DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:13:27ZSOURCES: 14CRITICAL: 30
⚠ ACTIVE ALERTS
@FalconFeedsio CRITICAL — 🚨 Ransomware Alert: The Gentlemen RaaS group continues active DLS postings. Now at 478… /// @DarkWebInformer CRITICAL — 🚨 ServiceNow discloses June 5 security update tied to anomalous activity — KB3067321.… /// @MsftSecIntel CRITICAL — MSTIC analysis of The Gentlemen ransomware (tracked internally): self-propagating… /// @GossiTheDog CRITICAL — ServiceNow KB3067321 situation is worse than the vendor comms suggest. Advisory was gated… /// @AlvieriD CRITICAL — The '340M OnlyFans' listing on the leak forum is a compiled corpus — seller confirmed to…
30Critical Threats
15Active CVEs
1IOCs Tracked
14New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // OPERATION-RIPTIDE-LE-ACTIONFIRST SEEN: JUN 2026

OPERATION RIPTIDE (FBI / Multi-National Law Enforcement Action)

ALSO KNOWN AS: N/A — law enforcement counter-operation targeting: ransomware infrastructure, First VPN Service operators, AudiA6 crypto mixer, Dark2Web forum administrators
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Targets: Russia-nexus criminal infrastructure
ATTRIBUTION:ORGANIZED CRIME
STATUS:ACTIVE
FIRST OBSERVED:JUN 2026
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL57/100
RESOURCES57/100
PERSISTENCE60/100
STEALTH52/100
IMPACT66/100

On June 9, 2026, the FBI's Cyber Division announced Operation Riptide — a coordinated, 60-day international law enforcement campaign targeting the full criminal ecosystem supporting cyber-enabled crime, including infrastructure, tools, communications platforms, and financial networks. The first major action under Riptide was the international takedown of 'First VPN Service' (active 2014–2026, 27 countries), used by at least 25 ransomware groups including Avaddon; concurrently, on June 10, Europol dismantled the AudiA6 Russian cryptocurrency mixing service — linked to over €336M ($389M) in laundered ransomware proceeds since 2021 — and its associated Dark2Web cybercrime forum. Additional actions by FBI, France's DNPJ, Dutch National Police, and partners across Ukraine, UK, Switzerland, and Luxembourg have included arrests, indictments, cryptocurrency seizures, and server confiscations; further actions are expected through August 2026.

Criminal infrastructure — bulletproof VPN services, crypto-laundering, and dark web forum administration enabling ransomware operations

Criminal enablement services: T1090.003 (Multi-hop Proxy — bulletproof VPN anonymization), T1583 (Acquire Infrastructure — bulletproof hosting), T1531 (Account Access Removal — mixer obfuscation), T1020 (Automated Exfiltration — AudiA6 crypto mixing pipeline), T1567 (Exfiltration to Dark2Web forum for data sales)

RANSOMWARE-INFRASTRUCTURE
CRYPTO-LAUNDERING
DARK-WEB-FORUMS
BULLETPROOF-VPN

First VPN Service — 27-country node network (SEIZED June 9, 2026); AudiA6 crypto mixer — €336M+ laundered since 2021 (SEIZED June 10, 2026); Dark2Web cybercrime forum (TAKEN DOWN June 10, 2026); multiple dark web forum servers; cryptocurrency wallets (partially seized)

FILE DATE: JUN 2026
First VPN Service Takedown
International coalition led by France's DNPJ and Dutch National Police, with FBI support, seized 'First VPN Service' — used by 25+ ransomware groups — as the first public action under Operation Riptide announced June 9, 2026.
FILE DATE: JUN 2026
AudiA6 Crypto Mixer & Dark2Web Forum Dismantlement
On June 10, 2026, Europol and partners dismantled AudiA6 — a ██████████████████████ that processed €336M+ in illicit ransomware proceeds and was linked to the Ledger app fraud — along with its associated Dark2Web cybercrime forum.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn