing institutional interests. Effective pressure identifies and exploits these contradictions rather than seeking coordinated Russian cooperation, which is not achievable at the strategic level. Confidence: CREDIBLE

Critically, FSB itself is not a monolith. It contains competing factions, officers with divergent financial interests, and internal competition for political favor. The officer liability track (Section 9) rests on this reality: the goal is not to activate a unified FSB response, but to create conditions where specific FSB factions or leadership figures (who have their own institutional incentives) find it in their interest to act against a specific officer. This is a different and more achievable objective than FSB cooperation.

▶ MANUFACTURING CONTRADICTIONS Contradictions are not only exploited. They can be manufactured. The protection layer track (Section 9) operationalizes this: financial exposure operations that surface an FSB officer's criminal protection relationships to competing officers or FSB leadership create contradictions where none previously existed. When an officer's krysha relationship becomes visible to FSB leadership as an attribution risk or domestic embarrassment, the institution's factional dynamics and self-preservation instincts can activate against that officer. You are not waiting for contradictions to exist, you are generating them through targeted analytic and exposure work.

3.3 Sequence for Minimum Backfire Risk

Actions that trigger protection reflexes (particularly public attribution and extradition requests) harden actor protection rather than undermining it. Pressure sequencing must account for this dynamic. Confidence: CREDIBLE

3.4 Measure Everything

Disruption operations without measurement become narrative. Every pressure action should have a defined expected effect and a mechanism for observing actual outcomes. Adaptation by actors is itself signal, log it. Confidence: CREDIBLE (as principle); implementation quality varies by resourcing

SECTION 4 | PHASE FRAMEWORK

The four phases are sequential at ecosystem scale but overlapping at the actor level. Phase 4 (Sustainment) begins as soon as the first pressure actions are taken and never ends.

PhaseNamePrimary ObjectiveKey Outputs
1Ecosystem MappingBuild a complete, dependency-linked map of the ecosystem across financial, infrastructure, human terrain, protection layer, and state-interaction layersDependency graph, choke point inventory, substitutability assessment, protection relationship map
2Pressure AlignmentIdentify which Russian domestic institutions are susceptible to which levers, and align foreign pressure to exploit internal contradictions, including manufactured contradictions via the protection layer trackAgency alignment matrix, referral targeting plan, reframing strategy, officer liability candidates
3Cost ImpositionApply coordinated pressure across financial, infrastructure, legal, social, and protection layer vectors to impose compounding costsSanctions actions, infrastructure takedowns, domestic referrals, underground trust disruption, officer exposure operations
4SustainmentMonitor adaptation, prevent reconstitution, reapply pressure to emergent nodesReconstitution tracking, KPI dashboards, updated pressure actions

4.1 Phase 1: Ecosystem Mapping

Before pressure can be applied effectively, the ecosystem must be understood as an interdependent system, not a collection of individual actors. Mapping focuses on nodes, dependencies, choke points, and substitutability. The protection layer is a mandatory fifth mapping domain.

Financial Layer

Key question: where do funds become fiat, and who touches them?

Infrastructure Layer

Key question: what is the minimum set of upstream providers whose removal collapses multiple downstream nodes?

Human Terrain

Protection Layer

Key question: for each protected actor, who is the officer or faction, what is the payment relationship, and what would make that officer a liability to FSB leadership or competing factions?

Substitutability Assessment

Substitutability is not a mapping output, it is a targeting input. Build substitutability assessments before disruption actions, not after. For each critical role:

▶ SUBSTITUTABILITY FAILURE PATTERN The most common operational error: disrupting a node without pre-positioned pressure on the identified successor. The successor steps in cleanly, reconstitution accelerates, and the operation produces a leadership transition rather than ecosystem degradation. Map the successor first. Apply pressure to the successor simultaneously with or before disrupting the primary.

State Interaction Layer

4.2 Phase 2: Pressure Alignment

Alignment means identifying which levers work through which Russian institutions, sequencing referrals to exploit internal contradictions, and ensuring domestic framing is in place before any action is taken. The full Russian agency reference is in Section 7.

Priority Channels: Confidence CREDIBLE

Secondary Channels, Confidence: CREDIBLE (conditional)

Reframing Strategy

4.3 Phase 3: Cost Imposition

Cost imposition operates across five simultaneous vectors. Actions within each vector should be sequenced from lowest to highest backfire risk and coordinated across vectors where possible.

Vector 1: Financial Pressure

Vector 2: Infrastructure Pressure

Vector 3: Legal and Non-Cyber Charges

Vector 4: Underground Social Infrastructure

Vector 5: Protection Layer Pressure

Full methodology in Section 9. Summary:

4.4 Phase 4: Sustainment

Sustainment is not a final phase, it is a continuous operational posture. Disrupted ecosystems reconstitute unless pressure is reapplied to emergent nodes.

Reconstitution Monitoring

Pressure Rotation

SECTION 5 | AFFILIATE STRATEGIC FRAMEWORK & RaaS-SPECIFIC DISRUPTION

The affiliate layer is the operational engine of the entire ecosystem. It has historically received less strategic attention than core leadership, a gap this section addresses. The framework below applies to both RaaS franchise operations and closed hierarchical groups.

5.1 Structural Comparison: RaaS vs. Closed Groups

CharacteristicClosed Group (e.g. early Conti, WizardSpider)RaaS (e.g. Qilin, Akira, DragonForce)
StructureCentralized. Employed developers, operators, and negotiators under unified leadership.Franchise model. Small core team (3-10) provides encryptor, infrastructure, and panel. Affiliates do the hacking.
Revenue splitCentralized revenue; leadership distributes salaries or shares.70-80% to affiliates, 20-30% admin cut to core team per ransom payment.
Leadership exposureHigher. Leadership directs operations and is connected to victim activity.Lower. Core team never touches victim networks. Admin wallet abstracted through multiple layers.
Affiliate roleEmployed operators, internal, vetted, salaried or revenue-share.Independent contractors, external, self-vetted via forum reputation, disposable.
Resilience to takedownModerate. Remove leadership, remove the operation.High. Affiliates migrate to competing RaaS within days. Core team rebrands and re-recruits.
Primary disruption leverLeadership identification and arrest.Business model degradation: trust destruction, affiliate risk elevation, cash-out pressure.

5.2 Affiliate Strategic Framework, Both Group Types

Regardless of group structure, the affiliate layer shares common characteristics that make it a high-value strategic target.

