US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller for Enabling Ransomware Operations (linked to FSB Center 16 Router Exploitation via CVE-2018-0171/CVE-2008-4128)

US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller (TL-2026-1290), also tracked as 1VPNS Sanctions, is a medium-severity tracked intrusion set scored CVSS 9.8, first published 2026-07-14. It is attributed to FSB Center 16 (Russia) with high confidence, affects Cisco IOS / IOS XE Software (Smart Install feature), references 2 CVEs (CVE-2018-0171, CVE-2008-4128), maps to 22 MITRE ATT&CK techniques (T1020, T1027, T1027.002), and is covered by 9 detection rules and 21 indicators of compromise.

Key facts for TL-2026-1290

Threat ID
TL-2026-1290
Also known as
1VPNS Sanctions, Operation Router Hygiene, AA26-194A
Severity
MEDIUM
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-07-14
Last reviewed
2026-07-14
Attribution
FSB Center 16
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
financial services, health, government administration, critical infrastructure, energy, municipal government, telecoms
Target regions
united states of america, Europe, united kingdom, ukraine, belarus, Asia
Detection rules
9
Indicators of compromise
21

Malware and tooling in US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller

Malware and tooling: Anubis Ransomware, Lumma Stealer - S1213, Qilin ransomware, Sinobi ransomware

OFAC sanctioned First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev on July 13, 2026 for enabling ransomware groups (Anubis, Qilin, Sinobi) to obscure attack origins and evade detection, coordinated with UK/EU sanctions on 24 individuals/entities including GRU Unit 29155 leadership and Lumma Stealer operators. The action follows a joint CISA/NSA/FBI/international advisory (AA26-194A) on Russian FSB Center 16 (Berserk Bear/Energetic Bear, Military Unit 71330) exploiting default SNMP credentials on poorly configured routers, including active exploitation of CVE-2018-0171 (Cisco Smart Install RCE) and the decade-old end-of-life CVE-2008-4128 (Cisco IOS CSRF).

How US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller works

On July 13, 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) designated First VPN Service (1VPNS), a VPN provider operational since 2014, along with its administrator Dmytro Rashevskyi (a 45-year-old Ukrainian national who used the aliases 'Maksim Sorin' and 'Roman Chabanenko' to procure infrastructure from providers that would otherwise refuse service due to abuse complaints), and Belarusian national Yevgeniy Vladimirovich Silayev, who supplied 'cryptor' malware-obfuscation services. 1VPNS marketed itself as a no-logs, law-enforcement-non-cooperative VPN and was purchased by ransomware groups to anonymize command infrastructure and manage stolen victim data; its website and supporting infrastructure were dismantled in a May 2026 joint European/North American law enforcement operation supported by the FBI's Boston Field Office. OFAC blockchain analysis (corroborated by TRM Labs) tied 1VPNS wallet infrastructure to payments from at least three named ransomware operations: Anubis ransomware (~$715 in Dec 2025/Mar 2026), Qilin ransomware (~$120 on 2026-01-11), and Sinobi Group (~$58 on 2026-02-08). OFAC designated 5 cryptocurrency addresses (BTC/ETH/LTC/TRX) tied to 1VPNS hosted at the Cryptomus exchange and 15 addresses (BTC/ETH/TRX/LTC/DOGE/DASH/ZEC/SOL) tied to Rashevskyi personally; no addresses were listed for Silayev. The designations were issued under Executive Order 13694 (as amended, standing cyber-sanctions authority) and reference Executive Order 14390 (March 2026), which directs U.S. agencies to harden systems against foreign cybercrime. Treasury states ransomware groups using these enablers' services caused billions of dollars in losses to American businesses and critical infrastructure providers. The action was coordinated internationally: the UK Foreign, Commonwealth & Development Office (FCDO) and the EU simultaneously sanctioned 24 additional individuals/entities (UK) and 9 individuals/4 entities (EU) tied to a cyberespionage/sabotage network targeting European governments and critical infrastructure (heating and power plants) since 2010. UK designations named GRU senior leadership Vyacheslav Stafeyev, Ivan Senin, and Ivan Kasyanenko for directing GRU Unit 29155's cyber/hybrid operations, which collaborated with the company IMPULS to recruit hackers from Russian universities, and separately sanctioned individuals behind Lumma Stealer, an information-stealing malware attributed to at least 2,100 UK victims in the prior six months per the National Crime Agency, with stolen credentials reportedly reused by Russian state actors for espionage.

The sanctions package explicitly links to a parallel joint cybersecurity advisory (CISA AA26-194A, 'Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting,' co-published with NSA, FBI, and 12 partner countries including Australia's ACSC/ASD) describing years-long exploitation by Russian FSB Center 16 — assessed by US/UK governments as almost certainly synonymous with the long-tracked APT cluster 'Berserk Bear' (aka Energetic Bear, Dragonfly, Dragonfly 2.0, Crouching Yeti, BROMINE, DYMALLOY, Ghost Blizzard, IRON LIBERTY, Koala, TeamSpy, Havex), formally Military Unit 71330 / the 'Center for Radio-Electronic Intelligence by Means of Communication' (TsRRSS), the FSB's core SIGINT arm. Center 16 actors conduct broad scanning to identify poorly configured, internet-exposed routers, specifically probing for SNMP agents (v1/v2c) that accept common or default community strings. Once access is obtained, actors send crafted SNMP Set-Requests (often from spoofed source IPs) with Object Identifiers (OIDs) instructing the device to copy its running configuration and transmit it via TFTP to attacker-controlled infrastructure — either a leased VPS or a compromised FTP server — enabling large-scale, low-cost reconnaissance and mapping of critical-infrastructure network topology. Since at least November 2021 the same unit has also exploited CVE-2018-0171, a critical (CVSSv3.1 9.8) unauthenticated remote code execution / denial-of-service flaw in the Cisco IOS/IOS XE Smart Install feature (crafted message to TCP port 4786, out-of-bounds write per CWE-787, improper input validation per CWE-20), patched by Cisco in March 2018 and added to the CISA KEV catalog November 3, 2021. The advisory also flags continued opportunistic exploitation of CVE-2008-4128, a set of CSRF vulnerabilities (CWE-352) in the HTTP administration component of Cisco IOS 12.4 on 871 Integrated Services Routers — a vulnerability affecting only end-of-life hardware, illustrating the actor's reliance on unpatched legacy edge devices as durable footholds. CISA's primary mitigation guidance: disable Cisco Smart Install where not actively required, migrate from SNMP v1/v2c community strings to SNMPv3 with strong authentication and encryption, patch or replace end-of-life devices, and apply standard router-hardening hygiene (disable unused services, restrict management-plane access, monitor for unauthorized configuration exfiltration).

