Threadlinqs IntelligenceStart free

Threat actorRussiaTracked since 2026-07

1VPNS

As of 2026-07-14, 1VPNS is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning other. ATT&CK coverage spans 20 techniques across 7 tactics in 2 of 2 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1027.002 (Software Packing), T1036 (Masquerading).

Tracked threats
22 medium
First seen
2026-07-14
Last seen
2026-07-14
ATT&CK techniques
20across 2 of 2 threats
Related CVEs
0None referenced
Attribution
RussiaNation or origin
Nation: Russia · 2 tracked threat(s) · Categories: OTHER

Activity timeline

1VPNS appears in 2 tracked threats between and .

ATT&CK techniques observed

20 techniques observed across 2 of 2 tracked threats · Resource Development (9), Command and Control (3), Stealth (formerly Defense Evasion) (3), Impact (2), Collection (1), Defense Impairment (1)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1027.002 Software Packing — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 2 of 2 tracked threats
  • T1090.002 External Proxy — Command and Controlobserved in 2 of 2 tracked threats
  • T1090.003 Multi-hop Proxy — Command and Controlobserved in 2 of 2 tracked threats
  • T1486 Data Encrypted for Impact — Impactobserved in 2 of 2 tracked threats
  • T1567 Exfiltration Over Web Service — Exfiltrationobserved in 2 of 2 tracked threats
  • T1583.003 Virtual Private Server — Resource Developmentobserved in 2 of 2 tracked threats
  • T1585 Establish Accounts — Resource Developmentobserved in 2 of 2 tracked threats
  • T1588.001 Malware — Resource Developmentobserved in 2 of 2 tracked threats
  • T1657 Financial Theft — Impactobserved in 2 of 2 tracked threats
  • T1685 Disable or Modify Tools — Defense Impairmentobserved in 2 of 2 tracked threats
  • T1005 Data from Local System — Collectionobserved in 1 of 2 tracked threats
  • T1583.001 Domains — Resource Developmentobserved in 1 of 2 tracked threats

Tracked threats