Affiliate Prioritization

Priority TierProfileRationalePrimary Action
Tier 1, High ValueHigh-volume affiliates responsible for DIB, CIKR, or healthcare targeting; affiliates with documented travel outside Russia/CISMaximum operational impact + maximum arrest feasibilityThird-country arrest development; simultaneous financial designation
Tier 2, Intelligence ValueAffiliates with documented contact methods, forum handles, or infrastructure links to core team leadershipEvery affiliate arrest is a potential collection opportunity toward core team identificationArrest + structured debrief; cultivate as CI with extreme OPSEC
Tier 3, Chilling EffectHigh-profile, visible affiliates whose arrest will be observed by the remaining affiliate poolArrests chill recruitment more than any single leadership actionPublic arrest + maximum public attribution to signal ecosystem-wide risk
Tier 4, Financial PressureAffiliates with Western-touchable financial exposure (exchange accounts, real estate, business interests)Financial pressure without arrest; imposes cost even without custodyOFAC designation + VASP KYC pressure + correspondent banking exposure

Affiliate Mapping Methodology

Affiliate Migration Tracking

When a group is disrupted, affiliates migrate. Migration patterns are intelligence, they reveal which competing groups are absorbing talent, what the new operational tempo will be, and who the resilient actors are.

The Affiliate Arrest Multiplier Effect

A single well-chosen affiliate arrest produces effects that extend far beyond the individual:

5.3 RaaS-Specific: Paths to Leadership Identification

VectorMechanismReliabilityOperational Notes
Financial tracing (admin cut)Admin wallet receives a consistent percentage of every ransom. High-volume recurring flows are harder to fully obscure. Trace through layering, OTC, and exchange withdrawal.HighPrimary path. Requires blockchain forensics combined with exchange KYC pressure. Long timeline but most durable evidence.
Seized infrastructureTakedown operations on affiliate panels and leak sites yield negotiation logs, affiliate identifiers, payment addresses, and admin access patterns. Operation Cronos (LockBit, Feb 2024) produced direct visibility into admin payment flows.High (if obtained)Requires prior takedown. Intelligence from seized panels compounds over time.
Affiliate cooperationArrested affiliates know core team contact methods, forum vetting handles, and sometimes infrastructure details.MediumCooperators become CI targets if exposed. Cooperator handling requires extreme OPSEC. Exposure triggers reverse enforcement by Russian agencies.
Developer artifacts in malwareCompile-time metadata, PDB paths, error strings, language settings, and coding style fingerprint individual developers across rebrands.MediumSlow but rebrand-resistant. Most valuable for linking a new group to a prior identity after reconstitution.
Underground forum historyRaaS operators maintain reputations on Exploit and XSS. Forum registration patterns, PGP key reuse, and posting style link current identities to prior personas.MediumIntel 471 and Flashpoint are primary sources.
Infrastructure persistenceEven OPSEC-conscious groups reuse infrastructure elements across brands: ASN patterns, hosting providers, panel code, domain registration behaviors.MediumDocument infrastructure fingerprints before takedown so reconstitution is immediately detectable.

5.4 Attacking the RaaS Business Model

Trust Destruction

Payment Rail Pressure

IAB Layer Disruption

Decryptor Release

5.5 Preventing Reconstitution and Rebrands

5.6 Victim-Side Engagement Framework

The ecosystem has historically been approached from the supply side. Victim payment refusal is one of the most powerful ecosystem pressure mechanisms available, it directly attacks the financial incentive sustaining the entire RaaS model. Every refused payment imposes a cost that no infrastructure rebuild can recover. This section proposes an engagement model, not just a list of mechanisms.

The Engagement Model

Victim-side pressure does not operate through law enforcement alone. It requires coordinated engagement across five institutional channels, each of which owns a different lever. These channels should be engaged in parallel, not sequentially.

ChannelLeverEcosystem EffectEngagement Mechanism
Law Enforcement (FBI/CISA)Decryptor release + affiliate panel seizureDirect revenue reduction; undermines franchise value propositionCoordinate decryptor release with takedown operations; public release maximizes chilling effect on pending victim negotiations
CISA / Sector ISACsPre-encryption victim notificationReduces successful attack completion rate; raises affiliate operational costCISA and sector ISACs maintain victim notification pipelines, engage early to ensure high-priority sectors receive alerts before encryption completes
FinCEN / TreasuryInsurer payment policy pressureReduces victim payment rate systematically across the ecosystemFinCEN engagement with cyber insurance sector; ransomware payment coverage restrictions and mandatory law enforcement notification requirements reduce payment rates without legislative action
OFACSanctions payment prohibitionReduces payment rate for designated groups; compels victim reportingOFAC designation paired with payment prohibition guidance creates legal liability for victim payment; should be coordinated with takedown timing to maximize disruption
CISA / Sector RegulatorsResilience investment incentivesLong-term structural reduction in victim payment rateBackup and recovery capability eliminates payment incentive entirely for resilient victims; resilience standards and investment incentives are the only mechanism that attacks the demand side structurally

Connection to Supply-Side Operations

Victim-side and supply-side operations should be sequenced to compound each other:

▶ CURRENT EFFECTIVENESS SIGNAL Ransom payment volume has fallen while attack volume has risen. On-chain payments were roughly $820 million in 2025 against roughly $892 million in 2024, and the non-payment rate reached a record high of about 72 percent, while claimed attacks rose over the same period. The payment picture has also changed shape rather than simply shrinking. Through the second quarter of 2026 the average payment rose sharply, to roughly $1.88 million, while the median fell to roughly $150,000. Revenue is concentrating into a small number of very large payments, driven by data-suppression deals rather than by victims buying decryption. Two implications follow. Friction is real, and it is landing on the money. But an ecosystem that earns comparable revenue from fewer and larger deals is a harder target rather than a weaker one, because the marginal victim matters less and one large payment can fund a quarter of operations. Payment refusal is a victory. Attack prevention, and closing the suppression-payment channel, are the harder objectives. Credible.

5.7 HUMINT and Cooperator Handling

The playbook references HUMINT as a source across several sections, particularly for protection relationship reconstitution tracking and core team identification. Given that cooperator exposure triggers active counterintelligence responses by Russian agencies, a brief set of handling principles is warranted. These are offered as analytic input; cooperator programs require specific authority and tradecraft that exceeds this document's scope.

Core Handling Principles

Any cooperator program requires dedicated tradecraft expertise and appropriate authority beyond this document’s scope.

