Breaking
Cyber CrimeDeveloping Story

U.S. Sanctions Infrastructure Providers

Treasury sanctions VPN and cryptor suppliers to disrupt the underlying network that supports global ransomware operations.

··1 month ago·2 min read
server room, digital security, network nodes
Photo by Picsum Photos on Unsplash

The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) has moved to penalize the specialized service providers that anchor the ransomware ecosystem. By targeting entities that offer technical anonymity and evasion tools, authorities are attempting to degrade the operational capabilities of cybercriminal groups attacking U.S. critical infrastructure.

Targeting Anonymity Services

The government formally designated First VPN Service (1VPNS) and its administrator, Dmytro Rashevskyi, for facilitating ransomware campaigns. Since 2014, the provider operated with the explicit promise of offering no logs and ignoring law enforcement inquiries. Rashevskyi reportedly utilized aliases, including "Maksim Sorin" and "Roman Chabanenko," to secure server infrastructure from providers that would have otherwise blacklisted him due to abuse reports.

Coordinated Infrastructure Dismantling

The sanctions follow a multi-national effort to seize the provider's assets. In May, French and Dutch authorities, supported by the FBI's Boston Field Office, took down 1VPNS's website and infrastructure. The investigation, which originated in December 2021, allowed law enforcement to infiltrate the network and capture its user database before the final takedown.

  • 33 servers were seized across 27 countries.
  • 1VPNS has been active since 2014.
  • The investigation into the VPN service officially began in December 2021.

Disrupting Malware Evasion Tools

Beyond network anonymity, the Treasury Department targeted the developers of specialized malware-hiding software. This includes the designation of Belarusian national Yegeniy Vladimirovich Silayev, who provides cryptors designed to bypass security detection mechanisms. These tools represent a critical component of the ransomware supply chain, allowing malicious code to persist undetected within target networks.

These actors supplied ransomware groups with tools to hide their identities, disguise malicious software, and evade detection — enabling attacks that have caused billions of dollars in losses to U.S. critical infrastructure providers.

— Thomas Pigott, State Department spokesperson

Consequences for the Ecosystem

These designations serve as a reminder that the ransomware threat is not limited to the operators launching the attacks, but also includes the shadow service industry. By freezing property within U.S. jurisdiction and prohibiting transactions, the Treasury aims to make it operationally and financially difficult for these providers to maintain their infrastructure. As authorities increase their focus on the jointly sanctioned dozens of Russian individuals and entities, the ability for cybercriminal groups to acquire reliable, anonymous, and evasive services may become increasingly restricted.

#ransomware#sanctions#vpn#cybersecurity#treasury

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories