Ransomware is extortion malware: an attacker encrypts or steals an organisation's data and demands payment, usually in cryptocurrency, to addresses the attacker controls. Those addresses and the paths leading away from them are attributable, so a wallet that received value from a ransom payment carries the connection. Some ransomware actors are also sanctioned, which turns what looks like a risk category into a legal obligation.
A ransomware payment is a transfer from a victim to an attacker-controlled address, and both ends of it are permanently visible. Investigators and intelligence providers attribute those addresses to the actor or the strain, and the attribution stays attached as value moves onward. That is why a wallet several transfers downstream of a ransom payment can still show the category.
The sanctions dimension is what makes this category different from ordinary fraud. Where an actor or an address has been designated, OFAC's virtual currency topic page is explicit that digital currency addresses can appear as identifiers on the SDN List and that US persons must block property of designated persons. Paying, or handling the proceeds, is then not merely unwise.
Because the category reaches people with no connection to the attack. Ransom proceeds get cashed out through the same retail channels everyone else uses: P2P deals, small exchangers, instant swap services. A trader selling USDT to a stranger can end up holding the receipt for that cash-out without ever knowing the strain's name.
For a desk, the decision is straightforward once the finding is visible and expensive once it is not. Screen before you accept, not after your bank asks. The Telegram bot does this free, three checks a day, and returns the verdict in seconds.
The result names ransomware as its own category in plain words, and separates a connection on the address itself from one in the funding path behind it. Next to the category you see the verdict — CLEAN, LOW, MEDIUM, HIGH or CRITICAL — with a recommendation of Proceed, Caution, Review or Reject, and the decision drivers spelled out. Where a sanctions connection is also present, it is named as sanctions, because the obligation is different.
Compliance teams work the same finding in the workspace, filter the case queue by the category and export a signed report for the file. Plans are on the pricing page.
Because value that once passed through a ransom payment reached you, usually through an intermediate counterparty such as a P2P seller or a small exchanger. The connection travels with the funds, not with the person.
It depends on your jurisdiction, and it becomes a sanctions question if the actor is designated. OFAC's guidance is clear that designated persons' property must be blocked by US persons — which is why the sanctions status of the actor is the first thing to establish.
No. Additional transfers add distance, not innocence, and the path remains reconstructable. What extra hops do change is how hard it is for you to document your own side.
Also available in: · · ·
Yes — paste it into the Telegram bot, three checks a day at no cost, and the category is named in the result if it is present.
Send any wallet to the Telegram bot and get a verdict in seconds. Three checks a day, free, no signup. Desks that screen every deposit run it on plans from $199/mo.