SECTION 6 | TAKEDOWN vs. MONITORING: THE CORE OPERATIONAL DECISION

Whether to take down infrastructure or continue monitoring it is one of the most consequential decisions in disruption operations. The central error is treating them as competing options. They are sequential phases of a single operation.

6.1 The Core Tension

Takedown produces immediate disruption and, if infrastructure is seized rather than just shut down, an intelligence windfall, potentially years of logs, user data, transaction records, and admin access patterns. Monitoring produces ongoing intelligence but allows real harm to continue while you watch.

Monitoring advantages: reveals operational intent, planned attacks, internal disputes, and full network structure before disruption. The panic signal after a takedown, who disappears, who migrates, who tries to contact whom, is itself intelligence on network structure. Live channels with operational planning visible generally outweigh the disruption value of shutting them down, unless imminent victim harm is preventable.

Takedown advantages: burn risk, if your access is discovered, you lose the intelligence and actors migrate to a hardened platform. Seized infrastructure often exceeds the value of continued monitoring. The seizure itself is a trust destruction weapon: remaining actors do not know who cooperated or what law enforcement now knows.

6.2 Decision Threshold: When to Move from Monitor to Takedown

TriggerRationaleRisk if Delayed
Ongoing victim harm exceeds intelligence valueParticularly if critical infrastructure, healthcare, or DIB targets are being hit. Continued monitoring becomes legally and ethically indefensible.Legal/oversight exposure; reputational damage if monitoring is disclosed
Monitoring access is at risk of discoverySophisticated actors conduct counterintelligence. A controlled takedown on your terms is better than a discovered access.Loss of all intelligence; actors harden new platform
Sufficient ecosystem mapping to support follow-on actionsLeadership identified or substantially narrowed; affiliate roster mapped; financial flows traced. Marginal value of additional monitoring is declining.Diminishing returns; unnecessary harm continuation
Time-sensitive operational opportunityA key actor is traveling outside Russia, a financial window exists for simultaneous designations, or a partner operation creates a coordination moment.Missed arrest or designation window
Coordinated multi-partner action is readyMaximum disruption requires simultaneous action across jurisdictions. When all partners are aligned, delay reduces coordination quality.Partner readiness degrades; coordination gaps widen
▶ BOTTOM LINE Monitor to map. Take down at maximum yield. Use seized data to pursue follow-on actions. Monitor reconstitution to target the next iteration. The takedown is a phase, not an endpoint.

SECTION 7 | RUSSIAN AGENCY QUICK REFERENCE

Confidence levels reflect observed enforcement behavior, not legal doctrine. Note: FSB is not treated as a unified actor. Internal factions, competing officer interests, and political dynamics within FSB create divergent enforcement behaviors, the column below reflects FSB's aggregate behavior while Section 9 operationalizes the factional divergences.

AgencyRole in EcosystemBest Leverage PointsConfidenceKey Limits
FSBPrimary architect of cyber ecosystem; recruits, co-opts, or protects actors for CI and strategic ops. Internally factional, competing officers and units have divergent interests that can be exploited.Attribution fallout; actor defiance of recruitment; actor ties to foreign intelligence; manufactured liability via protection layer exposure (Section 9); factional competition between FSB unitsHigh (selective)No legal cooperation as an institution. Foreign pressure reduces enforcement appetite at agency level. Individual factions may act when actor defies, embarrasses, or becomes a liability to specific officers or units.
GRULeverages actors for military/geopolitical ops; rarely arrests but will silence or cut off. Note: actors absorbed into wartime GRU operations fall outside this framework's scope.Sloppy OPSEC; attribution risk to ongoing ops; actor disobedience post-campaignLowNo transparency; no prosecutorial handoff. Disruption must be indirect.
MVD / Dept KEnforces mid-level fraud and technical cybercrime; reputationally sensitive; sidelined in elite casesDomestic financial harm; media scrutiny; interagency competition with FSB; arrest metrics pressureHigh (non-RIS)FSB can override at any time. Not accessible for RIS-linked actors.
FNSIdentifies shell companies, undeclared income, and lifestyle inconsistencies; no arrest powerFinancial irregularities; family asset exposure; laundering front structuresMed-HighAction requires political greenlight. Surfaces exposure; does not prosecute.
RosfinmonitoringRussia's financial intelligence hub; maps laundering infrastructure; triggers asset controls and referralsCrypto-fiat flows; suspicious transactions; Egmont Group scrutiny pathwaysHigh (mapping)Politicized. Requires downstream adoption by MVD or FSB to produce arrests.
CBRVia 115-FZ, enables banks to freeze or deny transactions based on risk without prosecutionSuspicious transaction patterns; politically exposed clients; AML risk flagsMed-HighDoes not attribute activity or target individuals. Non-attributable friction only.
SKREngages only when cybercrime is elevated to elite criminality or political scandalPolitical embarrassment; regime exposure; organized crime framing (Art. 210)MediumNot reachable through standard LE channels. Requires Kremlin-level political signal.
RoskomnadzorRestricts communications platforms; imposes infrastructure frictionHosting noncompliance; foreign platform resistance; digital sovereignty framingMediumDoes not target individuals. Disrupts legitimate users equally.

SECTION 8 | ENGAGEMENT TRIGGERS TO AVOID

These patterns consistently cause Russian agencies to protect, absorb, or redirect cybercriminals rather than suppress them. They are drawn from historical enforcement outcomes and institutional behavior analysis. Red = high backfire risk (avoid or delay until actor is isolated). Amber = conditional risk (proceed with domestic framing in place).

