The Observatory / Document Library / Ecosystem Disruption Playbook
EDP Corpus · Document 02

Ecosystem Disruption Playbook

ECOSYSTEM DISRUPTION PLAYBOOK

Sustained Degradation of the Russia-Linked Ransomware Ecosystem

Developed by Reno

Corpus documentDoc 02

OPERATOR SNAPSHOT

Mission. Sustained ecosystem degradation, not episodic takedowns. Success is measured by compounding friction over time: actors spending more on security and reconstitution, Russian institutions treating criminals as internal liabilities, protection relationships dismantled, ransom volume and operational tempo declining across multi-quarter windows.

The 4 Phases

PhaseNameObjectiveKey Outputs
1Ecosystem MappingBuild dependency-linked map across financial, infrastructure, human terrain, protection layer, and state-interaction layersDependency graph, choke point inventory, substitutability assessment, protection relationship map
2Pressure AlignmentIdentify which Russian institutions are susceptible to which levers; align pressure to internal contradictions including manufactured contradictions via the protection layer trackAgency alignment matrix, referral targeting plan, reframing strategy, officer liability candidates
3Cost ImpositionApply coordinated pressure across financial, infrastructure, legal, social, and protection layer vectors to impose compounding costsSanctions actions, infrastructure takedowns, domestic referrals, underground trust disruption, officer exposure operations
4SustainmentMonitor adaptation, prevent reconstitution, reapply pressure to emergent nodes and successor protection relationships (continuous, never ends)Reconstitution tracking, KPI dashboards, updated pressure actions, protection relationship succession map

Critical Do / Don’t Rules

DODON’T
Lead with domestic harm framing (tax fraud, organized crime, harm to Russian citizens)Lead with geopolitical harm framing (activates protection reflexes)
Sequence low-backfire-risk actions first; disrupt protection relationship before or simultaneously with the criminal actorLead with public attribution or extradition requests (hardens protection, not suppression)
Monitor before takedown; use seizure as a data collection event and feed follow-on actionsTreat a takedown as an endpoint: without sustained follow-on pressure, actors reconstitute within 30-90 days
Exploit internal Russian institutional contradictions (MVD vs. FSB; FNS financial exposure; FSB factional competition; CBR 115-FZ friction)Seek coordinated Russian cooperation at the strategic level (not achievable; signals foreign ownership of the case)
Measure every action: define expected effect before acting; log observed results and time-to-reconstitutionRun disruption operations without measurement (narrative without accountability)

SECTION 1 | PURPOSE & SCOPE

What This Document Is

This document proposes a framework for sustained disruption operations targeting the Russia-linked ransomware and cybercrime ecosystem, including the protection infrastructure (Russian state officers and institutional relationships) that insulates top-tier actors from enforcement. It is offered as analytic input for interagency partners with operational or analytic roles.

What This Document Is Not

This document draws on structural analysis of Russian agency behavior, observed enforcement outcomes, and analytic assessments of the ransomware ecosystem. Confidence levels are labeled throughout. Realpolitik incentives, not normative expectations, drive the analytical framework.

Scope Limitations

Three categories of actor fall outside this framework's intended scope and should be flagged through separate channels if encountered:

SECTION 2 | CORE THESIS

The Russia-linked ransomware ecosystem is resilient by design. Individual actors, infrastructure nodes, and even ransomware brands reconstitute quickly after episodic disruptions. Takedowns create friction but not degradation unless compounded over time.

The correct strategic model is sustained cost imposition across multiple ecosystem layers simultaneously: financial, infrastructural, human terrain, protection layer, and domestic Russian institutional. When pressure is applied in coordination across these layers, actors face compounding costs that cannot be absorbed through simple reconstitution.

Scope qualification: the compounding friction thesis is structurally sound but rests on an assumption of sustained, coordinated multi-node pressure that has no confirmed historical precedent at this scale. Available evidence — including the 2024 ransomware revenue decline — is consistent with the model but reflects partial implementation across a subset of vectors, not a full coordinated execution. The thesis should be treated as an operational framework and planning model, not an empirically validated outcome. Confidence in the model's logic is high; confidence that full coordinated execution is achievable within current interagency and allied coordination constraints is moderate. [ANALYST INFERENCE]

A critical layer absent from many disruption frameworks is the protection infrastructure itself. FSB officers who recruit, co-opt, and shield cybercriminal actors are not passive bystanders. They are load-bearing nodes in the ecosystem. Disrupting the protection relationship is as operationally important as disrupting the criminal infrastructure it shields.

Episodic Takedownsvs.Sustained Disruption
Single actor or infrastructure targetMultiple simultaneous pressure vectors
Rapid reconstitution within 30-90 daysCompounding costs across financial, infra, human, and protection layers
Creates narrative, not lasting frictionForces tradeoffs between criminal operations and regime stability
No measurable ecosystem effectMeasurable ecosystem health degradation over time
Protection layer untouchedProtection relationships dismantled, not worked around
▶ CORE MISSION The objective is not episodic takedowns. It is sustained ecosystem degradation: increasing operational friction, raising domestic risk for criminal actors, forcing alignment of Russia's internal institutional incentives against cybercrime, and dismantling the protection infrastructure that insulates top-tier actors from enforcement. Success is measured by compounding pressure, not individual arrests.

Defining Success

The strategic principles that follow govern all phases of this framework. Violating them (particularly the engagement triggers) consistently produces the opposite of the intended effect.

SECTION 3 | STRATEGIC PRINCIPLES

3.1 Lead with Domestic Harm Framing

Russian institutions respond to internal threats, not external ones. Cybercriminals must be reframed as threats to Russian financial stability, domestic public trust, and regime legitimacy, not as foreign adversaries. Framing that emphasizes geopolitical harms activates protection reflexes and is counterproductive. Confidence: CREDIBLE

3.2 Exploit Internal Contradictions, Including Within FSB

Russian agencies do not operate in unified alignment. The FSB, GRU, MVD, and FNS frequently have competing institutional interests. Effective pressure identifies and exploits these contradictions rather than seeking coordinated Russian cooperation, which is not achievable at the strategic level. Confidence: CREDIBLE

Critically, FSB itself is not a monolith. It contains competing factions, officers with divergent financial interests, and internal competition for political favor. The officer liability track (Section 9) rests on this reality: the goal is not to activate a unified FSB response, but to create conditions where specific FSB factions or leadership figures (who have their own institutional incentives) find it in their interest to act against a specific officer. This is a different and more achievable objective than FSB cooperation.

▶ MANUFACTURING CONTRADICTIONS Contradictions are not only exploited. They can be manufactured. The protection layer track (Section 9) operationalizes this: financial exposure operations that surface an FSB officer's criminal protection relationships to competing officers or FSB leadership create contradictions where none previously existed. When an officer's krysha relationship becomes visible to FSB leadership as an attribution risk or domestic embarrassment, the institution's factional dynamics and self-preservation instincts can activate against that officer. You are not waiting for contradictions to exist, you are generating them through targeted analytic and exposure work.

