A Ukrainian-Russian dual citizen has pleaded guilty to operating a money laundering network built on roughly 15,000 money mule accounts, moving millions of dollars in criminal proceeds for cybercrime operations worldwide. According to the reporting, the operation functioned as a professional cash-out service: stolen funds from fraud, business email compromise (BEC), and related schemes were funneled through this mule infrastructure to obscure the money trail and get proceeds into the hands of the threat actors.
For defenders, this story matters less for the individual defendant and more for what it reveals about the economics of the attacks landing in your environment right now. Every BEC wire diversion, every payroll redirect, every romance-scam victim recruited as an unwitting mule, and every ransomware affiliate that needs to convert stolen funds into usable currency depends on infrastructure exactly like this. Fifteen thousand accounts is industrial scale — and it means the fraud hitting your finance team is rarely a lone actor. It is the front end of a laundering pipeline with professional operators behind it.
If you can disrupt the cash-out — the inbox forwarding rules, the vendor bank account changes, the anomalous wires, the payroll direct-deposit edits — you break the business model even when you can't reach the operators.
Technical Analysis: How a 15,000-Mule Operation Actually Works
The money mule supply chain
Money mule networks are the financial logistics layer of cybercrime. Based on the structure described in this case and consistent with how these networks operate globally, the architecture typically looks like this:
- Recruitment layer — Mules are recruited through work-from-home "payment processor" job ads, romance scams, social media, and direct outreach. Some are unwitting victims who believe they're doing legitimate accounts-receivable work; others are fully complicit and paid a percentage (typically 5–15%) of funds moved.
- Collection layer — Stolen funds land in mule accounts: BEC wire diversions, payroll redirection, ACH fraud, scam victim payments, and account-takeover drains.
- Movement layer — Funds are rapidly layered: split across multiple mule accounts, converted to crypto, moved through gift cards, or wired internationally. Speed is the priority — every hour in a mule account is an hour the bank can freeze it.
- Consolidation layer — Operators like the defendant in this case aggregate and deliver cleaned funds to the threat actors, minus their commission.
Where this touches your environment
Organizations are hit at the collection layer, and the observable attack techniques are well-mapped in MITRE ATT&CK:
- T1657 – Financial Theft: The end goal — fraudulent transfers, diverted payroll, manipulated vendor payments.
- T1114.003 – Email Collection: Email Forwarding Rule: Attackers who compromise a finance or executive mailbox create inbox rules to auto-forward threads to external addresses and hide replies (moving them to RSS Subscriptions, Archive, or Conversation History and marking them read) so the victim never sees the bank's callback or the vendor's confusion.
- T1078 – Valid Accounts: Account takeover of finance staff, frequently via phishing or legacy authentication (IMAP/POP3) that bypasses MFA expectations.
- T1656 – Impersonation: Spoofed or look-alike vendor and executive domains requesting payment changes.
The fraud patterns that feed mule networks
The specific behaviors we see feeding laundering operations like this one:
- Vendor bank account change fraud: A compromised or spoofed vendor email requests updated remittance details. The new account is a mule drop. By the time the real vendor invoices, the money is layered and gone.
- Payroll direct-deposit diversion: An "employee" emails HR asking to update direct deposit, often with a plausible PDF form. The new account belongs to a mule.
- Executive impersonation wires: Urgent, confidential wire requests routed to accounts controlled by the mule network.
- Romance/scam proceeds: Less visible to enterprise defenders, but part of the same network — which is why law enforcement actions against operators like this one degrade the entire ecosystem.
Exploitation status
This is not a CVE-driven threat — there is no patch for a laundering network. The relevant status: the techniques (BEC, inbox rule abuse, payroll diversion) are confirmed, actively exploited at massive scale, and this guilty plea confirms the existence of professionalized laundering infrastructure serving those techniques globally. FinCEN and the FBI's IC3 have repeatedly flagged money mule networks and email compromise fraud as top-loss categories, with BEC losses in the billions annually. The defensive lever available to you is detection and process control at the collection layer.
Detection & Response
The detections below target the observable choke points: inbox rules used to hide fraud, legacy-authentication account takeover of finance mailboxes, and unauthorized remote access tooling that fraud crews use to operate inside victim environments. These are high-signal behaviors — not speculative IOCs.