TriggerEffectMechanismImplication for Operations
Public attribution by foreign governmentActor converts from criminal liability to national security assetOnce named by a foreign power (especially the U.S.), FSB/GRU may treat actor as soft-state asset regardless of prior behaviorAttribution hardens protection. Publicity equals absorption. Delay public attribution until actor is already isolated.
Formal arrest or extradition requestTriggers defensive nationalism; reduces arrest probability to near zeroRussian doctrine opposes surrender of nationals. Extradition requests signal foreign ownership of the case.Extradition-first strategies produce the opposite of suppression. Pursue third-country arrest opportunities instead.
Media naming and shaming campaignsAgencies treat engagement as hostile information warfare; enforcement appetite declinesWhen actors are labeled 'Russian cybercriminals' without domestic impact framing, it reads as sovereignty violationPaired domestic framing is required before any public naming.
Indication of actor cooperation with foreign LEActor becomes a counterintelligence interest; FSB views as double-agent riskSuspected cooperators are arrested, disappeared, or neutralizedCooperator handling requires extreme operational security. Exposure of cooperation triggers reverse enforcement.
Actor technical value or recruitment potentialDelays or cancels enforcement; actor becomes reusable state assetActors with malware or infrastructure capabilities are considered recruitablePrioritize disruption of capability before it triggers recruitment.
Target selection aligned with Russian strategic interestsActor becomes functionally aligned with state objectives; impunity followsOperations against Western banks, NATO infrastructure, or sanctions enforcement are considered symbiotic by Russian stateDocument target patterns to predict and preempt state absorption.
Internal elite sponsorship (krysha)Immunity from arrest regardless of cybercrime visibilityActor operates under protection of regional, political, or RIS patronPressure must first weaken or circumvent sponsor relationship. FNS/Rosfinmonitoring exposure of patron is prerequisite.
Multilateral pressure without local framingResistance from all Russian agencies; interpreted as sovereignty violationPressure through Western consortiums without Russian criminal charge equivalents reads as hostileAlign multilateral pressure with simultaneous domestic framing.
▶ BOTTOM LINE Russian agencies protect cybercriminals when engagement signals foreign ownership, regime threat, or operational opportunity. Effective disruption depends on avoiding these triggers while exploiting internal contradictions and institutional sensitivities.

SECTION 9 | PROTECTION LAYER DISRUPTION: FSB OFFICER LIABILITY TRACK

9.1 Core Concept: Protection as a Load-Bearing Ecosystem Node

FSB officers who provide krysha, recruitment, and protection to cybercriminal actors are not peripheral to the ecosystem, they are load-bearing nodes. Disrupting a criminal actor whose protection relationship remains intact produces reconstitution. Disrupting the protection relationship first, or simultaneously, produces ecosystem degradation.

The mechanism: individual FSB officers maintain protection relationships because they generate personal value, financial, operational, reputational within the service. When a specific protection relationship generates more cost than value, domestic embarrassment, attribution risk to the officer personally, institutional liability to FSB leadership or competing factions, the pressures on that officer change. You are not asking FSB to cooperate as an institution. You are creating conditions where a specific officer's calculus shifts, or where competing FSB factions find it advantageous to act against the liability-generating officer. These are different and more achievable objectives.

This distinction matters operationally. FSB's internal factions do not share interests. An officer in the FSB's economic security directorate and an officer in a cyber unit may be in active competition. Surfacing one officer's criminal financial exposure to competing FSB units, rather than to FSB 'leadership' as an abstraction, is a more precise and realistic targeting objective. Confidence: Medium-High (mechanism is well-supported; execution difficulty is high)

Worked example (Karakurt / Zolotarjovs, May 2026). On 4 May 2026 a US court sentenced Deniss Zolotarjovs to 102 months for his role in Karakurt, a data-extortion group the Department of Justice describes as led by former Conti leadership. DOJ stated the group relied on access to Russian government databases and law-enforcement connections, and paid bribes to secure military draft exemptions and tax avoidance for its members. This is the clearest open-source confirmation to date of the premise in this section: protection is a purchased, load-bearing relationship with named state touchpoints (government databases, draft boards, tax authorities), not a vague tolerance. It also illustrates the officer-liability logic in reverse. The same corruption that shields members is itself documentable financial exposure, exactly the paper trail the financial-exposure methodology below is built to surface. Confidence: Confirmed (DOJ statement and sentencing, 4 May 2026).

9.2 Officer Relationship Types and Leverage

Officer Relationship TypeProtection MechanismLiability TriggerPrimary Lever
Direct handler / recruiterTasks criminal actors for intelligence collection or strategic ops; provides operational coverSloppy OPSEC by the criminal actor creating attribution risk back to the officer; criminal actor creating domestic harm visible enough to attract MVD attentionAttribute criminal actor's domestic harm to officer's operational portfolio; surface attribution risk to competing FSB units
Krysha / protection providerFinancial relationship, officer receives payment to ensure enforcement non-interferenceFinancial exposure: payment flows documented and surfaced domestically; Western asset exposure via sanctionsAnomalous outflow analysis to document payment relationship; FNS lifestyle referral on officer; simultaneous criminal network + officer sanctions
Passive tolerance / non-interferenceOfficer aware of actor but chooses not to act; implicit protection through inactionActor creates embarrassment or domestic harm sufficient to make the officer's inaction visible to superiors or competing unitsDomestic harm amplification via investigative journalism; FNS lifestyle flags on actor to create paper trail officer cannot ignore
Retired / former officerResidual institutional relationships and access used to provide informal protectionNo active institutional protection; most vulnerable to financial sanctions and third-country arrestWestern asset designation; third-country arrest development (Annex A); family financial exposure

9.3 Financial Exposure Methodology for Officers

FSB officers on government salary who maintain protection relationships with high-volume cybercriminal actors accumulate financial exposure that does not match their declared income. Building this exposure profile requires no HUMINT, it is an open source and financial registry analytic task that extends directly from the criminal-side financial mapping already in this playbook. All deliverables in this section are proposed; none currently exist.

Step 1: Identify Anomalous Outflows from Criminal Actor Finances

This is the keystone analytic task. Detailed methodology in Section 10. For this section: the question to ask of every criminal actor's financial map is what outflows do not fit criminal operational cost profiles.

Step 2: Build the Officer Financial Profile

Step 3: Channel Selection for Exposure

ChannelMechanismBackfire RiskBest Use Case
FNS referral (domestic)Lifestyle inconsistency and undeclared income flagged to Federal Tax Service, no foreign fingerprint, purely domestic processLowOfficers with documented Russian-held assets inconsistent with salary; generates domestic paper trail
Rosfinmonitoring referralSuspicious transaction flags on protection payment flows, feeds CBR 115-FZ freeze pipelineLowHigh-volume payment flows between criminal actor and officer-linked accounts
Investigative journalism (OCCRP / Bellingcat / iStories / Meduza)Financial and lifestyle documentation provided to investigative outlets, produces domestic scandal framing rather than foreign attributionMedium (lower than official attribution)Officers with Western asset exposure and documentable lifestyle inconsistency; creates domestic embarrassment without official foreign-government fingerprint
Simultaneous OFAC/OFSI designationOfficer + criminal network designated simultaneously; Western asset freeze + correspondent banking pressureMedium-High (acceptable if domestic framing pre-positioned)Retired/former officers or officers already domestically exposed; batch with criminal network to maximize impact
Third-country legal pre-positioningSealed indictments or arrest warrants filed in viable European jurisdictions; activated when travel window opensLow (if kept sealed)Officers with documented travel patterns to viable jurisdictions (Annex A)

