{"id":1745,"date":"2026-07-14T09:07:41","date_gmt":"2026-07-14T09:07:41","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1745"},"modified":"2026-07-14T09:07:41","modified_gmt":"2026-07-14T09:07:41","slug":"u-s-sanctions-first-vpn-service-and-malware-cryptor-seller-over-ransomware-support","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1745","title":{"rendered":"U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhseKXQcobfKfQC4K6ja7LMDD4ntr9cnmn_88cEPY7jw6wbmiy0p_0xup5NyNrvKHvN4gm2Y1gT4P9kn_FV0ogJEsN6hQ0Dal0xqZgWMNW0mHfrUtnxDkm0FjIN13xxH2_mCkBIVcQeEAK8j2w46HuvE5yv8W6MIsj5VQP37keKQBdHeF2NU-ujhcdaLwdE\/s1700-e365\/sanctions.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>The U.S. Treasury Department&#8217;s Office of Foreign Assets Control (OFAC) has <a href=\"https:\/\/home.treasury.gov\/news\/press-releases\/sb0559\" target=\"_blank\">designated<\/a> two individuals and a VPN service provider for enabling ransomware actors&#8217; and other cybercriminals&#8217; malicious activities, including ransomware attacks against Americans.<\/p>\n<p>The VPN, named <b>First VPN Service<\/b> (<b>1VPNS<\/b>), has been accused of offering its tools to ransomware groups, along with its 45-year-old Ukrainian administrator, Dmytro Rashevskyi. The department has also sanctioned Yegeniy Vladimirovich Silayev, a Belarusian national, for selling cryptors to help conceal ransomware and other malware as safe programs to avoid being detected by security tools.<\/p>\n<p>First VPN was dismantled in May 2026 as part of a joint law enforcement operation by European and North American authorities for assisting criminal actors to obscure the origins of ransomware attacks, data theft, scanning, and denial-of-service attacks. The service had been operational since 2014, advertising that it neither keeps a log of users&#8217; identities or activities nor cooperates with law enforcement to tackle illegal activity originating from servers it rents to customers. <\/p>\n<p>Per the Treasury, several ransomware groups are said to have purchased First VPN to carry out attacks on U.S. companies and institutions and hide their true origins, deploy malware, and manage exfiltrated data. Victims of ransomware attacks that involved the VPN infrastructure included U.S. businesses, financial services companies, hospitals, and municipal governments.<\/p>\n<p>Ransomware groups using services supplied by the designated parties allegedly caused billions of dollars in losses to American businesses and critical infrastructure providers, U.S. officials said.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abRashevskyi has used false identities, including &#8216;Maksim Sorin&#8217; and &#8216;Roman Chabanenko,&#8217; to buy infrastructure from companies that might otherwise refuse to do business with him because of complaints of abuse from internet service providers about illegal activity originating from 1VPNS servers,\u00bb the department said.<\/p>\n<h3>U.K. and E.U. Impose Sanctions on Russian Individuals and Entities<\/h3>\n<p>The disclosure coincides with the U.K. and E.U. sanctioning Russian cyber networks for their \u00abpersistent and increasingly reckless attempts to sow chaos and division\u202facross Europe.\u00bb The sanctions target 24\u202findividuals\u202fand entities\u202fbehind\u202fdestructive cyber and hybrid\u202foperations, including operators involved in proxy networks\u202flinked to the Russian\u202fIntelligence\u202fServices (RIS). <\/p>\n<p>This includes Russia&#8217;s Main Intelligence Directorate (GRU) senior leadership members Vyacheslav Stafeyev, Ivan Senin, and Ivan Kasyanenko for their role in directing GRU cyber and hybrid threat operations. In tandem, <a href=\"https:\/\/thehackernews.com\/2026\/05\/turla-turns-kazuar-backdoor-into.html\" target=\"_blank\">Centre 16 of the Federal Security Service (FSB) has been attributed to disruptive sabotage operations against Poland&#8217;s energy grid late last year.<\/p>\n<p>\u00abGRU Unit 29155 cyber division worked with cybercriminals, including the company IMPULS, to recruit hackers and cyber specialists from universities and academies across Russia,\u00bb the U.K. government <a href=\"https:\/\/www.gov.uk\/government\/news\/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions\" target=\"_blank\">said<\/a>.