SIGMA Rules
---
title: External Email Forwarding Rule Created on Mailbox
tid: 3f8a1c42-7b2d-4e91-a6c5-9d0e1f2a3b4c
status: experimental
description: Detects creation or modification of inbox rules that forward, redirect, or attach mail to external addresses — a hallmark of BEC operations feeding money mule networks.
references:
- https://attack.mitre.org/techniques/T1114/003/
- https://www.bleepingcomputer.com/news/security/ukrainian-russian-dual-citizen-admits-to-laundering-millions-for-cybercriminals/
author: Security Arsenal
date: 2026/02/09
tags:
- attack.collection
- attack.t1114.003
logsource:
product: m365
service: exchange
detection:
selection_operation:
Operation:
- 'New-InboxRule'
- 'Set-InboxRule'
selection_forward:
Parameters|contains:
- 'ForwardTo'
- 'RedirectTo'
- 'ForwardAsAttachmentTo'
condition: selection_operation and selection_forward
falsepositives:
- Legitimate user-configured forwarding to personal mail — recommend policy prohibition and alerting on all hits for finance, HR, and executive mailboxes
level: high
---
title: BEC-Style Inbox Rule Hiding Messages
tid: 6c2d9e17-4a8f-4b53-9d21-7e0f3a5b8c1d
status: experimental
description: Detects inbox rules that delete, mark as read, or relocate messages to obscure folders (RSS Subscriptions, Archive, Conversation History) — used by BEC actors to suppress bank callbacks and vendor replies during wire fraud.
references:
- https://attack.mitre.org/techniques/T1114/003/
- https://attack.mitre.org/techniques/T1657/
author: Security Arsenal
date: 2026/02/09
tags:
- attack.collection
- attack.t1114.003
- attack.t1657
logsource:
product: m365
service: exchange
detection:
selection_operation:
Operation:
- 'New-InboxRule'
- 'Set-InboxRule'
selection_hide:
Parameters|contains:
- 'DeleteMessage'
- 'MarkAsRead'
- 'RSS Subscriptions'
- 'Conversation History'
condition: selection_operation and selection_hide
falsepositives:
- Users auto-filing newsletters — tune by scoping alerting to finance, AP/AR, payroll, and executive accounts
level: high
---
title: Legacy Authentication Sign-In to Cloud Mailbox
tid: 9b4e7a03-2d6c-4f18-8a35-1c9d0e2f4a6b
status: experimental
description: Detects successful sign-ins using legacy protocols (IMAP, POP3, SMTP Auth, Exchange ActiveSync) that bypass conditional access and MFA — a common account takeover path before BEC wire fraud.
references:
- https://attack.mitre.org/techniques/T1078/
author: Security Arsenal
date: 2026/02/09
tags:
- attack.initial_access
- attack.t1078
logsource:
product: azure
service: signinlogs
detection:
selection:
ClientAppUsed:
- 'IMAP4'
- 'POP3'
- 'Authenticated SMTP'
- 'Exchange ActiveSync'
- 'Exchange Online PowerShell'
- 'Other clients'
selection_success:
ResultType: 0
condition: selection and selection_success
falsepositives:
- Legacy line-of-business applications and older mobile clients — investigate and migrate; legacy auth should be blocked tenant-wide
level: medium
KQL — Microsoft Sentinel / Defender Hunting
// Hunt 1: Inbox rules forwarding mail externally — prioritize finance/HR/executive mailboxes
OfficeActivity
| where TimeGenerated > ago(14d)
| where OfficeWorkload == "Exchange"
