Cybercrime

US Sanctions Iranian Administrator of Nemesis Darknet Marketplace

Iranian national Behrouz Parsarad sanctioned for running Nemesis, a marketplace used for narcotics trafficking and cybercrime. 

Sanctions

The US Treasury Department on Tuesday announced sanctions against an Iranian national accused of running an online darknet marketplace used for trading drugs and cybercrime services.

The marketplace, named Nemesis Market, was shut down in March 2024 as a result of a law enforcement operation conducted by Germany, the US and Lithuania. 

German authorities announced after the takedown of Nemesis server infrastructure that more than 150,000 user accounts and over 1,100 seller accounts were registered on the site, which was accessible on the Tor network.

Nemesis provided a platform for drug trafficking and the trade of fraudulently obtained goods and data, as well as cybercrime services such as DDoS attacks, phishing, and ransomware. 

The Treasury Department announced sanctions against Iran-based Behrouz Parsarad, who is believed to be “the sole administrator of Nemesis”.

The sanctions are mainly over Nemesis’ use for narcotics trafficking, with authorities saying that the marketplace facilitated the sale of nearly $30 million worth of drugs between 2021 and 2024.

Advertisement. Scroll to continue reading.

Parsarad, who allegedly held full control over the website and its cryptocurrency wallets, pocketed millions of dollars through the fees he charged on every transaction. He also helped Nemesis users launder funds.

“Since the takedown of Nemesis, Parsarad has discussed setting up a new darknet marketplace to take the place of Nemesis with vendors that were once active on the marketplace,” the Treasury Department said. 

Related: Leader of North Korean Hackers Sanctioned by EU

Related: European Union Sanctions Russian Nationals for Hacking Estonia

Related: Russian Cybercrime Network Targeted for Sanctions Across US, UK and Australia

Related: Treasury Levels Sanctions Tied to a Massive Hack of Telecom Companies and Breach of Its Own Network

Related Content

Malware & Threats

Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands.

Cybercrime

Hundreds of C&C servers were disrupted in an operation involving law enforcement and several cybersecurity companies.

Cybercrime

Nathan Austad has been ordered to pay roughly $1.8 million in forfeiture and restitution, and the sentence also includes 3 years of supervised release. 

Malware & Threats

Mistic is used by Woodgnat, an initial access broker working with Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta.

Cybercrime

26-year-old Abdellah Belmili faces up to 30 years in prison for allegedly operating the marketplaces Market0Day and Spoxy.

Cybercrime

Using a custom sniffer, the threat actor has captured over 110 million credentials since at least February 2026.

Cybercrime

Oleksii Oleksiyovych Lytvynenko admitted to working on the development of a loader for the Conti gang.

Cybercrime

Researchers say the OnyxC2 malware targets more than 200 applications and extensions while evading detection through encrypted payloads, DLL sideloading, and in-memory execution techniques.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version