3.3 Sequence for Minimum Backfire Risk

Actions that trigger protection reflexes (particularly public attribution and extradition requests) harden actor protection rather than undermining it. Pressure sequencing must account for this dynamic. Confidence: CREDIBLE

3.4 Measure Everything

Disruption operations without measurement become narrative. Every pressure action should have a defined expected effect and a mechanism for observing actual outcomes. Adaptation by actors is itself signal, log it. Confidence: CREDIBLE (as principle); implementation quality varies by resourcing

SECTION 4 | PHASE FRAMEWORK

The four phases are sequential at ecosystem scale but overlapping at the actor level. Phase 4 (Sustainment) begins as soon as the first pressure actions are taken and never ends.

PhaseNamePrimary ObjectiveKey Outputs
1Ecosystem MappingBuild a complete, dependency-linked map of the ecosystem across financial, infrastructure, human terrain, protection layer, and state-interaction layersDependency graph, choke point inventory, substitutability assessment, protection relationship map
2Pressure AlignmentIdentify which Russian domestic institutions are susceptible to which levers, and align foreign pressure to exploit internal contradictions, including manufactured contradictions via the protection layer trackAgency alignment matrix, referral targeting plan, reframing strategy, officer liability candidates
3Cost ImpositionApply coordinated pressure across financial, infrastructure, legal, social, and protection layer vectors to impose compounding costsSanctions actions, infrastructure takedowns, domestic referrals, underground trust disruption, officer exposure operations
4SustainmentMonitor adaptation, prevent reconstitution, reapply pressure to emergent nodesReconstitution tracking, KPI dashboards, updated pressure actions

4.1 Phase 1: Ecosystem Mapping

Before pressure can be applied effectively, the ecosystem must be understood as an interdependent system, not a collection of individual actors. Mapping focuses on nodes, dependencies, choke points, and substitutability. The protection layer is a mandatory fifth mapping domain.

Financial Layer

Key question: where do funds become fiat, and who touches them?

Infrastructure Layer

Key question: what is the minimum set of upstream providers whose removal collapses multiple downstream nodes?

Human Terrain

Protection Layer

Key question: for each protected actor, who is the officer or faction, what is the payment relationship, and what would make that officer a liability to FSB leadership or competing factions?

Substitutability Assessment

Substitutability is not a mapping output, it is a targeting input. Build substitutability assessments before disruption actions, not after. For each critical role:

▶ SUBSTITUTABILITY FAILURE PATTERN The most common operational error: disrupting a node without pre-positioned pressure on the identified successor. The successor steps in cleanly, reconstitution accelerates, and the operation produces a leadership transition rather than ecosystem degradation. Map the successor first. Apply pressure to the successor simultaneously with or before disrupting the primary.

State Interaction Layer

4.2 Phase 2: Pressure Alignment

Alignment means identifying which levers work through which Russian institutions, sequencing referrals to exploit internal contradictions, and ensuring domestic framing is in place before any action is taken. The full Russian agency reference is in Section 7.

Priority Channels: Confidence CREDIBLE

Secondary Channels, Confidence: CREDIBLE (conditional)

Reframing Strategy

4.3 Phase 3: Cost Imposition

Cost imposition operates across five simultaneous vectors. Actions within each vector should be sequenced from lowest to highest backfire risk and coordinated across vectors where possible.

Vector 1: Financial Pressure

Vector 2: Infrastructure Pressure

Vector 3: Legal and Non-Cyber Charges

Vector 4: Underground Social Infrastructure

Vector 5: Protection Layer Pressure

Full methodology in Section 9. Summary:

4.4 Phase 4: Sustainment

Sustainment is not a final phase, it is a continuous operational posture. Disrupted ecosystems reconstitute unless pressure is reapplied to emergent nodes.

Reconstitution Monitoring

Pressure Rotation

SECTION 5 | AFFILIATE STRATEGIC FRAMEWORK & RaaS-SPECIFIC DISRUPTION

The affiliate layer is the operational engine of the entire ecosystem. It has historically received less strategic attention than core leadership, a gap this section addresses. The framework below applies to both RaaS franchise operations and closed hierarchical groups.

5.1 Structural Comparison: RaaS vs. Closed Groups

CharacteristicClosed Group (e.g. early Conti, WizardSpider)RaaS (e.g. LockBit, Qilin, RansomHub)
StructureCentralized. Employed developers, operators, and negotiators under unified leadership.Franchise model. Small core team (3-10) provides encryptor, infrastructure, and panel. Affiliates do the hacking.
Revenue splitCentralized revenue; leadership distributes salaries or shares.70-80% to affiliates, 20-30% admin cut to core team per ransom payment.
Leadership exposureHigher. Leadership directs operations and is connected to victim activity.Lower. Core team never touches victim networks. Admin wallet abstracted through multiple layers.
Affiliate roleEmployed operators, internal, vetted, salaried or revenue-share.Independent contractors, external, self-vetted via forum reputation, disposable.
Resilience to takedownModerate. Remove leadership, remove the operation.High. Affiliates migrate to competing RaaS within days. Core team rebrands and re-recruits.
Primary disruption leverLeadership identification and arrest.Business model degradation: trust destruction, affiliate risk elevation, cash-out pressure.

5.2 Affiliate Strategic Framework, Both Group Types

Regardless of group structure, the affiliate layer shares common characteristics that make it a high-value strategic target.

Affiliate Prioritization

Priority TierProfileRationalePrimary Action
Tier 1, High ValueHigh-volume affiliates responsible for DIB, CIKR, or healthcare targeting; affiliates with documented travel outside Russia/CISMaximum operational impact + maximum arrest feasibilityThird-country arrest development; simultaneous financial designation
Tier 2, Intelligence ValueAffiliates with documented contact methods, forum handles, or infrastructure links to core team leadershipEvery affiliate arrest is a potential collection opportunity toward core team identificationArrest + structured debrief; cultivate as CI with extreme OPSEC
Tier 3, Chilling EffectHigh-profile, visible affiliates whose arrest will be observed by the remaining affiliate poolArrests chill recruitment more than any single leadership actionPublic arrest + maximum public attribution to signal ecosystem-wide risk
Tier 4, Financial PressureAffiliates with Western-touchable financial exposure (exchange accounts, real estate, business interests)Financial pressure without arrest; imposes cost even without custodyOFAC designation + VASP KYC pressure + correspondent banking exposure

Affiliate Mapping Methodology

Affiliate Migration Tracking

When a group is disrupted, affiliates migrate. Migration patterns are intelligence, they reveal which competing groups are absorbing talent, what the new operational tempo will be, and who the resilient actors are.

