US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller for Enabling Ransomware Operations (linked to FSB Center 16 Router Exploitation via CVE-2018-0171/CVE-2008-4128)
US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller (TL-2026-1290), also tracked as 1VPNS Sanctions, is a medium-severity tracked intrusion set scored CVSS 9.8, first published 2026-07-14. It is attributed to FSB Center 16 (Russia) with high confidence, affects Cisco IOS / IOS XE Software (Smart Install feature), references 2 CVEs (CVE-2018-0171, CVE-2008-4128), maps to 22 MITRE ATT&CK techniques (T1020, T1027, T1027.002), and is covered by 9 detection rules and 21 indicators of compromise.
Key facts for TL-2026-1290
- Threat ID
- TL-2026-1290
- Also known as
- 1VPNS Sanctions, Operation Router Hygiene, AA26-194A
- Severity
- MEDIUM
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-07-14
- Last reviewed
- 2026-07-14
- Attribution
- FSB Center 16
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- financial services, health, government administration, critical infrastructure, energy, municipal government, telecoms
- Target regions
- united states of america, Europe, united kingdom, ukraine, belarus, Asia
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller
Malware and tooling: Anubis Ransomware, Lumma Stealer - S1213, Qilin ransomware, Sinobi ransomware
OFAC sanctioned First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev on July 13, 2026 for enabling ransomware groups (Anubis, Qilin, Sinobi) to obscure attack origins and evade detection, coordinated with UK/EU sanctions on 24 individuals/entities including GRU Unit 29155 leadership and Lumma Stealer operators. The action follows a joint CISA/NSA/FBI/international advisory (AA26-194A) on Russian FSB Center 16 (Berserk Bear/Energetic Bear, Military Unit 71330) exploiting default SNMP credentials on poorly configured routers, including active exploitation of CVE-2018-0171 (Cisco Smart Install RCE) and the decade-old end-of-life CVE-2008-4128 (Cisco IOS CSRF).
How US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller works
On July 13, 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) designated First VPN Service (1VPNS), a VPN provider operational since 2014, along with its administrator Dmytro Rashevskyi (a 45-year-old Ukrainian national who used the aliases 'Maksim Sorin' and 'Roman Chabanenko' to procure infrastructure from providers that would otherwise refuse service due to abuse complaints), and Belarusian national Yevgeniy Vladimirovich Silayev, who supplied 'cryptor' malware-obfuscation services. 1VPNS marketed itself as a no-logs, law-enforcement-non-cooperative VPN and was purchased by ransomware groups to anonymize command infrastructure and manage stolen victim data; its website and supporting infrastructure were dismantled in a May 2026 joint European/North American law enforcement operation supported by the FBI's Boston Field Office. OFAC blockchain analysis (corroborated by TRM Labs) tied 1VPNS wallet infrastructure to payments from at least three named ransomware operations: Anubis ransomware (~$715 in Dec 2025/Mar 2026), Qilin ransomware (~$120 on 2026-01-11), and Sinobi Group (~$58 on 2026-02-08). OFAC designated 5 cryptocurrency addresses (BTC/ETH/LTC/TRX) tied to 1VPNS hosted at the Cryptomus exchange and 15 addresses (BTC/ETH/TRX/LTC/DOGE/DASH/ZEC/SOL) tied to Rashevskyi personally; no addresses were listed for Silayev. The designations were issued under Executive Order 13694 (as amended, standing cyber-sanctions authority) and reference Executive Order 14390 (March 2026), which directs U.S. agencies to harden systems against foreign cybercrime. Treasury states ransomware groups using these enablers' services caused billions of dollars in losses to American businesses and critical infrastructure providers. The action was coordinated internationally: the UK Foreign, Commonwealth & Development Office (FCDO) and the EU simultaneously sanctioned 24 additional individuals/entities (UK) and 9 individuals/4 entities (EU) tied to a cyberespionage/sabotage network targeting European governments and critical infrastructure (heating and power plants) since 2010. UK designations named GRU senior leadership Vyacheslav Stafeyev, Ivan Senin, and Ivan Kasyanenko for directing GRU Unit 29155's cyber/hybrid operations, which collaborated with the company IMPULS to recruit hackers from Russian universities, and separately sanctioned individuals behind Lumma Stealer, an information-stealing malware attributed to at least 2,100 UK victims in the prior six months per the National Crime Agency, with stolen credentials reportedly reused by Russian state actors for espionage.