9.4 Manufacturing Internal FSB Contradictions

The goal is not to get FSB to cooperate as an institution, it is to make specific officers liabilities that competing FSB units or FSB leadership's factional interests will act against. This requires surfacing the right information to the right internal FSB audience, which requires knowing which FSB factions are in competition with the officer's unit. Confidence: Medium (mechanism is sound; intelligence requirements are high)

What Makes an Officer a Liability to FSB Leadership or Competing Factions

9.5 Portfolio Sequencing for Officer Targets

TierOfficer ProfileAction SequenceTimeline
Tier 1, ImmediateRetired/former officers with Western asset exposure and active criminal network tiesFinancial profile build → OFAC/OFSI designation (officer + criminal network simultaneously) → third-country arrest legal pre-positioning → investigative journalism pipeline0-90 days
Tier 2, Financial ExposureActive duty krysha officers with documentable payment relationshipsAnomalous outflow identification → FNS referral → Rosfinmonitoring flag → investigative journalism (if profile is strong) → OFAC designation after domestic exposure is established90-180 days
Tier 3, Contradiction ManufacturingActive duty handlers whose protected actors are generating domestic harm or attribution riskDomestic harm amplification → attribution risk surfacing to competing FSB unit awareness → operational incompetence signaling via repeated disruption of protected actor → monitor for protection relationship strain180-365 days
Tier 4, Long LeadActive duty officers with unclear status or current high collection valueMonitor only, define trigger conditions before monitoring begins; do not act until protection relationship mapping is complete and successor officer is identifiedOngoing
▶ COMPOUNDING FEEDBACK LOOP Criminal-side financial pressure → anomalous outflow identification → officer financial profile → FNS/investigative journalism exposure → domestic liability for officer → FSB factional pressure on officer's relationship → criminal actor loses protection → criminal actor becomes accessible to MVD enforcement → MVD enforcement generates more intelligence on financial flows → stronger anomalous outflow identification → repeat. Each cycle strengthens the next.

SECTION 10 | CRYPTO-TO-FIAT METHODOLOGY

10.1 Why This Is the Keystone Analytic Task

Every financial pressure action in this playbook, wallet designations, VASP engagement, correspondent banking exposure, OTC node targeting, protection payment identification, requires knowing where funds become fiat and who touches them. Without a documented cash-out graph, financial pressure actions are targeted at symptoms rather than structural nodes. With it, single actions produce cascading disruptions across multiple actor flows.

The cash-out graph also contains the protection payment data that drives the Section 9 officer liability track. Anomalous outflows, payments that do not fit criminal operational cost profiles, are only identifiable against a complete model of what criminal operational costs look like. Build the model first.

10.2 The Cash-Out Graph: Layer Structure

LayerWhat It ContainsKey QuestionsPrimary Sources
Layer 1: Ransom ReceiptInitial ransom payment wallets; victim-to-actor payment flows; multi-sig escrow structures used in negotiationWhat wallets receive ransom payments? Are they reused or single-use? What mixing or structuring occurs immediately post-receipt?Chainalysis Reactor; TRM Labs; on-chain forensics
Layer 2: LayeringMixing services, chain-hopping (BTC→Monero→BTC), structuring into sub-threshold amounts, peel chains, consolidation walletsHow many hops before funds reach a cash-out node? What mixing services are used? Are layer 2 wallets shared across multiple actor flows?Chainalysis; TRM; Elliptic, cross-validate outputs
Layer 3: Pre-Cash-Out AggregationConsolidation wallets that aggregate layered funds before exchange deposit or OTC transfer; admin cut separation at this layerWhere does the admin cut separate from affiliate payments? What wallets aggregate funds from multiple ransom flows? These are high-value designation targets.Blockchain forensics, look for consistent percentage splits
Layer 4: Cash-Out NodesOTC brokers, exchange deposits (VASP), peer-to-peer platforms, payment aggregators, crypto ATMsWhich specific OTC nodes and exchange accounts receive funds? What are the withdrawal patterns? What geographic concentration exists?Chainalysis + exchange KYC pressure; Intel 471 for OTC broker identification
Layer 5: Fiat EntryBank accounts, payment systems, real estate purchases, front company revenue, luxury asset acquisitionWhich banks receive fiat proceeds? What front companies hold proceeds? Where does money enter the legitimate financial system?Rosfinmonitoring referrals; FNS corporate registry; property registries; correspondent banking data

Worked Examples: Cash-Out Nodes Under Pressure, 2025 to 2026

Garantex was designated in April 2022 and not seized until March 2025, a three-year window of continued high-volume operation under designation. Its successor Grinex was designated in August 2025 and collapsed on or about 16 April 2026 after a drain of roughly $13.7 million. The sequence validates the pre-positioning rule stated in Phase 1: the successor exists before the primary is disrupted, so the attribution and designation pipeline for the most probable successor should be running before the primary node is fully taken. The standing requirement now points at the next successor in the chain. Confirmed on the designation and seizure record. The identity of the next successor is analyst inference.

The AudiA6 action of 10 June 2026 is the clearest recent example of Layers 4 and 5 being taken together. A combined laundering service and over-the-counter layer, integrated with its own forum, was dismantled: roughly EUR 336 million laundered, two administrators arrested, and more than 6,000 verified mule accounts exposed. The mule-account exposure is the part worth studying. A cash-out node that maintains its own inventory of verified accounts turns one takedown into a mule-network dataset, which is precisely the fiat-entry visibility this methodology exists to produce. Confirmed, on the coordinated action by the US Secret Service, IRS Criminal Investigation and European partners.

A third lever has appeared at Layers 2 and 4 that this methodology did not originally account for. Where illicit value moves in stablecoins the issuer can freeze it, and issuer freezes now follow designation within a day rather than over weeks: one July 2026 designation was followed by roughly $131 million frozen at the issuer inside 24 hours. The share of illicit inflows to sanctioned entities that moves through stablecoins is high enough that issuer engagement belongs in the standing financial-pressure repertoire rather than being treated as an occasional windfall. Credible.

10.3 Anomalous Outflow Identification

Once the standard cash-out graph is built, anomalous outflows become visible as flows that do not fit the expected pattern at each layer. These are protection payment candidates.

