US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller for Enabling Ransomware Operations (linked to FSB Center 16 Router Exploitation via CVE-2018-0171/CVE-2008-4128) — Threadlinqs Intelligence
As of 2026-07-14, US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller for Enabling Ransomware Operations (linked to FSB Center 16 Router Exploitation via CVE-2018-0171/CVE-2008-4128) is a medium-severity threat intel threat attributed to FSB Center 16 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-1290 · Severity: MEDIUM · CVSS: 9.8 · Status: ACTIVE · Category: THREAT_INTEL
Attribution: FSB Center 16 · Russia · ESPIONAGE
OFAC sanctioned First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev on July 13, 2026 for enabling ransomware groups (Anubis,
On July 13, 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) designated First VPN Service (1VPNS), a VPN provider operational since 2014, along with its administrator Dmytro Rashevskyi (a 45-year-old Ukrainian national who used the aliases 'Maksim Sorin' and 'Roman Chabanenko' to procure infrastructure from providers that would otherwise refuse service due to abuse complaints), and Belarusian national Yevgeniy Vladimirovich Silayev, who supplied 'cryptor' malware-obfuscation services. 1VPNS marketed itself as a no-logs, law-enforcement-non-cooperative VPN and was purchased by ransomware groups to anonymize command infrastructure and manage stolen victim data; its website and supporting infrastructure were dismantled in a May 2026 joint European/North American law enforcement operation supported by the FBI's Boston Field Office. OFAC blockchain analysis (corroborated by TRM Labs) tied 1VPNS wallet infrastructure to payments from at least three named ransomware operations: Anubis ransomware (~$715 in Dec 2025/Mar 2026), Qilin ransomware (~$120 on 2026-01-11), and Sinobi Group (~$58 on 2026-02-08). OFAC designated 5 cryptocurrency addresses (BTC/ETH/LTC/TRX) tied to 1VPNS hosted at the Cryptomus exchange and 15 addresses (BTC/ETH/TRX/LTC/DOGE/DASH/ZEC/SOL) tied to Rashevskyi personally; no addresses were listed for Silayev. The designations were issued under Executive Order 13694 (as amended, standing cyber-sanctions authority) and reference Executive Order 14390 (March 2026), which directs U.S. agencies to harden systems against foreign cybercrime. Treasury states ransomware groups using these enablers' services caused billions of dollars in losses to American businesses and critical infrastructure providers. The action was coordinated internationally: the UK Foreign, Commonwealth & Development Office (FCDO) and the EU simultaneously sanctioned 24 additional individuals/entities (UK) and 9 individuals/4 entities (EU) tied to a cyberespionage/sabotage network targeting European governments and critical infrastructure (heating and power plants) since 2010. UK designations named GRU senior leadership Vyacheslav Stafeyev, Ivan Senin, and Ivan Kasyanenko for directing GRU Unit 29155's cyber/hybrid operations, which collaborated with the company IMPULS to recruit hackers from Russian universities, and separately sanctioned individuals behind Lumma Stealer, an information-stealing malware attributed to at least 2,100 UK victims in the prior six months per the National Crime Agency, with stolen credentials reportedly reused by Russian state actors for espionage.
The sanctions package explicitly links to a parallel joint cybersecurity advisory (CISA AA26-194A, 'Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting,' co-published with NSA, FBI, and 12 partner countries including Australia's ACSC/ASD) describing years-long exploitation by Russian FSB Center 16 — assessed by US/UK governments as almost certainly synonymous with the long-tracked APT cluster 'Berserk Bear' (aka Energetic Bear, Dragonfly, Dragonfly 2.0, Crouching Yeti, BROMINE, DYMALLOY, Ghost Blizzard, IRON LIBERTY, Koala, TeamSpy, Havex), formally Military Unit 71330 / the 'Center for Radio-Electronic Intelligence by Means of Communication' (TsRRSS), the FSB's core SIGINT arm. Center 16 actors conduct broad scanning to identify poorly configured, internet-exposed routers, specifically probing for SNMP agents (v1/v2c) that accept common or default community strings. Once access is obtained, actors send crafted SNMP Set-Requests (often from spoofed source IPs) with Object Identifiers (OIDs) instructing the device to copy its running configuration and transmit it via TFTP to attacker-controlled infrastructure — either a leased VPS or a compromised FTP server — enabling large-scale, low-cost reconnaissance and mapping of critical-infrastructure network topology. Since at least November 2021 the same unit has also exploit
Weaknesses (CWE)
CWE-787, CWE-20, CWE-352
Target sectors: financial services, health, government administration, critical infrastructure, energy, municipal government, telecoms
Target regions: united states of america, Europe, united kingdom, ukraine, belarus, Asia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, MEDIUM, threat intelligence, cybersecurity, CVE-2018-0171, CVE-2008-4128, T1595.001, T1583.003, T1585, T1190, T1078.001, T1059, T1505, T1027, T1027.002, T1562