logo

Rublevka Team: Anatomy of a Russian Crypto Drainer Operation

ID: cfd69501-5c34-5cb0-907f-9e41f946bbe4

STIX ID: report--cfd69501-5c34-5cb0-907f-9e41f946bbe4

Feed Name: Recorded Future Blog

Threat Score
75/100

Date Published: 2026-02-04

Date Updated: 2026-04-29

...
...

Rublevka Team is an affiliate-based cryptoscam operation that uses a JavaScript “drainer” embedded in phishing landing pages (impersonating airdrops, exchanges, and DeFi services) to trick Solana wallet users into signing transactions that transfer assets to attacker-controlled addresses; the report details the group's recruitment, Telegram bot and channels, domain/infrastructure rotation, drainer functionality and modes (e.g., Honeypot, Crasher), IoCs (domains, file hashes, RPC endpoints, and ~160 Solana addresses), and observed profits totaling roughly $10.9M as of Dec 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.