The Affiliate Arrest Multiplier Effect

A single well-chosen affiliate arrest produces effects that extend far beyond the individual:

5.3 RaaS-Specific: Paths to Leadership Identification

VectorMechanismReliabilityOperational Notes
Financial tracing (admin cut)Admin wallet receives a consistent percentage of every ransom. High-volume recurring flows are harder to fully obscure. Trace through layering, OTC, and exchange withdrawal.HighPrimary path. Requires blockchain forensics combined with exchange KYC pressure. Long timeline but most durable evidence.
Seized infrastructureTakedown operations on affiliate panels and leak sites yield negotiation logs, affiliate identifiers, payment addresses, and admin access patterns. Operation Cronos (LockBit, Feb 2024) produced direct visibility into admin payment flows.High (if obtained)Requires prior takedown. Intelligence from seized panels compounds over time.
Affiliate cooperationArrested affiliates know core team contact methods, forum vetting handles, and sometimes infrastructure details.MediumCooperators become CI targets if exposed. Cooperator handling requires extreme OPSEC. Exposure triggers reverse enforcement by Russian agencies.
Developer artifacts in malwareCompile-time metadata, PDB paths, error strings, language settings, and coding style fingerprint individual developers across rebrands.MediumSlow but rebrand-resistant. Most valuable for linking a new group to a prior identity after reconstitution.
Underground forum historyRaaS operators maintain reputations on Exploit and XSS. Forum registration patterns, PGP key reuse, and posting style link current identities to prior personas.MediumIntel 471 and Flashpoint are primary sources.
Infrastructure persistenceEven OPSEC-conscious groups reuse infrastructure elements across brands: ASN patterns, hosting providers, panel code, domain registration behaviors.MediumDocument infrastructure fingerprints before takedown so reconstitution is immediately detectable.

5.4 Attacking the RaaS Business Model

Trust Destruction

Payment Rail Pressure

IAB Layer Disruption

Decryptor Release

5.5 Preventing Reconstitution and Rebrands

5.6 Victim-Side Engagement Framework

The ecosystem has historically been approached from the supply side. Victim payment refusal is one of the most powerful ecosystem pressure mechanisms available, it directly attacks the financial incentive sustaining the entire RaaS model. Every refused payment imposes a cost that no infrastructure rebuild can recover. This section proposes an engagement model, not just a list of mechanisms.

The Engagement Model

Victim-side pressure does not operate through law enforcement alone. It requires coordinated engagement across five institutional channels, each of which owns a different lever. These channels should be engaged in parallel, not sequentially.

ChannelLeverEcosystem EffectEngagement Mechanism
Law Enforcement (FBI/CISA)Decryptor release + affiliate panel seizureDirect revenue reduction; undermines franchise value propositionCoordinate decryptor release with takedown operations; public release maximizes chilling effect on pending victim negotiations
CISA / Sector ISACsPre-encryption victim notificationReduces successful attack completion rate; raises affiliate operational costCISA and sector ISACs maintain victim notification pipelines, engage early to ensure high-priority sectors receive alerts before encryption completes
FinCEN / TreasuryInsurer payment policy pressureReduces victim payment rate systematically across the ecosystemFinCEN engagement with cyber insurance sector; ransomware payment coverage restrictions and mandatory law enforcement notification requirements reduce payment rates without legislative action
OFACSanctions payment prohibitionReduces payment rate for designated groups; compels victim reportingOFAC designation paired with payment prohibition guidance creates legal liability for victim payment; should be coordinated with takedown timing to maximize disruption
CISA / Sector RegulatorsResilience investment incentivesLong-term structural reduction in victim payment rateBackup and recovery capability eliminates payment incentive entirely for resilient victims; resilience standards and investment incentives are the only mechanism that attacks the demand side structurally

Connection to Supply-Side Operations

Victim-side and supply-side operations should be sequenced to compound each other:

▶ CURRENT EFFECTIVENESS SIGNAL Ransom payment volumes have declined despite attack frequency increasing. This divergence is the clearest measurable signal that multi-vector ecosystem pressure is producing real compounding friction. The drivers are consistent with the model in this playbook: better victim resilience, law enforcement trust destruction operations, sanctions reducing payment legality, and insurers tightening payment policies. The critical caveat: attacks staying high while payments fall means groups are working harder for less. Friction is real. But victims are still being hit and data is still being exfiltrated. Payment refusal is a victory; attack prevention is the harder and more important objective.

5.7 HUMINT and Cooperator Handling

The playbook references HUMINT as a source across several sections, particularly for protection relationship reconstitution tracking and core team identification. Given that cooperator exposure triggers active counterintelligence responses by Russian agencies, a brief set of handling principles is warranted. These are offered as analytic input; cooperator programs require specific authority and tradecraft that exceeds this document's scope.

Core Handling Principles

Any cooperator program requires dedicated tradecraft expertise and appropriate authority beyond this document’s scope.

SECTION 6 | TAKEDOWN vs. MONITORING: THE CORE OPERATIONAL DECISION

Whether to take down infrastructure or continue monitoring it is one of the most consequential decisions in disruption operations. The central error is treating them as competing options. They are sequential phases of a single operation.

6.1 The Core Tension

Takedown produces immediate disruption and, if infrastructure is seized rather than just shut down, an intelligence windfall, potentially years of logs, user data, transaction records, and admin access patterns. Monitoring produces ongoing intelligence but allows real harm to continue while you watch.

Monitoring advantages: reveals operational intent, planned attacks, internal disputes, and full network structure before disruption. The panic signal after a takedown, who disappears, who migrates, who tries to contact whom, is itself intelligence on network structure. Live channels with operational planning visible generally outweigh the disruption value of shutting them down, unless imminent victim harm is preventable.

Takedown advantages: burn risk, if your access is discovered, you lose the intelligence and actors migrate to a hardened platform. Seized infrastructure often exceeds the value of continued monitoring. The seizure itself is a trust destruction weapon: remaining actors do not know who cooperated or what law enforcement now knows.

6.2 Decision Threshold: When to Move from Monitor to Takedown

TriggerRationaleRisk if Delayed
Ongoing victim harm exceeds intelligence valueParticularly if critical infrastructure, healthcare, or DIB targets are being hit. Continued monitoring becomes legally and ethically indefensible.Legal/oversight exposure; reputational damage if monitoring is disclosed
Monitoring access is at risk of discoverySophisticated actors conduct counterintelligence. A controlled takedown on your terms is better than a discovered access.Loss of all intelligence; actors harden new platform
Sufficient ecosystem mapping to support follow-on actionsLeadership identified or substantially narrowed; affiliate roster mapped; financial flows traced. Marginal value of additional monitoring is declining.Diminishing returns; unnecessary harm continuation
Time-sensitive operational opportunityA key actor is traveling outside Russia, a financial window exists for simultaneous designations, or a partner operation creates a coordination moment.Missed arrest or designation window
Coordinated multi-partner action is readyMaximum disruption requires simultaneous action across jurisdictions. When all partners are aligned, delay reduces coordination quality.Partner readiness degrades; coordination gaps widen
▶ BOTTOM LINE Monitor to map. Take down at maximum yield. Use seized data to pursue follow-on actions. Monitor reconstitution to target the next iteration. The takedown is a phase, not an endpoint.