| where Operation in ("New-InboxRule", "Set-InboxRule")
| extend Params = tostring(parse_json(Parameters))
| where Params has_any ("ForwardTo", "RedirectTo", "ForwardAsAttachmentTo")
| extend RuleParams = tostring(parse_json(Params)[0].Value)
| project TimeGenerated, UserId, ClientIP, Operation, RuleParams
| order by TimeGenerated desc;
// Hunt 2: Legacy auth sign-ins followed by mailbox rule changes within 24h (ATO-to-BEC chain)
let LegacySignins = SigninLogs
| where TimeGenerated > ago(30d)
| where ClientAppUsed in ("IMAP4", "POP3", "Authenticated SMTP", "Exchange ActiveSync", "Other clients")
| where ResultType == 0
| summarize FirstLegacySignin = min(TimeGenerated), Locations = make_set(Location), IPs = make_set(IPAddress) by UserPrincipalName;
let RuleChanges = OfficeActivity
| where TimeGenerated > ago(30d)
| where Operation in ("New-InboxRule", "Set-InboxRule")
| extend UserPrincipalName = tolower(tostring(UserId))
| summarize FirstRuleChange = min(TimeGenerated), Rules = make_set(Operation) by UserPrincipalName;
LegacySignins
| extend UserPrincipalName = tolower(UserPrincipalName)
| join kind=inner RuleChanges on UserPrincipalName
| where FirstRuleChange between (FirstLegacySignin .. FirstLegacySignin + 24h)
| project UserPrincipalName, FirstLegacySignin, Locations, IPs, FirstRuleChange, Rules
| order by FirstLegacySignin desc;
// Hunt 3: Rapid payroll/vendor keyword chatter in mailboxes that just had rule changes
let SuspiciousRuleUsers = OfficeActivity
| where TimeGenerated > ago(14d)
| where Operation in ("New-InboxRule", "Set-InboxRule")
| summarize by UserId;
EmailEvents
| where TimeGenerated > ago(14d)
| where RecipientEmailAddress in~ (SuspiciousRuleUsers.UserId)
| where Subject has_any ("wire", "payment", "remittance", "bank account", "direct deposit", "ACH", "invoice", "routing number")
| project TimeGenerated, SenderFromAddress, RecipientEmailAddress, Subject
| order by TimeGenerated desc
Velociraptor VQL — Hunting Unauthorized Remote Access Tooling
Fraud crews operating mule networks and BEC account takeovers frequently deploy remote access tools (AnyDesk, TeamViewer, ScreenConnect) to operate victim machines directly — including instructing recruited "work-from-home payment processors" to install them. Hunt for unauthorized RMM execution:
-- Hunt for unauthorized remote access tools commonly abused in fraud and mule operations
LET rmm_names = '(?i)(anydesk|teamviewer|screenconnect|connectwise|ammyy|ultraviewer|rustdesk|splashtop|logmein|gotohttp|parsec)'
SELECT Pid, Ppid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE Exe =~ rmm_names
OR CommandLine =~ rmm_names
-- Identify RMM binaries on disk outside approved installation paths
SELECT FullPath, Size, Mtime, Ctime
FROM glob(globs='C:/Users/*/Downloads/**/*')
WHERE FullPath =~ '(?i)(anydesk|teamviewer|screenconnect|ammyy|ultraviewer|rustdesk|splashtop)'
ORDER BY Mtime DESC
Baseline first: export your approved RMM inventory and whitelist those paths/publishers. Any hit outside that baseline on a finance, HR, or payroll workstation is an immediate investigation.
Remediation Script — Audit and Remove External Forwarding (Exchange Online)