The sanctions package explicitly links to a parallel joint cybersecurity advisory (CISA AA26-194A, 'Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting,' co-published with NSA, FBI, and 12 partner countries including Australia's ACSC/ASD) describing years-long exploitation by Russian FSB Center 16 — assessed by US/UK governments as almost certainly synonymous with the long-tracked APT cluster 'Berserk Bear' (aka Energetic Bear, Dragonfly, Dragonfly 2.0, Crouching Yeti, BROMINE, DYMALLOY, Ghost Blizzard, IRON LIBERTY, Koala, TeamSpy, Havex), formally Military Unit 71330 / the 'Center for Radio-Electronic Intelligence by Means of Communication' (TsRRSS), the FSB's core SIGINT arm. Center 16 actors conduct broad scanning to identify poorly configured, internet-exposed routers, specifically probing for SNMP agents (v1/v2c) that accept common or default community strings. Once access is obtained, actors send crafted SNMP Set-Requests (often from spoofed source IPs) with Object Identifiers (OIDs) instructing the device to copy its running configuration and transmit it via TFTP to attacker-controlled infrastructure — either a leased VPS or a compromised FTP server — enabling large-scale, low-cost reconnaissance and mapping of critical-infrastructure network topology. Since at least November 2021 the same unit has also exploited CVE-2018-0171, a critical (CVSSv3.1 9.8) unauthenticated remote code execution / denial-of-service flaw in the Cisco IOS/IOS XE Smart Install feature (crafted message to TCP port 4786, out-of-bounds write per CWE-787, improper input validation per CWE-20), patched by Cisco in March 2018 and added to the CISA KEV catalog November 3, 2021. The advisory also flags continued opportunistic exploitation of CVE-2008-4128, a set of CSRF vulnerabilities (CWE-352) in the HTTP administration component of Cisco IOS 12.4 on 871 Integrated Services Routers — a vulnerability affecting only end-of-life hardware, illustrating the actor's reliance on unpatched legacy edge devices as durable footholds. CISA's primary mitigation guidance: disable Cisco Smart Install where not actively required, migrate from SNMP v1/v2c community strings to SNMPv3 with strong authentication and encryption, patch or replace end-of-life devices, and apply standard router-hardening hygiene (disable unused services, restrict management-plane access, monitor for unauthorized configuration exfiltration).
MITRE ATT&CK techniques used in TL-2026-1290
Exfiltration
T1020 Automated Exfiltration; T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
Defense Evasion
T1027 Obfuscated Files or Information; T1027.002 Software Packing
Discovery
T1040 Network Sniffing; T1046 Network Service Discovery
Execution
T1059 Command and Scripting Interpreter
Initial Access
T1078.001 Default Accounts; T1190 Exploit Public-Facing Application
Command and Control
T1090.002 External Proxy; T1090.003 Multi-hop Proxy
Credential Access
T1110.001 Password Guessing; T1555 Credentials from Password Stores
Collection
T1119 Automated Collection; T1602.002 Network Device Configuration Dump
Impact
T1486 Data Encrypted for Impact; T1498 Network Denial of Service
Persistence
T1505 Server Software Component
Resource Development
T1583.003 Virtual Private Server; T1585 Establish Accounts
Reconnaissance
defense-impairment
Affected products and versions in US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller
- Cisco — IOS / IOS XE Software (Smart Install feature)
Vulnerable versions: Multiple IOS/IOS XE releases with Smart Install enabled, e.g. 15.2(5)e
Fixed in: Cisco fixed releases per Cisco Security Advisory, March 2018 - Cisco — IOS 12.4 (871 Integrated Services Router)
Vulnerable versions: IOS 12.4 on 871 ISR (end-of-life)
Fixed in: None — end-of-life, no vendor patch; replacement recommended - Generic — Network devices with SNMP v1/v2c enabled and default/common community strings
Vulnerable versions: Any SNMPv1/v2c-enabled router/switch using default or guessable community strings
Fixed in: Migrate to SNMPv3 with authentication and encryption
Remediation for US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller
Patches
- Apply Cisco fixed software for CVE-2018-0171 (Smart Install, patched March 2018)
- CVE-2008-4128 affects only end-of-life Cisco IOS 12.4 / 871 ISR hardware — no vendor patch available; replace hardware
Immediate actions
- Disable Cisco Smart Install feature on all IOS/IOS XE devices where not actively required
- Migrate SNMP from v1/v2c community strings to SNMPv3 with strong authentication and encryption
- Block or restrict inbound TCP/4786 (Smart Install) at network perimeter and internally
- Identify and replace/isolate end-of-life Cisco devices (e.g. 871 ISR) affected by CVE-2008-4128
- Audit router/network-device configurations for unauthorized changes or unexpected TFTP/FTP configuration transfers
- Block payment/infrastructure relationships with sanctioned entities: 1VPNS, Dmytro Rashevskyi, Yevgeniy Silayev per OFAC SDN designations
Workarounds
- Disable Smart Install client feature (no-vstack config) if upgrade is not immediately feasible