SECTION 7 | RUSSIAN AGENCY QUICK REFERENCE

Confidence levels reflect observed enforcement behavior, not legal doctrine. Note: FSB is not treated as a unified actor. Internal factions, competing officer interests, and political dynamics within FSB create divergent enforcement behaviors, the column below reflects FSB's aggregate behavior while Section 9 operationalizes the factional divergences.

AgencyRole in EcosystemBest Leverage PointsConfidenceKey Limits
FSBPrimary architect of cyber ecosystem; recruits, co-opts, or protects actors for CI and strategic ops. Internally factional, competing officers and units have divergent interests that can be exploited.Attribution fallout; actor defiance of recruitment; actor ties to foreign intelligence; manufactured liability via protection layer exposure (Section 9); factional competition between FSB unitsHigh (selective)No legal cooperation as an institution. Foreign pressure reduces enforcement appetite at agency level. Individual factions may act when actor defies, embarrasses, or becomes a liability to specific officers or units.
GRULeverages actors for military/geopolitical ops; rarely arrests but will silence or cut off. Note: actors absorbed into wartime GRU operations fall outside this framework's scope.Sloppy OPSEC; attribution risk to ongoing ops; actor disobedience post-campaignLowNo transparency; no prosecutorial handoff. Disruption must be indirect.
MVD / Dept KEnforces mid-level fraud and technical cybercrime; reputationally sensitive; sidelined in elite casesDomestic financial harm; media scrutiny; interagency competition with FSB; arrest metrics pressureHigh (non-RIS)FSB can override at any time. Not accessible for RIS-linked actors.
FNSIdentifies shell companies, undeclared income, and lifestyle inconsistencies; no arrest powerFinancial irregularities; family asset exposure; laundering front structuresMed-HighAction requires political greenlight. Surfaces exposure; does not prosecute.
RosfinmonitoringRussia's financial intelligence hub; maps laundering infrastructure; triggers asset controls and referralsCrypto-fiat flows; suspicious transactions; Egmont Group scrutiny pathwaysHigh (mapping)Politicized. Requires downstream adoption by MVD or FSB to produce arrests.
CBRVia 115-FZ, enables banks to freeze or deny transactions based on risk without prosecutionSuspicious transaction patterns; politically exposed clients; AML risk flagsMed-HighDoes not attribute activity or target individuals. Non-attributable friction only.
SKREngages only when cybercrime is elevated to elite criminality or political scandalPolitical embarrassment; regime exposure; organized crime framing (Art. 210)MediumNot reachable through standard LE channels. Requires Kremlin-level political signal.
RoskomnadzorRestricts communications platforms; imposes infrastructure frictionHosting noncompliance; foreign platform resistance; digital sovereignty framingMediumDoes not target individuals. Disrupts legitimate users equally.

SECTION 8 | ENGAGEMENT TRIGGERS TO AVOID

These patterns consistently cause Russian agencies to protect, absorb, or redirect cybercriminals rather than suppress them. They are drawn from historical enforcement outcomes and institutional behavior analysis. Red = high backfire risk (avoid or delay until actor is isolated). Amber = conditional risk (proceed with domestic framing in place).

TriggerEffectMechanismImplication for Operations
Public attribution by foreign governmentActor converts from criminal liability to national security assetOnce named by a foreign power (especially the U.S.), FSB/GRU may treat actor as soft-state asset regardless of prior behaviorAttribution hardens protection. Publicity equals absorption. Delay public attribution until actor is already isolated.
Formal arrest or extradition requestTriggers defensive nationalism; reduces arrest probability to near zeroRussian doctrine opposes surrender of nationals. Extradition requests signal foreign ownership of the case.Extradition-first strategies produce the opposite of suppression. Pursue third-country arrest opportunities instead.
Media naming and shaming campaignsAgencies treat engagement as hostile information warfare; enforcement appetite declinesWhen actors are labeled 'Russian cybercriminals' without domestic impact framing, it reads as sovereignty violationPaired domestic framing is required before any public naming.
Indication of actor cooperation with foreign LEActor becomes a counterintelligence interest; FSB views as double-agent riskSuspected cooperators are arrested, disappeared, or neutralizedCooperator handling requires extreme operational security. Exposure of cooperation triggers reverse enforcement.
Actor technical value or recruitment potentialDelays or cancels enforcement; actor becomes reusable state assetActors with malware or infrastructure capabilities are considered recruitablePrioritize disruption of capability before it triggers recruitment.
Target selection aligned with Russian strategic interestsActor becomes functionally aligned with state objectives; impunity followsOperations against Western banks, NATO infrastructure, or sanctions enforcement are considered symbiotic by Russian stateDocument target patterns to predict and preempt state absorption.
Internal elite sponsorship (krysha)Immunity from arrest regardless of cybercrime visibilityActor operates under protection of regional, political, or RIS patronPressure must first weaken or circumvent sponsor relationship. FNS/Rosfinmonitoring exposure of patron is prerequisite.
Multilateral pressure without local framingResistance from all Russian agencies; interpreted as sovereignty violationPressure through Western consortiums without Russian criminal charge equivalents reads as hostileAlign multilateral pressure with simultaneous domestic framing.
▶ BOTTOM LINE Russian agencies protect cybercriminals when engagement signals foreign ownership, regime threat, or operational opportunity. Effective disruption depends on avoiding these triggers while exploiting internal contradictions and institutional sensitivities.

SECTION 9 | PROTECTION LAYER DISRUPTION: FSB OFFICER LIABILITY TRACK

9.1 Core Concept: Protection as a Load-Bearing Ecosystem Node

FSB officers who provide krysha, recruitment, and protection to cybercriminal actors are not peripheral to the ecosystem, they are load-bearing nodes. Disrupting a criminal actor whose protection relationship remains intact produces reconstitution. Disrupting the protection relationship first, or simultaneously, produces ecosystem degradation.

The mechanism: individual FSB officers maintain protection relationships because they generate personal value, financial, operational, reputational within the service. When a specific protection relationship generates more cost than value, domestic embarrassment, attribution risk to the officer personally, institutional liability to FSB leadership or competing factions, the pressures on that officer change. You are not asking FSB to cooperate as an institution. You are creating conditions where a specific officer's calculus shifts, or where competing FSB factions find it advantageous to act against the liability-generating officer. These are different and more achievable objectives.