Criminal Operational Cost Baseline

Establish what normal operational costs look like before flagging anomalies:

Anomalous Outflow Indicators

▶ ANALYTICAL DISCIPLINE NOTE Anomalous outflow identification requires a complete operational cost baseline before anomalies can be flagged. Designating a wallet as a protection payment candidate without establishing what normal looks like produces false positives that undermine subsequent legal action. Build the baseline first. Flag anomalies against it. Cross-validate across multiple ransom payment flows for the same actor before drawing conclusions.

10.4 OTC Broker Network Mapping

OTC brokers are the most critical cash-out bottleneck in the Russian ransomware ecosystem. Unlike exchanges, they are relationship-based, less regulated, and serve as the primary bridge between crypto and Russian domestic fiat for high-volume criminal actors.

OTC Identification Methodology

OTC Network Graph Components

SECTION 11 | MEASUREMENT FRAMEWORK

Disruption operations without measurement produce narrative, not accountability. This section defines the minimum viable measurement posture for tracking ecosystem health and operational effectiveness. When this playbook was first written, none of it existed. Parts of it now do: a finalised metric framework with defined reading rules, a published series measuring recovery time after each public pressure episode, and a continuously maintained record of enforcement actions and what followed them. Those products are the source of record for measurement, and this section defers to them rather than restating their contents, which is how a static document falls behind a live one. What remains missing is the pressure-effect ledger at 11.4 and the protection-layer indicators at 11.3, neither of which can be built from public data alone.

11.1 Establishing Baselines

KPIs defined without documented baselines cannot be used to attribute change to specific actions versus ecosystem-level trends. Establish baselines before any pressure actions are taken.

11.2 Ecosystem Health KPIs

The metric set itself lives in the measurement framework, not here, and that framework is authoritative on definitions, direction of movement, and the conditions under which a metric should not be trusted. What follows is the map of which product answers which question, so that a reader knows where to go rather than working from a list that ages. Baselines are still required per 11.1 before any of these can attribute change to a specific action.

Measurement productWhat it answersSource of recordCadence
Metric framework and metric referenceWhether the ecosystem is weakening, not weakening, or currently unmeasurable, metric by metricThe framework's own metric reference, which is authoritative on definitions and reading rulesQuarterly review
Recovery-time seriesHow long each node took to heal after a public pressure episode, and which episodes have never closed at allPublished series, public dates onlyPer episode
Enforcement recordWhat has been done, to whom, by which authorities, with sources, and what followedMaintained action recordContinuous
Victim and posting dataOperational tempo and breadth of the ecosystemLeak-site monitoring, subject to a known posting-to-collection lagWeekly and monthly
Payment and flow dataWhether ransom revenue is shrinking, and where it is concentratingBlockchain analytics and incident-response reporting, cross-checkedQuarterly

11.3 Protection Layer Leading Indicators

Reconstitution time is a lagging indicator, it measures outcomes after the fact. The following leading indicators are proposed to track Section 9 progress before protection relationship changes are observable in reconstitution data:

Leading IndicatorWhat It SignalsSourceCadence
Officer lifestyle exposure pipeline activityFNS referrals filed; investigative journalism materials prepared and delivered, signals that exposure operations are in motion before domestic effects are visibleInternal trackingMonthly
Anomalous outflow identification progressNumber of protection payment candidates documented with cross-validation, leading indicator for both officer profiles and designation packagesInternal trackingMonthly
Criminal actor forum signals re: protection confidenceUnderground forum discussions showing actor uncertainty about protection status, complaints about krysha quality, or explicit concern about handler reliability, these precede protection relationship breakdownIntel 471 / Flashpoint / forum monitoringMonthly
Reconstitution attempts without normal protection speedActor attempts to reconstitute more slowly than historical baseline, or without the infrastructure access that protected actors typically have, signals protection may be weakening before explicit breakdownCensys / internal monitoringPer event
Protection payment flow routing changesAnomalous outflows rerouting, declining in volume, or converting through different channels than established pattern, may signal actor concern about protection relationship integrityChainalysis / TRMMonthly

11.4 Pressure-Effect Ledger

Every significant pressure action should be logged in a structured ledger. This enables retrospective analysis of what worked, what failed, and what adaptation patterns emerged.

FieldDescriptionRequired?
Action dateDate action was takenYes
Action typeSanction / takedown / referral / designation / exposure / officer liability action / otherYes
TargetActor, wallet, domain, provider, node, or officer targetedYes
Expected effectWhat outcome was predicted and over what timeframeYes
Observed effectWhat actually happened; include null result if no observable changeYes
Time to reconstitutionDays until actor resumed operations or infrastructure re-appearedIf applicable
Protection status changeDid protection relationship change following action? New officer? Weakened protection? New FSB faction involved?If applicable
Adaptation patternHow actor adapted; use this to update substitutability modelsIf applicable

11.5 Recommended Investment Priorities

These recommendations are offered for consideration by operational and policy stakeholders. Two have moved since the first edition: the measurement layer is now partly built, and the enforcement record is maintained continuously. The remainder are not resourced, and all require appropriate authority and partner coordination before implementation. The order below reflects what is still missing rather than what is merely desirable.

SECTION 12 | TOOL & PARTNER REFERENCE

Vendors provide validation, not conclusions. Outputs should be cross-checked across multiple sources before driving operational decisions.

