Fourteen members of QQAAZZ, an international cybercrime group known for money laundering, were indicted yesterday in the US, Portugal, Spain and the UK for providing money laundering services that originated from the illegal activities of notorious malware companies, including Trickbot, Dridex and GozNym.
According to the charges, QQAAZZ has laundered (or at least attempted to launder) tens of millions stolen from cybercrime victims. US authorities said the group has been active since 2016 and operates by advertising its services on Russian-language hacking forums.

The US Department of Justice (DoJ) noted that QQAAZZ members operated a large network of bank accounts and money mules that allowed gangs to move money from compromised accounts to new, “clean” destinations.
QQAAZZ members were organized in a corporate-style hierarchy. Leaders handled customer communications, mid-level managers recruited money mules, and the money mules in turn opened bank accounts and withdrew money from ATMswhen needed.

Additionally, U.S. officials said the group operated a vast network of bank accounts around the world using fake identities and shell companies. These accounts served as destination points for money obtained from hacks, malware infections, and other cybercrime operations. The money would then travel through QQAAZZ accounts and be converted into cryptocurrencies.
QQAAZZ then returned a portion of the money “laundered” to its cybercrime clients, receiving fees of up to 50% of the total balance of the stolen money received. In addition to the 14 suspects charged, five other suspects were also charged in October 2019 with money laundering.

Sixteen countries participated in an international operation against QQAAZZ, which Europol dubbed “Operation 2BaGoldMule.” As part of this operation, Europol said participating countries conducted over 40 investigations in the United Kingdom, Spain, Italy, Latvia and Bulgaria, and made 20 arrests.