This distinction matters operationally. FSB's internal factions do not share interests. An officer in the FSB's economic security directorate and an officer in a cyber unit may be in active competition. Surfacing one officer's criminal financial exposure to competing FSB units, rather than to FSB 'leadership' as an abstraction, is a more precise and realistic targeting objective. Confidence: Medium-High (mechanism is well-supported; execution difficulty is high)

Worked example (Karakurt / Zolotarjovs, May 2026). On 4 May 2026 a US court sentenced Deniss Zolotarjovs to 102 months for his role in Karakurt, a data-extortion group the Department of Justice describes as led by former Conti leadership. DOJ stated the group relied on access to Russian government databases and law-enforcement connections, and paid bribes to secure military draft exemptions and tax avoidance for its members. This is the clearest open-source confirmation to date of the premise in this section: protection is a purchased, load-bearing relationship with named state touchpoints (government databases, draft boards, tax authorities), not a vague tolerance. It also illustrates the officer-liability logic in reverse. The same corruption that shields members is itself documentable financial exposure, exactly the paper trail the financial-exposure methodology below is built to surface. Confidence: Confirmed (DOJ statement and sentencing, 4 May 2026).

9.2 Officer Relationship Types and Leverage

Officer Relationship TypeProtection MechanismLiability TriggerPrimary Lever
Direct handler / recruiterTasks criminal actors for intelligence collection or strategic ops; provides operational coverSloppy OPSEC by the criminal actor creating attribution risk back to the officer; criminal actor creating domestic harm visible enough to attract MVD attentionAttribute criminal actor's domestic harm to officer's operational portfolio; surface attribution risk to competing FSB units
Krysha / protection providerFinancial relationship, officer receives payment to ensure enforcement non-interferenceFinancial exposure: payment flows documented and surfaced domestically; Western asset exposure via sanctionsAnomalous outflow analysis to document payment relationship; FNS lifestyle referral on officer; simultaneous criminal network + officer sanctions
Passive tolerance / non-interferenceOfficer aware of actor but chooses not to act; implicit protection through inactionActor creates embarrassment or domestic harm sufficient to make the officer's inaction visible to superiors or competing unitsDomestic harm amplification via investigative journalism; FNS lifestyle flags on actor to create paper trail officer cannot ignore
Retired / former officerResidual institutional relationships and access used to provide informal protectionNo active institutional protection; most vulnerable to financial sanctions and third-country arrestWestern asset designation; third-country arrest development (Annex A); family financial exposure

9.3 Financial Exposure Methodology for Officers

FSB officers on government salary who maintain protection relationships with high-volume cybercriminal actors accumulate financial exposure that does not match their declared income. Building this exposure profile requires no HUMINT, it is an open source and financial registry analytic task that extends directly from the criminal-side financial mapping already in this playbook. All deliverables in this section are proposed; none currently exist.

Step 1: Identify Anomalous Outflows from Criminal Actor Finances

This is the keystone analytic task. Detailed methodology in Section 10. For this section: the question to ask of every criminal actor's financial map is what outflows do not fit criminal operational cost profiles.

Step 2: Build the Officer Financial Profile

Step 3: Channel Selection for Exposure

ChannelMechanismBackfire RiskBest Use Case
FNS referral (domestic)Lifestyle inconsistency and undeclared income flagged to Federal Tax Service, no foreign fingerprint, purely domestic processLowOfficers with documented Russian-held assets inconsistent with salary; generates domestic paper trail
Rosfinmonitoring referralSuspicious transaction flags on protection payment flows, feeds CBR 115-FZ freeze pipelineLowHigh-volume payment flows between criminal actor and officer-linked accounts
Investigative journalism (OCCRP / Bellingcat / iStories / Meduza)Financial and lifestyle documentation provided to investigative outlets, produces domestic scandal framing rather than foreign attributionMedium (lower than official attribution)Officers with Western asset exposure and documentable lifestyle inconsistency; creates domestic embarrassment without official foreign-government fingerprint
Simultaneous OFAC/OFSI designationOfficer + criminal network designated simultaneously; Western asset freeze + correspondent banking pressureMedium-High (acceptable if domestic framing pre-positioned)Retired/former officers or officers already domestically exposed; batch with criminal network to maximize impact
Third-country legal pre-positioningSealed indictments or arrest warrants filed in viable European jurisdictions; activated when travel window opensLow (if kept sealed)Officers with documented travel patterns to viable jurisdictions (Annex A)

9.4 Manufacturing Internal FSB Contradictions

The goal is not to get FSB to cooperate as an institution, it is to make specific officers liabilities that competing FSB units or FSB leadership's factional interests will act against. This requires surfacing the right information to the right internal FSB audience, which requires knowing which FSB factions are in competition with the officer's unit. Confidence: Medium (mechanism is sound; intelligence requirements are high)

What Makes an Officer a Liability to FSB Leadership or Competing Factions

9.5 Portfolio Sequencing for Officer Targets

TierOfficer ProfileAction SequenceTimeline
Tier 1, ImmediateRetired/former officers with Western asset exposure and active criminal network tiesFinancial profile build → OFAC/OFSI designation (officer + criminal network simultaneously) → third-country arrest legal pre-positioning → investigative journalism pipeline0-90 days
Tier 2, Financial ExposureActive duty krysha officers with documentable payment relationshipsAnomalous outflow identification → FNS referral → Rosfinmonitoring flag → investigative journalism (if profile is strong) → OFAC designation after domestic exposure is established90-180 days
Tier 3, Contradiction ManufacturingActive duty handlers whose protected actors are generating domestic harm or attribution riskDomestic harm amplification → attribution risk surfacing to competing FSB unit awareness → operational incompetence signaling via repeated disruption of protected actor → monitor for protection relationship strain180-365 days
Tier 4, Long LeadActive duty officers with unclear status or current high collection valueMonitor only, define trigger conditions before monitoring begins; do not act until protection relationship mapping is complete and successor officer is identifiedOngoing
▶ COMPOUNDING FEEDBACK LOOP Criminal-side financial pressure → anomalous outflow identification → officer financial profile → FNS/investigative journalism exposure → domestic liability for officer → FSB factional pressure on officer's relationship → criminal actor loses protection → criminal actor becomes accessible to MVD enforcement → MVD enforcement generates more intelligence on financial flows → stronger anomalous outflow identification → repeat. Each cycle strengthens the next.

SECTION 10 | CRYPTO-TO-FIAT METHODOLOGY

10.1 Why This Is the Keystone Analytic Task

Every financial pressure action in this playbook, wallet designations, VASP engagement, correspondent banking exposure, OTC node targeting, protection payment identification, requires knowing where funds become fiat and who touches them. Without a documented cash-out graph, financial pressure actions are targeted at symptoms rather than structural nodes. With it, single actions produce cascading disruptions across multiple actor flows.

