To Disrupt Russia’s Shadow War, Follow the Money

To Disrupt Russia’s Shadow War, Follow the Money
Editor's note: The "Short of War" Podcast discussing this article is AI-generated.

Just before eight o’clock on a September evening in 2021, two men opened a conversation on Telegram about how to kidnap a Russian fugitive. One, Orlin Roussev, was a Bulgarian information technology specialist working out of a guesthouse in the faded English seaside town of Great Yarmouth. The other was Jan Marsalek, the fugitive former chief operating officer of the collapsed German payments company Wirecard, by then living in Moscow and freelancing for Russia’s intelligence services. Together they ran a cell of Bulgarian nationals who surveilled targets and carried out reconnaissance across Europe, including at U.S. Army Garrison Stuttgart, until the Metropolitan Police’s Counter Terrorism Command rolled up the network in February 2023 and its members were convicted in 2025.

The tradecraft and curiosities of the spy ring made the headlines: Roussev’s warehouse of espionage equipment with over 2,000 items, the spy ring’s reference to themselves as ‘Minions,’ Marsalek’s cavalier messages about kidnapping and potential assassination of exiled Russian journalists. The more instructive and overlooked detail about Russia’s covert operations, however, was the financial plumbing. Marsalek, a payments professional by trade, moved money to the cell through a mix of bank transfers and cryptocurrency wallets. According to Britain’s National Crime Agency, in the summer of 2023, individuals linked to Russian intelligence tried to pay this very cell through a Russian-speaking money-laundering network codenamed Smart, the same infrastructure that washed the proceeds of drug trafficking and ransomware for ordinary criminal clients. A spy ring, a disgraced financier, and a criminal laundromat were all connected and operating through the same illicit financial channel.

Illicit finance serves as the operating infrastructure for Russian irregular warfare below the threshold of open conflict. Analysts typically read Russia’s campaign of sabotage, subversion, influence, and procurement through its operators, treating the financial layer as background logistics that is a matter for financial investigators and compliance teams. In an operating model built on volume, dispersion, and deniability, the payment channel is frequently the binding constraint, and therefore the most consequential variable. Illicit finance is not the backdrop to Russian irregular warfare; it is the key adaptation to Western countermeasures since 2022.

Illicit Finance as a Threat Vector

Western governments mostly read Russian dirty money as corruption, capital flight, or sanctions evasion. Those framings are not wrong, but they are incomplete and fail to identify illicit finance as a threat vector exploited by Russian intelligence services.

Illicit finance and intelligence work have long been connected across many states, but the post-2022 shift matters for Russia specifically. Three Western countermeasures changed the operating environment at once: the mass expulsion of more than 750 suspected Russian intelligence officers from European capitals between February 2022 and late 2024, the severing of major Russian banks and Russia as a whole from Western finance, and tightened export controls. However, these did not end Russian covert activity but instead changed how it is resourced and who carries it out. Moscow leaned further into non-state actors, criminal infrastructure, informal settlement systems, and cryptocurrency rails. According to a CSIS database, Russian-attributed attacks in Europe quadrupled between 2022 and 2023 and tripled again the following year. IISS and GLOBSEC/ICCT datasets confirm the trajectory.

The GRU, Russia’s foreign military intelligence agency, leads this campaign inside the Russian state. A recent Dossier Center investigation identifies the long-standing Unit 29155 and a Department of Special Tasks (SSD) stood up in 2023 under Colonel-General Andrey Averyanov as its principal architects. The Dossier Center’s analysis is striking. The Kremlin has pushed military intelligence outside its traditional competencies, asking it to run a campaign of “terrorism and hooliganism in unfriendly countries” that strains its conventional remit. The institutional consequence matters because the GRU cannot resource arson, parcel-bomb plots, and disposable proxy recruitment through normal military channels, so it reaches for criminal and crypto infrastructure outside the regulated financial system. The efficiency and pseudonymity of stablecoins coupled with social media has become a force-multiplier for state actors like Russia, enabling greater recruitment and reach even while facing unprecedented sanctions.

Illicit finance offers Russia four opportunities in the state-crime nexus:

·         It converts constrained value into usable value.

·         It provides deniability, because a payment can pass through multiple unregulated crypto wallets rather than regulated financial institutions.

·         It offers reach, because criminal networks already move value across borders and can benefit from being at the other end, in terms of settlement, of state activity.

