U.S. Sanctions Infrastructure Providers
Treasury sanctions VPN and cryptor suppliers to disrupt the underlying network that supports global ransomware operations.
The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) has moved to penalize the specialized service providers that anchor the ransomware ecosystem. By targeting entities that offer technical anonymity and evasion tools, authorities are attempting to degrade the operational capabilities of cybercriminal groups attacking U.S. critical infrastructure.
Targeting Anonymity Services
The government formally designated First VPN Service (1VPNS) and its administrator, Dmytro Rashevskyi, for facilitating ransomware campaigns. Since 2014, the provider operated with the explicit promise of offering no logs and ignoring law enforcement inquiries. Rashevskyi reportedly utilized aliases, including "Maksim Sorin" and "Roman Chabanenko," to secure server infrastructure from providers that would have otherwise blacklisted him due to abuse reports.
Coordinated Infrastructure Dismantling
The sanctions follow a multi-national effort to seize the provider's assets. In May, French and Dutch authorities, supported by the FBI's Boston Field Office, took down 1VPNS's website and infrastructure. The investigation, which originated in December 2021, allowed law enforcement to infiltrate the network and capture its user database before the final takedown.
- 33 servers were seized across 27 countries.
- 1VPNS has been active since 2014.
- The investigation into the VPN service officially began in December 2021.
Disrupting Malware Evasion Tools
Beyond network anonymity, the Treasury Department targeted the developers of specialized malware-hiding software. This includes the designation of Belarusian national Yegeniy Vladimirovich Silayev, who provides cryptors designed to bypass security detection mechanisms. These tools represent a critical component of the ransomware supply chain, allowing malicious code to persist undetected within target networks.
These actors supplied ransomware groups with tools to hide their identities, disguise malicious software, and evade detection — enabling attacks that have caused billions of dollars in losses to U.S. critical infrastructure providers.
— Thomas Pigott, State Department spokesperson
Consequences for the Ecosystem
These designations serve as a reminder that the ransomware threat is not limited to the operators launching the attacks, but also includes the shadow service industry. By freezing property within U.S. jurisdiction and prohibiting transactions, the Treasury aims to make it operationally and financially difficult for these providers to maintain their infrastructure. As authorities increase their focus on the jointly sanctioned dozens of Russian individuals and entities, the ability for cybercriminal groups to acquire reliable, anonymous, and evasive services may become increasingly restricted.
Sources
- BleepingComputer Original source
- designated First VPN Service (1VPNS) Also reporting
- took down 1VPNS's website and infrastructure Also reporting
- jointly sanctioned dozens of Russian individuals and entities Also reporting
Continue Reading
AI Coding Assistant Now a Ransomware Weapon
Aurora ransomware actors use Cursor Agent AI to automate post-exploitation tasks, per Gambit Security research.
TeamPCP arrests expose supply chain risk
Alleged masterminds of TeamPCP, tied to Shai-Hulud worm, arrested in Perth with FBI help.
CRPx0's big claims and where they lead
CRPx0's victim count rose from under 10 to 48 organizations since June, but experts urge caution over unverified claims.