The cash-out graph also contains the protection payment data that drives the Section 9 officer liability track. Anomalous outflows, payments that do not fit criminal operational cost profiles, are only identifiable against a complete model of what criminal operational costs look like. Build the model first.

10.2 The Cash-Out Graph: Layer Structure

LayerWhat It ContainsKey QuestionsPrimary Sources
Layer 1: Ransom ReceiptInitial ransom payment wallets; victim-to-actor payment flows; multi-sig escrow structures used in negotiationWhat wallets receive ransom payments? Are they reused or single-use? What mixing or structuring occurs immediately post-receipt?Chainalysis Reactor; TRM Labs; on-chain forensics
Layer 2: LayeringMixing services, chain-hopping (BTC→Monero→BTC), structuring into sub-threshold amounts, peel chains, consolidation walletsHow many hops before funds reach a cash-out node? What mixing services are used? Are layer 2 wallets shared across multiple actor flows?Chainalysis; TRM; Elliptic, cross-validate outputs
Layer 3: Pre-Cash-Out AggregationConsolidation wallets that aggregate layered funds before exchange deposit or OTC transfer; admin cut separation at this layerWhere does the admin cut separate from affiliate payments? What wallets aggregate funds from multiple ransom flows? These are high-value designation targets.Blockchain forensics, look for consistent percentage splits
Layer 4: Cash-Out NodesOTC brokers, exchange deposits (VASP), peer-to-peer platforms, payment aggregators, crypto ATMsWhich specific OTC nodes and exchange accounts receive funds? What are the withdrawal patterns? What geographic concentration exists?Chainalysis + exchange KYC pressure; Intel 471 for OTC broker identification
Layer 5: Fiat EntryBank accounts, payment systems, real estate purchases, front company revenue, luxury asset acquisitionWhich banks receive fiat proceeds? What front companies hold proceeds? Where does money enter the legitimate financial system?Rosfinmonitoring referrals; FNS corporate registry; property registries; correspondent banking data

10.3 Anomalous Outflow Identification

Once the standard cash-out graph is built, anomalous outflows become visible as flows that do not fit the expected pattern at each layer. These are protection payment candidates.

Criminal Operational Cost Baseline

Establish what normal operational costs look like before flagging anomalies:

Anomalous Outflow Indicators

▶ ANALYTICAL DISCIPLINE NOTE Anomalous outflow identification requires a complete operational cost baseline before anomalies can be flagged. Designating a wallet as a protection payment candidate without establishing what normal looks like produces false positives that undermine subsequent legal action. Build the baseline first. Flag anomalies against it. Cross-validate across multiple ransom payment flows for the same actor before drawing conclusions.

10.4 OTC Broker Network Mapping

OTC brokers are the most critical cash-out bottleneck in the Russian ransomware ecosystem. Unlike exchanges, they are relationship-based, less regulated, and serve as the primary bridge between crypto and Russian domestic fiat for high-volume criminal actors.

OTC Identification Methodology

OTC Network Graph Components

SECTION 11 | MEASUREMENT FRAMEWORK

Disruption operations without measurement produce narrative, not accountability. This section defines the minimum viable measurement posture for tracking ecosystem health and operational effectiveness. None of these measurement capabilities currently exist; they are proposed for build-out.

11.1 Establishing Baselines

KPIs defined without documented baselines cannot be used to attribute change to specific actions versus ecosystem-level trends. Establish baselines before any pressure actions are taken.

11.2 Ecosystem Health KPIs

KPIWhat It MeasuresSourceCadence
Active ransomware groups (count)Total groups posting victims; proxy for ecosystem breadthRansomware.liveMonthly
Victims posted per week (rolling average)Operational tempo; leading indicator of ecosystem healthRansomware.liveWeekly
Ransom payment volume (USD)Financial incentive sustaining ecosystem; lagging indicatorChainalysisQuarterly
Time to reconstitution after takedownResilience measure; declining trend = increasing frictionCensys / internalPer event
BPH provider count (active)Infrastructure supply; declining trend = upstream pressure workingShadowserver / CensysMonthly
Sanctioned wallet activity (post-designation)Sanctions effectiveness; continued activity = compliance gapChainalysis / TRMMonthly
Underground market activity indexForum post volume, pricing stability, trust-node activity; proxy for market healthIntel 471 / FlashpointQuarterly
New IAB listings (count)Supply of network access available to ransomware affiliatesIntel 471 / FlashpointMonthly
Affiliate migration speed post-disruptionEcosystem resilience; fast migration = low friction; slow = increasing costIntel 471 / forum monitoringPer event
Victim payment refusal rate (where measurable)Victim-side resilience; increasing trend compounds supply-side pressureCoveware / insurer reportingQuarterly
Protection relationship reconstitution timeHow quickly disrupted actors acquire new FSB protection; declining speed = officer network under pressureHUMINT / forum monitoring / enforcement gap analysisPer event

11.3 Protection Layer Leading Indicators

Reconstitution time is a lagging indicator, it measures outcomes after the fact. The following leading indicators are proposed to track Section 9 progress before protection relationship changes are observable in reconstitution data:

Leading IndicatorWhat It SignalsSourceCadence
Officer lifestyle exposure pipeline activityFNS referrals filed; investigative journalism materials prepared and delivered, signals that exposure operations are in motion before domestic effects are visibleInternal trackingMonthly
Anomalous outflow identification progressNumber of protection payment candidates documented with cross-validation, leading indicator for both officer profiles and designation packagesInternal trackingMonthly
Criminal actor forum signals re: protection confidenceUnderground forum discussions showing actor uncertainty about protection status, complaints about krysha quality, or explicit concern about handler reliability, these precede protection relationship breakdownIntel 471 / Flashpoint / forum monitoringMonthly
Reconstitution attempts without normal protection speedActor attempts to reconstitute more slowly than historical baseline, or without the infrastructure access that protected actors typically have, signals protection may be weakening before explicit breakdownCensys / internal monitoringPer event
Protection payment flow routing changesAnomalous outflows rerouting, declining in volume, or converting through different channels than established pattern, may signal actor concern about protection relationship integrityChainalysis / TRMMonthly

11.4 Pressure-Effect Ledger

Every significant pressure action should be logged in a structured ledger. This enables retrospective analysis of what worked, what failed, and what adaptation patterns emerged.

FieldDescriptionRequired?
Action dateDate action was takenYes
Action typeSanction / takedown / referral / designation / exposure / officer liability action / otherYes
TargetActor, wallet, domain, provider, node, or officer targetedYes
Expected effectWhat outcome was predicted and over what timeframeYes
Observed effectWhat actually happened; include null result if no observable changeYes
Time to reconstitutionDays until actor resumed operations or infrastructure re-appearedIf applicable
Protection status changeDid protection relationship change following action? New officer? Weakened protection? New FSB faction involved?If applicable
Adaptation patternHow actor adapted; use this to update substitutability modelsIf applicable

11.5 Recommended Investment Priorities

These recommendations are offered for consideration by operational and policy stakeholders. None are currently resourced; all require appropriate authority and partner coordination before implementation.