·         It provides scale, because small payments can sustain many small operations at once.

The result is not a single Kremlin hand directing every transaction, but rather an ecosystem in which state and criminal actors converge around shared incentives through the vector of finance.

Minors in the Gig Economy: Russia’s Adaptation after 2022

Breaking Russia’s illicit finance activity into its constituent parts reveal how far the threat extends.

The first category is operational finance, for example, paying for sabotage and reconnaissance. Most of the post-2022 European caseload sits with the GRU, whose Telegram and TikTok recruitment was traced in detail by the Dossier Center. A recent Financial Times investigation documented how Russian and Iranian handlers recruit teenagers through gaming platforms, Telegram, and Snapchat, assign them discrete tasks such as filming a logistics hub or torching a warehouse, and promise to pay them in cryptocurrency on completion of the mission. In fact, Ukrainian officials say a fifth of those arrested for collaborating with Russia in 2025 were minors. For example, a British citizen, Dylan Earl, was recruited over Telegram to firebomb a London warehouse storing aid bound for Ukraine. RUSI has described an emerging Russian sabotage “gig economy” in which handlers hire freelancers and petty criminals through encrypted apps for one-off tasks. The model lowers the skill threshold, lowers the cost of failure, and complicates attribution, because the recruit often does not know who is paying. Cryptocurrencies like stablecoins offer a bridge from the ruble to desirable currencies like the dollar, slotting neatly into a digitally enabled workflow. Crypto makes sabotage scalable with no need for physical cash drop-offs or regulated bank transfers.

The second category is influence finance, of which Moldova is the clearest case. Ahead of its 2025 parliamentary election, authorities warned of an unprecedented Russian interference campaign involving disinformation, paid protests, cyberattacks, and illegal financing that included an estimated 100 million euros in cryptocurrency. A separate Elliptic analysis, based on leaked documents from companies linked to sanctioned oligarch Ilan Shor, found that wallets tied to Shor’s A7 group and related businesses had received about 8 billion dollars in stablecoin transactions since early 2024. The funds reportedly supported infrastructure for pro-Russian influence operations in Moldova, including apps used to manage and pay political activists. A7 also relied on A7A5, a ruble-backed stablecoin connected to Shor’s network and Russia’s sanctioned Promsvyazbank. While the Kremlin’s influence campaign in Moldova has not borne fruit in the last years, this does not preclude future successes in countries like Serbia, Romania, Georgia and Armenia, as Russia continues to probe vulnerabilities through illicitly financed operations.

The third category is intelligence finance, and it returns us to the spy ring. Operation Destabilise, disclosed by the National Crime Agency in December 2024 alongside U.S. Treasury sanctions, exposed two Russian-linked laundering networks, Smart and TGR, that moved cash and cryptocurrency in the billions of dollars for drug traffickers, ransomware crews, sanctioned elites and, the agency assessed, Russian intelligence. The operation produced eighty-four arrests and the seizure of more than twenty million euros. The laundering ring and the spy ring were not adjacent problems; they were one problem. The same channel that laundered ransomware and drug proceeds also settled payments to intelligence assets, meaning the boundary between organized crime and state tradecraft had already dissolved.

The fourth category is procurement finance, where Russia is moving from improvisation to institutionalization. A war economy starved of Western microelectronics depends on intermediaries, third-country routes, and alternative payment mechanisms. A7A5 sits at the center of this too: blockchain analysts at Elliptic estimated it was moving roughly a billion dollars a day by mid-2025. When the Russia-linked exchange Garantex was seized in March 2025, its operators activated a near-identical successor, Grinex, in Kyrgyzstan, with value migrating into A7A5. The infrastructure is being built to outlast any single takedown, and non-traditional finance provides ample opportunities to continue financing Russia’s own irregular warfare initiatives.

Cutting Heads Off a Hydra

A March 2026 Henry Jackson Society report, built on a new open-source Global Cryptocurrency Laundering Database, catalogues 164 major crypto-laundering cases over two decades through which an estimated 350 billion dollars has moved, with the number of cases growing at about sixteen and a half per cent a year. Russia is the second most common point of origin: half of the high-risk exchanges and brokers in the database operated from Russia and four of the five major ransomware crews were Russian. Stablecoins now account for the majority of illicit crypto flows. However, seventy-nine per cent of the catalogued cases produced no convictions, and only about a quarter of the funds were ever recovered. Notably, the report’s seventeen-year-old author Alexander Browder was placed on Russia’s sanctions list in June 2026, an indication of how closely the Kremlin tracks this space.

