Everyone knows the Russian state shelters its ransomware crews. What gets less attention is that it also watches them: formally, comprehensively, and without a court order. Once you see the surveillance, tolerance stops being a plausible story.
Read the dispatch →The seven moves that turn a victim's payment into spendable money, and the few places that money is thin enough to break.
The takedown was real. The plumbing rerouted in days. The settlement layer underneath has not moved at all.
Every major Russian ransomware brand since 2007 descends from a small circle of men who knew each other before 2014. Track the people and the chaos resolves into a family tree. Seven parts. Named, sourced, and graded.
Ninety-six named and graded. Who holds the roof, who stands under it, and what it would take to make the arrangement expensive. The first four are unsealed, with more to follow.
Enter The Protected →End Krysha is an independent threat intelligence publication, the public face of a longer research program: mapping the dependencies that keep Russia and CIS ransomware operations alive, and identifying the pressure points where targeted enforcement produces measurable degradation. Every dispatch is sourced and carries analytic confidence labels.
Groups rebrand. Dependencies don't. Ransomware doesn't run on malware; it runs on a krysha: the roof the Russian state holds over its crews while the money moves and the servers stay up. We find the roof, we document how it works, and we map where it is weakest.
Leads, data, source documents, and pushback on the analysis are all welcome, and so are reading recommendations for the shelf. Confidentiality respected.