Operation Destabilise is a threat campaign tracked across 2 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed November 20, 2025; most recent activity November 21, 2025.
Operation Destabilise is described in recent reporting as a Russia-linked ransomware-for-profit threat campaign. Reports indicate the group purchased a private bank to launder cybercrime proceeds, including ransomware profits, illustrating a shift toward using legitimate financial institutions to conceal illicit gains. The campaign's significance lies in its fusion of cybercrime with financial infrastructure, increasing the difficulty of detection and enforcement for cybersecurity and financial sectors.
A Russian-linked money laundering network purchased a controlling stake in a bank in Kyrgyzstan on Christmas Day 2024. This acquisition was part of a scheme to launder cybercrime profits and convert them into…
On Christmas Day 2024, a Russian-linked money laundering network purchased a controlling stake in a bank in Kyrgyzstan. This acquisition was part of a scheme to wash cybercrime profits and support the Russian war…