SECTION 12 | TOOL & PARTNER REFERENCE

Vendors provide validation, not conclusions. Outputs should be cross-checked across multiple sources before driving operational decisions.

Tool / PartnerCategoryWhen to UseKey Questions to Ask
Chainalysis Reactor / Data SolutionsBlockchain attributionWallet clustering, sanctions exposure screening, laundering typology mapping, tracing from ransom payment to cash-outWhat assumptions underpin the clustering? Where does attribution confidence drop? What exchanges or OTC nodes touch the end of the chain?
TRM Labs / EllipticBlockchain attributionCross-validation of Chainalysis outputs; sanctions screening; VASP risk profilingWhere do outputs diverge from Chainalysis, and why? What is the confidence basis for VASP compliance risk scoring?
Mandiant / CrowdStrike IntelligenceMalware & campaign intelMalware lineage and evolution, affiliate migration, tradecraft shifts, actor attributionWhat would falsify this attribution? What evidence supports continuity vs. rebrand? What replaces this toolchain within 30 days?
ESET Research / Kaspersky (open-source only)Malware & campaign intelTechnical malware analysis, campaign tracking; Kaspersky limited to public reporting with verificationWhat is the publication basis? For Kaspersky: has this been corroborated by a second source?
Intel 471 / FlashpointUnderground monitoringUnderground market dynamics, pricing, trust relationships, actor reputation, recruitment channels, forum activityWhat is the source methodology? How current is the access? Where does underground visibility drop off?
Ransomware.live / RansomLookVictim & campaign trackingReal-time victim counts, leak site monitoring, group activity tracking, ecosystem health KPIsWhat is the data lag? Are posting dates confirmed or estimated? What groups are absent from monitoring?
Shadowserver / CensysInfrastructure attributionInfrastructure persistence and reconstitution patterns, ASN and hosting clustering, BPH provider mappingWhat upstream dependencies are shared across multiple criminal nodes? How quickly does reconstitution appear in scan data?
Recorded Future / Microsoft MDTIInfrastructure & OSINTDomain and IP intelligence, cross-platform OSINT fusion, threat actor profiling, infrastructure persistenceWhat is the evidence basis for actor-to-infrastructure attribution? What is the confidence tier?
OCCRP / Bellingcat / iStories / MeduzaInvestigative journalism pipelineOfficer financial exposure and lifestyle documentation; surfacing protection relationship evidence through non-attributable channelsIs the documentation package sufficient to withstand investigative scrutiny? Does it contain USG fingerprints that would trigger backfire? Is domestic framing pre-positioned?

ANNEX A | EUROPEAN JURISDICTIONAL FRAMEWORK

This annex provides country-by-country assessment of European jurisdictions for third-country arrest viability, legal pre-positioning requirements, and treaty landscape for Russia/CIS-linked cybercriminal actors and FSB officers. Five Eyes jurisdictions (US, UK, Canada, Australia, New Zealand) are treated as assumed known baseline and not covered here.

Assessment criteria for each jurisdiction: extradition treaty status with the U.S.; treaty status with Russia (a bilateral extradition treaty with Russia makes the jurisdiction less viable as Russia can request competing extradition); rule of law and judicial independence; historical cooperation on cybercrime cases; travel pattern intelligence; and practical arrest infrastructure (liaison relationships, legal pre-positioning lead time).

A.1 Tier 1, High Viability (Priority Pre-Positioning)

Germany

Extradition treaty (U.S.)Yes, bilateral treaty; active cooperation history
Treaty with RussiaNone, Russia cannot compete for extradition
Cooperation track recordHigh, Operation Endgame (2024) demonstrated deep BKA/FBI/Europol cooperation; German prosecutors have filed independent cybercrime indictments
Travel pattern relevanceSignificant Russian business and diaspora community; transit hub for Eastern European actors traveling west
Pre-positioning lead time60-90 days for coordination with BKA and German federal prosecutors; MLAT requests processed efficiently
Key limitsGerman courts require substantial evidentiary basis before issuing arrest warrants on foreign requests; political sensitivity around Russia-related cases post-2022 has increased rather than decreased cooperation willingness
VerdictVIABLE, TIER 1. Priority pre-positioning jurisdiction. BKA relationship and Operation Endgame precedent make this the strongest European arrest jurisdiction for cybercrime.

Netherlands

Extradition treaty (U.S.)Yes, active cooperation; NHTCU has deep FBI/DOJ relationship
Treaty with RussiaNone
Cooperation track recordExceptional, Operation Cronos (LockBit), Hive takedown, DoubleVPN, RaidForums all involved Dutch jurisdiction; NHTCU is among the most capable and cooperative cybercrime units in Europe
Travel pattern relevanceAmsterdam Schiphol is a major transit hub; significant Russian business presence; financial sector attracts criminal financial infrastructure
Pre-positioning lead time45-60 days; established MLAT channels and existing working relationships accelerate pre-positioning
Key limitsDutch legal standards for provisional arrest require imminent flight risk documentation; judges are independent and will scrutinize evidentiary basis
VerdictVIABLE, TIER 1. Possibly the single strongest European jurisdiction for cybercrime arrests. Default first-choice pre-positioning jurisdiction.

Spain

Extradition treaty (U.S.)Yes, bilateral treaty; multiple successful extraditions
Treaty with RussiaNone
Cooperation track recordGood, multiple Russia/CIS cybercrime arrests; Spanish law enforcement has demonstrated willingness to act on U.S. requests
Travel pattern relevanceHigh, favored destination for Russian/CIS criminal actors and oligarchs; Costa del Sol and Barcelona have significant Russian community presence; known residence jurisdiction for multiple cybercriminal actors
Pre-positioning lead time60-90 days; Guardia Civil and Policia Nacional have established FBI liaison relationships
Key limitsSpanish judicial process can be slow; provisional arrest requests require prompt follow-up with formal extradition documentation or the subject must be released
VerdictVIABLE, TIER 1. High travel pattern relevance elevates Spain as a high-priority pre-positioning jurisdiction, particularly for actors known to reside or vacation there.