Policymakers, government officials, and practitioners need to understand that Russian illicit financing for irregular warfare behaves like a hydra: when one mixer or exchange is cut off, value reroutes to a successor. A7A5 keeps operating despite U.S., UK and EU designations, partly because jurisdictions such as Kyrgyzstan have proved uncooperative and partly because sanctions have lagged behind the threat. Because stablecoins sit at least one step removed from the regulated financial system, they give Russian statecraft something traditional sanctions struggle to reach, namely, a payment rail that can be re-domiciled, re-branded, and re-issued faster than designations can be drafted.

Implications of Illicit Finance for Countering Russia

Western strategy still treats Russian illicit finance as sanctions evasion and compliance risk. This approach misses the strategic reality. Crypto rails, laundering networks, brokers, and shell companies are now part of Moscow’s irregular warfare infrastructure, not a peripheral compliance concern. For practitioners, the lesson is that finance belongs in the operating environment, not in a separate silo. A robust strategy for the United States and its partners has four pillars.

First, treat illicit finance as intelligence terrain. Wallets, brokers, shell companies, and trade anomalies reveal operational patterns that human and signals intelligence can miss, while blockchain analytics can unearth key data points. Counter-intelligence should fuse financial intelligence with order-of-battle and logistics analysis, mapping how financial activity connects to physical nodes such as rail hubs, ports, and front companies that can be observed, exploited, or in conflict targeted.

Second, build financial counterintelligence systems. The anti-money-laundering regime was designed to flag laundering and terrorist financing, not espionage. It should be repurposed to surface transaction patterns that suggest state operations and paired with faster cross-border sharing between financial-intelligence units. The constraint is rarely missing data. Instead, the problem is that the data is fragmented across agencies, which is exactly what the design of illicit finance exploits.

Third, go after the chokepoints and the enablers. Ruble-backed stablecoins, successor exchanges, third-country intermediaries, and the lawyers, brokers, and company-formation agents who structure opaque financial rails are the load-bearing elements. Sanctions should escalate dynamically against protocols that repeatedly facilitate hostile activity, and Western pressure should concentrate on the jurisdictions that host the off-ramps.

Finally, compete on speed. In compliant jurisdictions, cryptocurrency can be frozen if it is flagged fast enough. Public-private partnerships with blockchain-analytics firms, fast-freeze mechanisms, and whistleblower-reward schemes, which the United States and South Korea use but the United Kingdom and European Union largely do not, shift the advantage from the launderer to the investigator. As one recent argument for striking back at Russia’s shadow war puts it, the point is to impose costs, not merely to absorb them.

Follow the Money to Stay Ahead

Diplomatic expulsions and financial sanctions were designed to punish and restrict Russian statecraft. They have instead forced its adaptation. The character of the threat has changed and Russia’s intelligence services have been pushed outside of their institutional comfort zone. They now conduct operations at scale through disposable proxies and  criminal and crypto infrastructure the West does not yet treat as part of the operating environment. Russia’s hidden front is fought not only by spies, saboteurs and propagandists. It is also sustained by brokers, couriers, exchanges, shell companies, and crypto wallets. To stay one step ahead of Russia’s covert campaign, Western states and their national security establishments need to follow the money beyond the traditional financial landscape.


Peter Meedom is an assistant professor at the Royal Danish Defence College, where he researches Russian military affairs, statecraft and warfare. He is the author of Mørke penge (Dark Money, 2026), a non-fiction book on how corporate and legal secrecy enable kleptocracy, sanctions evasion and covert statecraft. His background includes work on illicit finance in the private sector, and he serves as a reserve officer in the Danish Army.

The views expressed are those of the authors and do not reflect the official position of the Irregular Warfare Initiative, Princeton University’s Empirical Studies of Conflict Project, the Modern War Institute at West Point, the Department of the Army, the Department of War, or the United States Government.

The main image is of Russian Rubles from Vardan Papikyan on Unsplash.

If you value reading the Irregular Warfare Initiative, please consider supporting our work. And for the best gear, check out the IWI store for mugs, coasters, apparel, and other items.