- Restrict SNMP access via ACLs to trusted management hosts only
- Disable HTTP administration interface on legacy/EOL Cisco IOS devices
Longer-term hardening
- Deploy network device configuration-integrity monitoring and baseline drift detection
- Implement network segmentation isolating management interfaces from general traffic
- Establish vulnerability/patch management program prioritizing internet-facing network infrastructure and CISA KEV entries
- Monitor for VPN/anonymization-service usage patterns consistent with known ransomware-affiliated providers
- Integrate OFAC SDN list screening into payment and vendor risk processes
CVEs associated with US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller
Weaknesses (CWE) in US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller
CWE-787, CWE-20, CWE-352
Timeline of US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller
- CVE-2008-4128 (Cisco IOS 12.4 / 871 ISR CSRF) published
- First VPN Service (1VPNS) begins operating, marketed as no-log/law-enforcement-non-cooperative VPN
- CVE-2018-0171 (Cisco IOS/IOS XE Smart Install RCE/DoS, CVSS 9.8) published and patched by Cisco
- FSB Center 16 (Berserk Bear) begins exploiting CVE-2018-0171 against Smart Install-enabled Cisco devices
- CVE-2018-0171 added to CISA Known Exploited Vulnerabilities (KEV) catalog
- CISA/FBI/NSA publish AA22-110A on Russian state-sponsored and criminal cyber threats to critical infrastructure
- FBI publicly warns of FSB-linked hackers exploiting unpatched Cisco devices for espionage
- Anubis ransomware group sends first tracked payment (~part of $715 total) to 1VPNS-linked wallet infrastructure
- Qilin ransomware sends ~$120 to 1VPNS-linked cryptocurrency address
- Sinobi ransomware group sends ~$58 to 1VPNS-linked cryptocurrency address
- Anubis ransomware group sends second tracked payment to 1VPNS-linked wallet infrastructure
- Executive Order 14390 signed, directing US agencies to harden systems against foreign cybercrime
- Joint European/North American law enforcement operation (with FBI Boston Field Office support) dismantles 1VPNS website and supporting infrastructure
- CISA, NSA, FBI, and 12 partner nations publish joint advisory AA26-194A, 'Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting,' detailing FSB Center 16 SNMP-based router exploitation and CVE-2018-0171/CVE-2008-4128 usage
- OFAC designates 1VPNS, Dmytro Rashevskyi, and Yevgeniy Silayev under Executive Order 13694 (as amended); UK FCDO sanctions 24 individuals/entities including GRU Unit 29155 leadership and Lumma Stealer operators; EU sanctions 9 individuals/4 entities
- Coverage of the sanctions action and its links to FSB Center 16 router exploitation published by The Hacker News and other outlets
Sources cited for US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller
- U.S. Sanctions First VPN Service and Malware Cryptor Seller
- Treasury Sanctions Malware and Infrastructure Providers Supporting Ransomware Attacks Against Americans
- OFAC Sanctions FirstVPN and Ransomware Enablers Behind Attacks on Americans
- Sanctioning Ransomware Enablers in Coordinated International Action
- VPN service favored by ransomware groups is sanctioned by US
- Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting (AA26-194A)
- Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting
- Russian FSB Center 16 exploits decade-old Cisco flaw in cyber espionage campaign to target critical infrastructure
- FSB Center 16 Exploited Default Router Passwords to Map Critical Infrastructure for Years
- NSA Urges Organizations to Disable Cisco Smart Install as Russian Hackers Target Routers
- FBI Warns FSB-Linked Hackers Exploiting Unpatched Cisco Devices for Cyber Espionage
- Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure (AA22-110A)
- UK and EU strike Russian cyber networks with new sanctions
- EU and Britain Target Russian Intelligence Officers Over a Major Cyberspying Campaign
- NVD - CVE-2018-0171
Threats related to US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller
- FSB Center 16 (Static Tundra) Exploits SNMP Config Exfiltration and Cisco Smart Install RCE (CVE-2018-0171) Against Routers
- CVE-2008-4128 Cisco IOS CSRF Vulnerability Added to CISA KEV — Exploited by Russian FSB Center 16 (Static Tundra / Berserk Bear) in Ongoing Router-Hygiene Espionage Campaign
- FSB Center 16 (Static Tundra / Berserk Bear) Exploits Default/Weak SNMP and Unpatched Cisco Smart Install (CVE-2018-0171) to Compromise Networking Devices — AA26-194A
- FSB Centre 16 (Berserk Bear/Static Tundra) Targets Critical Infrastructure via Weak SNMP Credentials and Cisco Smart Install Exploitation (CVE-2018-0171) — UK/EU Attribute December 2025 Poland Energy Grid Attack
- Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint NSA/FBI/13-Nation Advisory
- NSA/FBI Joint Advisory: Disable Cisco Smart Install to Block Russian FSB "Static Tundra" Exploitation of CVE-2018-0171
Detection coverage for TL-2026-1290
As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1290 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.