# 1VPNS

> As of 2026-07-14, 1VPNS is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning other. ATT&CK coverage spans 20 techniques across 7 tactics in 2 of 2 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1027.002 (Software Packing), T1036 (Masquerading).

- **Nation:** Russia
- **Tracked threats:** 2
- **Categories:** OTHER
- **As of:** 2026-07-14

## ATT&CK techniques observed

20 techniques observed across 2 of 2 tracked threats. Tactics: Resource Development (9), Command and Control (3), Stealth (formerly Defense Evasion) (3), Impact (2), Collection (1), Defense Impairment (1).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1027.002](https://intel.threadlinqs.com/technique/T1027.002) Software Packing — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 2 of 2 tracked threats
- [T1090.002](https://intel.threadlinqs.com/technique/T1090.002) External Proxy — Command and Control — observed in 2 of 2 tracked threats
- [T1090.003](https://intel.threadlinqs.com/technique/T1090.003) Multi-hop Proxy — Command and Control — observed in 2 of 2 tracked threats
- [T1486](https://intel.threadlinqs.com/technique/T1486) Data Encrypted for Impact — Impact — observed in 2 of 2 tracked threats
- [T1567](https://intel.threadlinqs.com/technique/T1567) Exfiltration Over Web Service — Exfiltration — observed in 2 of 2 tracked threats
- [T1583.003](https://intel.threadlinqs.com/technique/T1583.003) Virtual Private Server — Resource Development — observed in 2 of 2 tracked threats
- [T1585](https://intel.threadlinqs.com/technique/T1585) Establish Accounts — Resource Development — observed in 2 of 2 tracked threats
- [T1588.001](https://intel.threadlinqs.com/technique/T1588.001) Malware — Resource Development — observed in 2 of 2 tracked threats
- [T1657](https://intel.threadlinqs.com/technique/T1657) Financial Theft — Impact — observed in 2 of 2 tracked threats
- [T1685](https://intel.threadlinqs.com/technique/T1685) Disable or Modify Tools — Defense Impairment — observed in 2 of 2 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 1 of 2 tracked threats
- [T1583.001](https://intel.threadlinqs.com/technique/T1583.001) Domains — Resource Development — observed in 1 of 2 tracked threats

## Tracked threats

- [US Treasury Sanctions VPN Provider 1VPNS and Crypter Seller for Enabling Ransomware Operations](https://intel.threadlinqs.com/threat/TL-2026-1295) — MEDIUM
- [OFAC Sanctions First VPN Service (1VPNS), Administrator Dmytro Rashevskyi, and Cryptor Vendor Yevgeniy Silayev for Enabling Ransomware Attacks on U.S. Critical Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-1291) — MEDIUM

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/1VPNS