A.2 Tier 2, Conditional Viability (Compressed Assessment)

JurisdictionKey StrengthsKey LimitsVerdict
FranceBilateral U.S. extradition treaty; Paris and Riviera have Russian high-net-worth presence; ANSSI and DGSI have participated in joint operationsJudicial process is slow (90-120 day pre-positioning lead time); French courts are genuinely independent, provisional arrest without strong evidentiary package risks releaseTIER 2, CONDITIONAL. Secondary option; do not rely as primary jurisdiction unless actor has documented presence.
PolandBilateral U.S. extradition treaty; no Russia extradition treaty; strong post-2022 political motivation to counter Russian-linked activity; ABW expanding cybercrime cooperationLess established MLAT infrastructure; judicial standards less predictable than Western European counterparts; more relevant for Eastern European actors than Russian actors specificallyTIER 2, CONDITIONAL. Increasing viability post-2022. Best for Eastern European-based actors transiting Poland.
Czech RepublicBilateral U.S. extradition treaty; no Russia treaty; Nikulin arrest (2017) proved viability; Czech courts withstood Russian diplomatic pressureNikulin-style cases attract significant Russian diplomatic pressure; Czech authorities held firm but the political cost was realTIER 2, CONDITIONAL. Proven jurisdiction with established precedent. Russia will apply maximum diplomatic pressure on high-profile cases.
ItalyBilateral U.S. extradition treaty; no Russia treaty; high Russian high-net-worth residential presence (northern Italy, Sardinia)Slow judicial process (90-120 day lead time); inconsistent cooperation track record; provisional arrest procedures less streamlined than Northern EuropeTIER 2, CONDITIONAL. High travel relevance but slower and less predictable. Pre-position for actors with documented Italian presence; not primary for time-sensitive operations.
GreeceBilateral U.S. extradition treaty; no Russia treaty; Vinnik arrest (2017) demonstrated viability; high Russian tourist and transit traffic; significant Russian property ownershipVinnik case showed Greece will arrest but then spent years processing competing extradition requests from Russia and France, extradited to France, not U.S. (2022). Viable for arrest; unreliable for extradition completion.TIER 2, ARREST ONLY. Use for disruption and detention while primary extradition proceedings run through a more reliable jurisdiction. Do not pre-position as sole extradition pathway.

A.3 Tier 3, Limited Viability

JurisdictionActor PresenceKey ProblemUse
CyprusVery high, major Russian business and residential jurisdiction; significant Russian asset holding post-2022 sanctions evasionDeep Russian economic integration creates political obstacles to cooperation. Low active cooperation track record despite bilateral U.S. extradition treaty.FINANCIAL DOCUMENTATION ONLY. Most valuable as a financial registry and asset mapping jurisdiction. Do not pre-position for arrest.
HungaryModerate, Budapest transit point; some Russian actor presenceOrban government's Russia policy makes this jurisdiction actively unreliable for Russia-linked cases regardless of EU membership and treaty status. Has blocked EU sanctions measures.AVOID FOR RUSSIA-LINKED CASES. Do not pre-position here.
TurkeyVery high, Istanbul and Antalya are among the most significant Russian actor transit and residence jurisdictions post-2022 sanctions; Turkish financial system actively used for sanctions evasionIndependent Russia policy and economic interests create significant unpredictability. Some cases have received cooperation; others have not. Treat every Turkey-based operation as a potential compromise risk.LIMITED, TIER 3. Useful for financial documentation and asset mapping. Do not rely on Turkish cooperation for high-priority arrest operations without current bilateral relationship assessment.

A.4 Avoid, Explicit Entries

JurisdictionWhy Avoid
SerbiaRussia alignment and limited extradition cooperation. Serbian authorities have demonstrated willingness to alert Russian-linked subjects to law enforcement interest, making Serbia an active operational security risk. Do not pre-position, do not share case information with Serbian authorities, do not rely on Serbian cooperation for any Russia-linked operation.
BelarusUnion State, operationally equivalent to Russia. Lukashenko government will not cooperate on any Russia-linked cybercrime case. Actors based in Belarus have the same practical protection as actors based in Russia.
Armenia / GeorgiaGeorgia and Armenia have both produced confirmed arrests of Russian nationals and should not be treated as equivalent to Russia-aligned jurisdictions. Neither has a U.S. extradition treaty, and formal extradition frameworks are underdeveloped in both. However, operational cooperation has occurred on a case-by-case basis and should be pursued through bilateral LE channels rather than formal treaty mechanisms. Georgia is the more viable of the two post-2022: Russia-Georgia tensions have increased Georgian willingness to act, and Georgian authorities have demonstrated operational cooperation on specific cases. Armenia has also produced confirmed arrests despite its historically closer Russian alignment. Both jurisdictions carry risks of Russian pressure on local authorities and require tight operational security and limited advance disclosure. Pre-position through bilateral relationships, not MLAT. Do not treat as primary extradition jurisdictions; treat as viable arrest and temporary detention jurisdictions with case-by-case assessment required.
AzerbaijanNo U.S. extradition treaty. Significant Russian economic and political influence. No confirmed operational cooperation on Russia/CIS cybercrime cases. Cooperation posture is unpredictable and insufficient data exists to assess viability. Do not pre-position. Monitor for changes in bilateral posture; reassess if cooperation track record develops.

A.5 Jurisdictional Quick Reference

JurisdictionExtradition (US)Russia TreatyTrack RecordTravel RelevanceTier
GermanyYesNoneHighHighTier 1, Viable
NetherlandsYesNoneExceptionalHighTier 1, Viable
SpainYesNoneGoodVery HighTier 1, Viable
FranceYesNoneModerateMod-HighTier 2, Conditional
PolandYesNoneIncreasingModerateTier 2, Conditional
Czech RepublicYesNoneProvenModerateTier 2, Conditional
ItalyYesNoneModerateHighTier 2, Conditional
GreeceYesNoneInconsistentHighTier 2, Arrest only
CyprusYesCloseLowVery HighTier 3, Finance only
HungaryYes (EU)CloseUnreliableModerateAVOID
TurkeyYesMaintainedUnpredictableVery HighTier 3, Limited
SerbiaYesCloseUnreliableModerateAVOID, OPSEC risk
BelarusNoneUnion StateNoneN/AAVOID, Treat as Russia
Armenia / GeorgiaPartialVariableInsufficientLow-ModTier 2, Arrest / Bilateral Only
AzerbaijanNoneCloseNone confirmedLowAVOID, Insufficient Data

A.6 Legal Pre-Positioning Checklist

For each priority jurisdiction where an actor has documented travel patterns, complete the following before any arrest window opens:

DOCUMENT MAINTENANCE

This playbook should be reviewed and updated quarterly. Key triggers for unscheduled updates: major takedown or law enforcement action, significant actor rebrand or ecosystem restructuring, new agency alignment evidence from Russian domestic enforcement, material change in VASP or infrastructure provider compliance posture, new jurisdictional cooperation developments in Annex A jurisdictions, or identification of new FSB officer protection relationships requiring integration into Section 9 targeting.

Version tracking is maintained by the document owner and is not reflected in the document text. Recipients should confirm they hold the current version before acting on this analysis.

Ecosystem Dependency Project. This page is the full text of a corpus framework document, converted from the original for reading on the web. Content is unchanged. Figures and assessments carry the confidence language of the source document.