# Requires: ExchangeOnlineManagement module, connected via Connect-ExchangeOnline
# Audits every mailbox for external forwarding rules and SMTP forwarding, then removes them.
# Run the AUDIT section first; review output before running the REMOVE section.
# ============ AUDIT ============
$report = @()
$mailboxes = Get-Mailbox -ResultSize Unlimited -RecipientTypeDetails UserMailbox
foreach ($mbx in $mailboxes) {
# SMTP forwarding set at mailbox level
if ($mbx.ForwardingSmtpAddress -or $mbx.ForwardingAddress) {
$report += [PSCustomObject]@{
Mailbox = $mbx.UserPrincipalName
Type = 'MailboxSMTPForwarding'
Target = "$($mbx.ForwardingAddress)$($mbx.ForwardingSmtpAddress)"
RuleName = 'N/A'
}
}
# Inbox rules forwarding externally
$rules = Get-InboxRule -Mailbox $mbx.UserPrincipalName -ErrorAction SilentlyContinue
foreach ($rule in $rules) {
$targets = @($rule.ForwardTo, $rule.RedirectTo, $rule.ForwardAsAttachmentTo) | Where-Object { $_ }
foreach ($t in $targets) {
if ($t -notmatch "@yourdomain\.com") { # <-- replace with your verified internal domain(s)
$report += [PSCustomObject]@{
Mailbox = $mbx.UserPrincipalName
Type = 'InboxRuleExternalForward'
Target = $t
RuleName = $rule.Name
}
}
}
}
}
$report | Export-Csv -Path ".\ExternalForwardingAudit_$(Get-Date -Format yyyyMMdd).csv" -NoTypeInformation
$report | Format-Table -AutoSize
# ============ REMOVE (only after review) ============
foreach ($hit in ($report | Where-Object { $_.Type -eq 'InboxRuleExternalForward' })) {
Remove-InboxRule -Mailbox $hit.Mailbox -Identity $hit.RuleName -Confirm:$false
Write-Output "Removed external forwarding rule '$($hit.RuleName)' from $($hit.Mailbox)"
}
foreach ($hit in ($report | Where-Object { $_.Type -eq 'MailboxSMTPForwarding' })) {
Set-Mailbox -Identity $hit.Mailbox -ForwardingAddress $null -ForwardingSmtpAddress $null
Write-Output "Cleared SMTP forwarding on $($hit.Mailbox)"
}
# ============ PREVENT: disable auto-forwarding tenant-wide ============
Set-RemoteDomain Default -AutoForwardEnabled $false
Get-RemoteDomain | Select-Object DomainName, AutoForwardEnabled
Remediation: Breaking the Cash-Out Pipeline
There is no patch for a money laundering network — but there is a control framework that makes your organization a hostile environment for the fraud that feeds it. Prioritize:
Payment process controls (highest ROI):
- Out-of-band verification for all bank detail changes: Any request to change vendor remittance or employee direct-deposit information must be confirmed by phone using a number from your existing records — never the number in the requesting email. No exceptions for executives.
- Dual authorization on wires and ACH above a defined threshold, with a cooling-off period (e.g., 48–72 hours) on first-time payees and changed accounts.
- Payroll change freeze: Hold direct-deposit changes until after the next pay cycle unless verified in person or via a known contact channel.
Email and identity hardening:
- Block external auto-forwarding tenant-wide (script above) and alert on any inbox rule with external forwarding, redirect, or message-hiding behavior — treat hits on finance, HR, payroll, AP/AR, and executive mailboxes as incidents, not noise.
- Block legacy authentication protocols (IMAP, POP3, authenticated SMTP) via Conditional Access. These are the workhorse of mailbox takeover preceding BEC.
- Enforce phishing-resistant MFA (FIDO2/passkeys) for finance and executive roles at minimum.
- Enforce DMARC at p=reject on your domains and configure inbound display-name/spoof alerts for executive and vendor impersonation.
Detection and response:
- Deploy the Sigma, KQL, and VQL content above. The legacy-signin-to-inbox-rule correlation (KQL Hunt 2) is the single highest-fidelity BEC chain indicator in this post.
- Maintain an RMM allowlist and investigate any unauthorized remote access tool on finance-side endpoints.
People and reporting:
- Train HR and recruiting staff to recognize that "payment processor," "financial agent," and "work-from-home transfer assistant" roles are mule recruitment lures — employees moonlighting as mules create direct legal and fraud exposure.
- If you suspect mule-linked fraud: contact your bank's fraud department immediately to attempt recall (speed is everything — funds are layered within hours), file with the FBI at ic3.gov, and review FinCEN's advisories on email compromise fraud and money mule red flags at fincen.gov. Financial institutions have SAR filing obligations on suspected mule activity.
The operator of this 15,000-mule network is headed to sentencing, but the demand that built his business hasn't gone anywhere. Every BEC crew, ransomware affiliate, and fraud ring still needs cash-out capacity — and they'll rebuild. The organizations that make the collection layer expensive — verified payment changes, monitored mailboxes, blocked legacy auth — are the ones the fraud pipeline routes around.
Related Resources
Security Arsenal Healthcare Cybersecurity AlertMonitor Platform Book a SOC Assessment healthcare Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.