Tool / PartnerCategoryWhen to UseKey Questions to Ask
Chainalysis Reactor / Data SolutionsBlockchain attributionWallet clustering, sanctions exposure screening, laundering typology mapping, tracing from ransom payment to cash-outWhat assumptions underpin the clustering? Where does attribution confidence drop? What exchanges or OTC nodes touch the end of the chain?
TRM Labs / EllipticBlockchain attributionCross-validation of Chainalysis outputs; sanctions screening; VASP risk profilingWhere do outputs diverge from Chainalysis, and why? What is the confidence basis for VASP compliance risk scoring?
Mandiant / CrowdStrike IntelligenceMalware & campaign intelMalware lineage and evolution, affiliate migration, tradecraft shifts, actor attributionWhat would falsify this attribution? What evidence supports continuity vs. rebrand? What replaces this toolchain within 30 days?
ESET Research / Kaspersky (open-source only)Malware & campaign intelTechnical malware analysis, campaign tracking; Kaspersky limited to public reporting with verificationWhat is the publication basis? For Kaspersky: has this been corroborated by a second source?
Intel 471 / FlashpointUnderground monitoringUnderground market dynamics, pricing, trust relationships, actor reputation, recruitment channels, forum activityWhat is the source methodology? How current is the access? Where does underground visibility drop off?
Ransomware.live / RansomLookVictim & campaign trackingReal-time victim counts, leak site monitoring, group activity tracking, ecosystem health KPIsIs the date field the victim posting date or the date the collector first observed it? Our own measurement of that gap averages about five days across 2026, which materially affects any weekly series. What groups are absent from monitoring altogether?
Shadowserver / CensysInfrastructure attributionInfrastructure persistence and reconstitution patterns, ASN and hosting clustering, BPH provider mappingWhat upstream dependencies are shared across multiple criminal nodes? How quickly does reconstitution appear in scan data?
Recorded Future / Microsoft MDTIInfrastructure & OSINTDomain and IP intelligence, cross-platform OSINT fusion, threat actor profiling, infrastructure persistenceWhat is the evidence basis for actor-to-infrastructure attribution? What is the confidence tier?
OCCRP / Bellingcat / iStories / MeduzaInvestigative journalism pipelineOfficer financial exposure and lifestyle documentation; surfacing protection relationship evidence through non-attributable channelsIs the documentation package sufficient to withstand investigative scrutiny? Does it contain USG fingerprints that would trigger backfire? Is domestic framing pre-positioned?

ANNEX A | EUROPEAN JURISDICTIONAL FRAMEWORK

This annex provides country-by-country assessment of European jurisdictions for third-country arrest viability, legal pre-positioning requirements, and treaty landscape for Russia/CIS-linked cybercriminal actors and FSB officers. Five Eyes jurisdictions (US, UK, Canada, Australia, New Zealand) are treated as assumed known baseline and not covered here.

Assessment criteria for each jurisdiction: extradition treaty status with the U.S.; treaty status with Russia (a bilateral extradition treaty with Russia makes the jurisdiction less viable as Russia can request competing extradition); rule of law and judicial independence; historical cooperation on cybercrime cases; travel pattern intelligence; and practical arrest infrastructure (liaison relationships, legal pre-positioning lead time).

Scope note: this annex assesses arrest viability and legal pre-positioning only. For the broader question of which jurisdictions cooperate, on what, and how reliably, use the separate cooperation assessment rather than stretching the tiers below beyond their purpose. Where the two appear to disagree, the cooperation assessment governs on cooperation and this annex governs on arrest mechanics.

A.1 Tier 1, High Viability (Priority Pre-Positioning)

Germany

Extradition treaty (U.S.)Yes, bilateral treaty; active cooperation history
Treaty with RussiaNone, Russia cannot compete for extradition
Cooperation track recordHigh, Operation Endgame (2024) demonstrated deep BKA/FBI/Europol cooperation; German prosecutors have filed independent cybercrime indictments
Travel pattern relevanceSignificant Russian business and diaspora community; transit hub for Eastern European actors traveling west
Pre-positioning lead time60-90 days for coordination with BKA and German federal prosecutors; MLAT requests processed efficiently
Key limitsGerman courts require substantial evidentiary basis before issuing arrest warrants on foreign requests; political sensitivity around Russia-related cases post-2022 has increased rather than decreased cooperation willingness
VerdictVIABLE, TIER 1. Priority pre-positioning jurisdiction. BKA relationship and Operation Endgame precedent make this the strongest European arrest jurisdiction for cybercrime.

Netherlands

Extradition treaty (U.S.)Yes, active cooperation; NHTCU has deep FBI/DOJ relationship
Treaty with RussiaNone
Cooperation track recordExceptional, Operation Cronos (LockBit), Hive takedown, DoubleVPN, RaidForums all involved Dutch jurisdiction; NHTCU is among the most capable and cooperative cybercrime units in Europe
Travel pattern relevanceAmsterdam Schiphol is a major transit hub; significant Russian business presence; financial sector attracts criminal financial infrastructure
Pre-positioning lead time45-60 days; established MLAT channels and existing working relationships accelerate pre-positioning
Key limitsDutch legal standards for provisional arrest require imminent flight risk documentation; judges are independent and will scrutinize evidentiary basis
VerdictVIABLE, TIER 1. Possibly the single strongest European jurisdiction for cybercrime arrests. Default first-choice pre-positioning jurisdiction.

Spain

Extradition treaty (U.S.)Yes, bilateral treaty; multiple successful extraditions
Treaty with RussiaNone
Cooperation track recordGood, multiple Russia/CIS cybercrime arrests; Spanish law enforcement has demonstrated willingness to act on U.S. requests
Travel pattern relevanceHigh, favored destination for Russian/CIS criminal actors and oligarchs; Costa del Sol and Barcelona have significant Russian community presence; known residence jurisdiction for multiple cybercriminal actors
Pre-positioning lead time60-90 days; Guardia Civil and Policia Nacional have established FBI liaison relationships
Key limitsSpanish judicial process can be slow; provisional arrest requests require prompt follow-up with formal extradition documentation or the subject must be released
VerdictVIABLE, TIER 1. High travel pattern relevance elevates Spain as a high-priority pre-positioning jurisdiction, particularly for actors known to reside or vacation there.

A.2 Tier 2, Conditional Viability (Compressed Assessment)

JurisdictionKey StrengthsKey LimitsVerdict
FranceBilateral U.S. extradition treaty; Paris and Riviera have Russian high-net-worth presence; ANSSI and DGSI have participated in joint operationsJudicial process is slow (90-120 day pre-positioning lead time); French courts are genuinely independent, provisional arrest without strong evidentiary package risks releaseTIER 2, CONDITIONAL. Secondary option; do not rely as primary jurisdiction unless actor has documented presence.
PolandBilateral U.S. extradition treaty; no Russia extradition treaty; strong post-2022 political motivation to counter Russian-linked activity; ABW expanding cybercrime cooperationLess established MLAT infrastructure; judicial standards less predictable than Western European counterparts; more relevant for Eastern European actors than Russian actors specificallyTIER 2, CONDITIONAL. Increasing viability post-2022. Best for Eastern European-based actors transiting Poland.
Czech RepublicBilateral U.S. extradition treaty; no Russia treaty; Nikulin arrest (2017) proved viability; Czech courts withstood Russian diplomatic pressureNikulin-style cases attract significant Russian diplomatic pressure; Czech authorities held firm but the political cost was realTIER 2, CONDITIONAL. Proven jurisdiction with established precedent. Russia will apply maximum diplomatic pressure on high-profile cases.
ItalyBilateral U.S. extradition treaty; no Russia treaty; high Russian high-net-worth residential presence (northern Italy, Sardinia)Slow judicial process (90-120 day lead time); inconsistent cooperation track record; provisional arrest procedures less streamlined than Northern EuropeTIER 2, CONDITIONAL. High travel relevance but slower and less predictable. Pre-position for actors with documented Italian presence; not primary for time-sensitive operations.
GreeceBilateral U.S. extradition treaty; no Russia treaty; Vinnik arrest (2017) demonstrated viability; high Russian tourist and transit traffic; significant Russian property ownershipVinnik case showed Greece will arrest but then spent years processing competing extradition requests from Russia and France, extradited to France, not U.S. (2022). Viable for arrest; unreliable for extradition completion.TIER 2, ARREST ONLY. Use for disruption and detention while primary extradition proceedings run through a more reliable jurisdiction. Do not pre-position as sole extradition pathway.