<\/p>\n<p>The sanctions are also aimed at individuals behind\u202fLumma\u202fStealer for enabling cybercriminals to collect sensitive information from compromised\u202fdevices at\u202fscale. Russia is said to have used the stealer&#8217;s stolen credentials to conduct cyber espionage operations against targets globally to support the Kremlin&#8217;s objectives. <\/p>\n<p>\u00abCybercriminals, self-proclaimed hacktivists and private companies linked to Russia, including actors operating under its instructions, direction or control, have also carried out, enabled and facilitated a wide range of malicious activities,\u00bb the E.U. <a href=\"https:\/\/www.consilium.europa.eu\/en\/press\/press-releases\/2026\/07\/13\/cyber-russia-statement-by-the-high-representative-on-behalf-of-the-european-union-denouncing-russia-s-malicious-cyber-ecosystem-targeting-the-eu-its-member-states-and-international-partners\/\" target=\"_blank\">said<\/a>.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/sygnia-cyber-response-d-2\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjHcvlLVmAqlffm6kG54_0cGVf8WfcgzqT9B0fBSizSSeIjh8tBepXnrf6BMqKiG344WgqNejcRtEFKT1PmOzQNQBhdmu2iz9Po10z0SSDlFuZ37iip2uYibJDoxTEkbUI7Bx8NJM2Io_z_nl5p4YA-ZhqFLfi0GW1axyu-lQx-iytCn9RGSJ2iqCwdyv8m\/s1600\/sy-d-2.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abWe strongly condemn Russia&#8217;s behaviour and misuse of this cyber ecosystem, targeting public services and critical infrastructure, causing disruptions and financial losses. By calling out Russia&#8217;s malicious behaviour and imposing costs on those responsible for such activities, the EU underscores its determination to uphold accountability in cyberspace.\u00bb<\/p>\n<h3>Russian State-Sponsored Targeting Goes After Routers<\/h3>\n<p>The sanctions also arrive against the <a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa26-194a\" target=\"_blank\">backdrop<\/a> of a <a href=\"https:\/\/www.ic3.gov\/CSA\/2026\/260713.pdf\" target=\"_blank\">new advisory<\/a> issued by the U.S. Federal Bureau of Investigation (FBI) about FSB Center 16 cyber actors&#8217; exploitation of poorly configured and vulnerable networking devices across the world to opportunistically hack into multiple critical infrastructure sector networks.<\/p>\n<p>\u00abThe Russian FSB Center 16 cyber actors primarily use scanning to identify poorly configured networking devices, primarily routers, for exploitation,\u00bb the agency said. \u00abThe actors scan for Internet IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default community strings for authentication.\u00bb<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj6j690zqscB_IC-qcrQEV_y43zvAsRc0YeiGxzf1PNyT0zVCt6jyo7gUQts8vhsjP1WQS6MVMh81QduBo8FJwoKw-0OXUY9XKmaRlNwiJ2n_Qm1-cpz75pIkSN5P9kLdQ7NS4-yKOfe36WSZ-23P7sc3kin-VL3Rqhj8t70tC2I2VateSo0F-n8v0I2UbU\/s1700-e365\/cisa.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj6j690zqscB_IC-qcrQEV_y43zvAsRc0YeiGxzf1PNyT0zVCt6jyo7gUQts8vhsjP1WQS6MVMh81QduBo8FJwoKw-0OXUY9XKmaRlNwiJ2n_Qm1-cpz75pIkSN5P9kLdQ7NS4-yKOfe36WSZ-23P7sc3kin-VL3Rqhj8t70tC2I2VateSo0F-n8v0I2UbU\/s1700-e365\/cisa.png\" alt=\"\" border=\"0\" data-original-height=\"576\" data-original-width=\"1024\"\/><\/a><\/div>\n<p>These scans, which are run via proxies, consist of SNMP Set-Requests from a spoofed IP address containing Object Identifiers (OIDs) that instruct the SNMP agent on poorly configured networking devices to copy its configuration to a file and transfer it to an attacker-controlled virtual private server (VPS) or compromised FTP server.<\/p>\n<p>The activity also involves abusing common vulnerabilities and exposures (CVEs) in Cisco devices, such as CVE-2018-0171 and <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2008-4128\" target=\"_blank\">CVE-2008-4128<\/a>, as a way to discover and exploit poorly configured networking appliances. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/07\/13\/cisa-adds-one-known-exploited-vulnerability-catalog\" target=\"_blank\">added<\/a> CVE-2008-4128 to its Known Exploited Vulnerabilities (<a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\">KEV<\/a>) catalog, requiring federal agencies to apply the fixes by July 16, 2026.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The U.S. Treasury Department&#8217;s Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling ransomware actors&#8217; and other cybercriminals&#8217; malicious activities, including ransomware&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1746,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[2514,42,93,744,2515,572,405,96,668],"class_list":["post-1745","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-cryptor","tag-malware","tag-ransomware","tag-sanctions","tag-seller","tag-service","tag-support","tag-u-s","tag-vpn"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1745","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1745"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1745\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1746"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1745"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1745"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1745"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}