Rublevka Team is a Russian cybercriminal cryptocurrency-theft operation active since 2023 that runs an affiliate-driven wallet-draining service model. The group is commonly described as a traffer team focused on social engineering and traffic acquisition rather than traditional network intrusion or infostealer deployment. It provides low-skill affiliates with turnkey tooling to create spoofed cryptocurrency-themed landing pages, lure victims with airdrops, giveaways, and token-purchase themes, and induce them to connect wallets and sign malicious transactions that transfer assets to the operators. The operation has been associated with the aliases Rublevka and rublevka_team. It has operated primarily through Russian-language cybercrime communities including LolzTeam, with additional presence on Exploit and XSS, and uses Telegram extensively for affiliate recruitment, automation, support, profit tracking, and operational coordination. Its platform includes landing-page generators, cloaking and evasion features, automated notifications, payout automation, and support for a large number of wallet types. Rublevka Team initially focused on The Open Network ecosystem and later pivoted heavily to Solana, with Solana-focused campaigns accounting for most of its reported revenue. Rublevka Team’s core tradecraft centers on spoofing trusted cryptocurrency brands and services, embedding custom obfuscated JavaScript drainer logic in phishing pages, and using wallet-specific social-engineering flows to maximize transaction approval by victims. The group has used infrastructure rotation, cloaking, benign fallback pages, and anti-scanner measures to reduce detection and disruption. Its model resembles broader crime-as-a-service and ransomware-affiliate ecosystems in that administrators supply tooling, infrastructure, and revenue-sharing arrangements while affiliates handle victim acquisition. Reported proceeds exceed $10 million in stolen cryptocurrency, making Rublevka Team a notable example of industrialized, service-based crypto theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates a highly automated scam-as-a-service platform focused on crypto wallet draining. Provides affiliates turnkey tooling (Telegram bots, landing page generators, cloaking, automated payout infrastructure) to run high-volume social-engineering campaigns that trick users into signing malicious transactions (airdrop/token-buy scams), with a pivot from TON to Solana driving most revenue.
Affiliate-driven cryptocurrency wallet-draining operation (since 2023) using spoofed landing pages and custom JavaScript to trick victims into connecting wallets and approving fraudulent transactions; provides automation via Telegram bots and landing-page generators.
Affiliate-driven cryptocurrency drainer operation ("cryptoscam"/traffer team) primarily active on LolzTeam with presence on Exploit and XSS. Initially ran fake crypto exchanges and TON-themed lures, then shifted (2024 onward) to a custom JavaScript wallet drainer embedded in landing pages impersonating token airdrops/giveaways and DeFi services; later pivoted to Solana (SOL) in 2025. Uses Telegram bots/channels for affiliate onboarding, landing-page generation, cloaking/"white pages" for evasion, and automated profit splitting; rotates domains and uses obfuscated JS (index.js) plus RPC services (Helius/WalletConnect/PublicNode) to execute draining transactions.
Affiliate-driven cryptocurrency drainer operation ("traffer"/cryptoscam team) advertising on underground forums and operating primarily via Telegram + LolzTeam. Uses custom obfuscated JavaScript wallet-drainer landing pages impersonating airdrops/giveaways and DeFi/crypto brands to trick victims into signing Solana transactions, draining SOL/SPL tokens/NFTs; provides bots, landing-page generator, cloaking/bypass features, and profit-splitting to affiliates.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.