Operation Destabilise — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
November 20, 2025
Last Seen
November 21, 2025

Operation Destabilise is described in recent reporting as a Russia-linked ransomware-for-profit threat campaign.

Overview

Operation Destabilise is described in recent reporting as a Russia-linked ransomware-for-profit threat campaign. Reports indicate the group purchased a private bank to launder cybercrime proceeds, including ransomware profits, illustrating a shift toward using legitimate financial institutions to conceal illicit gains. The campaign's significance lies in its fusion of cybercrime with financial infrastructure, increasing the difficulty of detection and enforcement for cybersecurity and financial sectors.

Related Threat Clusters

Recent Intelligence Reports

  • Russia-linked crooks bought a bank for Christmas to launder cyber loot — Theregister · November 21, 2025
  • Russia — Theregister · November 21, 2025
  • Russian money launderers bought a bank to disguise ransomware profit — Computerweekly · November 20, 2025

CVSS v3.1 Breakdown