Rublevka Team: Anatomy of a Russian Crypto Drainer Operation
ID: cfd69501-5c34-5cb0-907f-9e41f946bbe4
STIX ID: report--cfd69501-5c34-5cb0-907f-9e41f946bbe4
Feed Name: Recorded Future Blog
Rublevka Team is an affiliate-based cryptoscam operation that uses a JavaScript “drainer” embedded in phishing landing pages (impersonating airdrops, exchanges, and DeFi services) to trick Solana wallet users into signing transactions that transfer assets to attacker-controlled addresses; the report details the group's recruitment, Telegram bot and channels, domain/infrastructure rotation, drainer functionality and modes (e.g., Honeypot, Crasher), IoCs (domains, file hashes, RPC endpoints, and ~160 Solana addresses), and observed profits totaling roughly $10.9M as of Dec 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