A.3 Tier 3, Limited Viability

JurisdictionActor PresenceKey ProblemUse
CyprusVery high, major Russian business and residential jurisdiction; significant Russian asset holding post-2022 sanctions evasionDeep Russian economic integration creates political obstacles to cooperation. Low active cooperation track record despite bilateral U.S. extradition treaty.FINANCIAL DOCUMENTATION ONLY. Most valuable as a financial registry and asset mapping jurisdiction. Do not pre-position for arrest.
HungaryModerate, Budapest transit point; some Russian actor presenceOrban government's Russia policy makes this jurisdiction actively unreliable for Russia-linked cases regardless of EU membership and treaty status. Has blocked EU sanctions measures.AVOID FOR RUSSIA-LINKED CASES. Do not pre-position here.
TurkeyVery high, Istanbul and Antalya are among the most significant Russian actor transit and residence jurisdictions post-2022 sanctions; Turkish financial system actively used for sanctions evasionIndependent Russia policy and economic interests create significant unpredictability. Some cases have received cooperation; others have not. Treat every Turkey-based operation as a potential compromise risk.LIMITED, TIER 3. Useful for financial documentation and asset mapping. Do not rely on Turkish cooperation for high-priority arrest operations without current bilateral relationship assessment.

A.4 Avoid, Explicit Entries

JurisdictionWhy Avoid
SerbiaRussia alignment and limited extradition cooperation. Serbian authorities have demonstrated willingness to alert Russian-linked subjects to law enforcement interest, making Serbia an active operational security risk. Do not pre-position, do not share case information with Serbian authorities, do not rely on Serbian cooperation for any Russia-linked operation.
BelarusUnion State, operationally equivalent to Russia. Lukashenko government will not cooperate on any Russia-linked cybercrime case. Actors based in Belarus have the same practical protection as actors based in Russia.
Armenia / GeorgiaGeorgia and Armenia have both produced confirmed arrests of Russian nationals and should not be treated as equivalent to Russia-aligned jurisdictions. Both have participated in coordinated international actions, including the June 2026 laundering-service takedown. The limiting factor is detention durability rather than willingness to arrest: in June 2024 Armenia arrested a senior Russian-linked extortion figure in Yerevan on a US request and released him after roughly three days, after which he reached Russia. Pre-position here only with the provisional arrest and onward transfer framework confirmed in advance, and plan on a window of days rather than weeks. Confirmed.
AzerbaijanNo U.S. extradition treaty. Significant Russian economic and political influence. No confirmed operational cooperation on Russia/CIS cybercrime cases. Cooperation posture is unpredictable and insufficient data exists to assess viability. Do not pre-position. Monitor for changes in bilateral posture; reassess if cooperation track record develops.

A.5 Jurisdictional Quick Reference

JurisdictionExtradition (US)Russia TreatyTrack RecordTravel RelevanceTier
GermanyYesNoneHighHighTier 1, Viable
NetherlandsYesNoneExceptionalHighTier 1, Viable
SpainYesNoneGoodVery HighTier 1, Viable
FranceYesNoneModerateMod-HighTier 2, Conditional
PolandYesNoneIncreasingModerateTier 2, Conditional
Czech RepublicYesNoneProvenModerateTier 2, Conditional
ItalyYesNoneModerateHighTier 2, Conditional
GreeceYesNoneInconsistentHighTier 2, Arrest only
CyprusYesCloseLowVery HighTier 3, Finance only
HungaryYes (EU)CloseUnreliableModerateAVOID
TurkeyYesMaintainedUnpredictableVery HighTier 3, Limited
SerbiaYesCloseUnreliableModerateAVOID, OPSEC risk
BelarusNoneUnion StateNoneN/AAVOID, Treat as Russia
Armenia / GeorgiaPartialVariableArrests yes, holds noLow-ModTier 2, Arrest / Bilateral Only
AzerbaijanNoneCloseNone confirmedLowAVOID, Insufficient Data

A.6 Legal Pre-Positioning Checklist

For each priority jurisdiction where an actor has documented travel patterns, complete the following before any arrest window opens:

DOCUMENT MAINTENANCE

This playbook should be reviewed and updated quarterly. Key triggers for unscheduled updates: major takedown or law enforcement action, significant actor rebrand or ecosystem restructuring, new agency alignment evidence from Russian domestic enforcement, material change in VASP or infrastructure provider compliance posture, new jurisdictional cooperation developments in Annex A jurisdictions, or identification of new FSB officer protection relationships requiring integration into Section 9 targeting.

Changes in this edition. The reconstitution claim is restated as two clocks, node and brand, after the earlier single figure was found to conflate them. The effectiveness evidence is updated to the 2025 payment and 2026 payment-rate picture, including the shift toward fewer and larger suppression payments. Section 10 gains worked cash-out examples from 2025 and 2026 and the stablecoin issuer-freeze lever. Section 11 now defers to the measurement products that exist rather than carrying its own metric list. Annex A is scoped explicitly to arrest mechanics and cross-references the separate cooperation assessment, and the South Caucasus entry is qualified by the June 2024 Yerevan arrest-and-release case. Confidence labelling is applied only to load-bearing claims.

Version tracking is maintained by the document owner and is not reflected in the document text. Recipients should confirm they hold the current version before acting on this analysis.

Ecosystem Dependency Project. This page is the full text of a corpus framework document, converted from the original for reading on the web. Content is unchanged. Figures and assessments carry the confidence language of the source document.