MITRE ATT&CK techniques used in TL-2026-1290

Exfiltration

T1020 Automated Exfiltration; T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol

Defense Evasion

T1027 Obfuscated Files or Information; T1027.002 Software Packing

Discovery

T1040 Network Sniffing; T1046 Network Service Discovery

Execution

T1059 Command and Scripting Interpreter

Initial Access

T1078.001 Default Accounts; T1190 Exploit Public-Facing Application

Command and Control

T1090.002 External Proxy; T1090.003 Multi-hop Proxy

Credential Access

T1110.001 Password Guessing; T1555 Credentials from Password Stores

Collection

T1119 Automated Collection; T1602.002 Network Device Configuration Dump

Impact

T1486 Data Encrypted for Impact; T1498 Network Denial of Service

Persistence

T1505 Server Software Component

Resource Development

T1583.003 Virtual Private Server; T1585 Establish Accounts

Reconnaissance

T1595.001 Scanning IP Blocks

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller

  • Cisco — IOS / IOS XE Software (Smart Install feature)
    Vulnerable versions: Multiple IOS/IOS XE releases with Smart Install enabled, e.g. 15.2(5)e
    Fixed in: Cisco fixed releases per Cisco Security Advisory, March 2018
  • Cisco — IOS 12.4 (871 Integrated Services Router)
    Vulnerable versions: IOS 12.4 on 871 ISR (end-of-life)
    Fixed in: None — end-of-life, no vendor patch; replacement recommended
  • Generic — Network devices with SNMP v1/v2c enabled and default/common community strings
    Vulnerable versions: Any SNMPv1/v2c-enabled router/switch using default or guessable community strings
    Fixed in: Migrate to SNMPv3 with authentication and encryption

Remediation for US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller

Patches

  • Apply Cisco fixed software for CVE-2018-0171 (Smart Install, patched March 2018)
  • CVE-2008-4128 affects only end-of-life Cisco IOS 12.4 / 871 ISR hardware — no vendor patch available; replace hardware

Immediate actions

  • Disable Cisco Smart Install feature on all IOS/IOS XE devices where not actively required
  • Migrate SNMP from v1/v2c community strings to SNMPv3 with strong authentication and encryption
  • Block or restrict inbound TCP/4786 (Smart Install) at network perimeter and internally
  • Identify and replace/isolate end-of-life Cisco devices (e.g. 871 ISR) affected by CVE-2008-4128
  • Audit router/network-device configurations for unauthorized changes or unexpected TFTP/FTP configuration transfers
  • Block payment/infrastructure relationships with sanctioned entities: 1VPNS, Dmytro Rashevskyi, Yevgeniy Silayev per OFAC SDN designations

Workarounds

  • Disable Smart Install client feature (no-vstack config) if upgrade is not immediately feasible
  • Restrict SNMP access via ACLs to trusted management hosts only
  • Disable HTTP administration interface on legacy/EOL Cisco IOS devices

Longer-term hardening

  • Deploy network device configuration-integrity monitoring and baseline drift detection
  • Implement network segmentation isolating management interfaces from general traffic
  • Establish vulnerability/patch management program prioritizing internet-facing network infrastructure and CISA KEV entries
  • Monitor for VPN/anonymization-service usage patterns consistent with known ransomware-affiliated providers
  • Integrate OFAC SDN list screening into payment and vendor risk processes

CVEs associated with US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller

CVE-2018-0171, CVE-2008-4128

Weaknesses (CWE) in US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller

CWE-787, CWE-20, CWE-352

Timeline of US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller

  • CVE-2008-4128 (Cisco IOS 12.4 / 871 ISR CSRF) published
  • First VPN Service (1VPNS) begins operating, marketed as no-log/law-enforcement-non-cooperative VPN
  • CVE-2018-0171 (Cisco IOS/IOS XE Smart Install RCE/DoS, CVSS 9.8) published and patched by Cisco
  • FSB Center 16 (Berserk Bear) begins exploiting CVE-2018-0171 against Smart Install-enabled Cisco devices
  • CVE-2018-0171 added to CISA Known Exploited Vulnerabilities (KEV) catalog
  • CISA/FBI/NSA publish AA22-110A on Russian state-sponsored and criminal cyber threats to critical infrastructure
  • FBI publicly warns of FSB-linked hackers exploiting unpatched Cisco devices for espionage
  • Anubis ransomware group sends first tracked payment (~part of $715 total) to 1VPNS-linked wallet infrastructure
  • Qilin ransomware sends ~$120 to 1VPNS-linked cryptocurrency address
  • Sinobi ransomware group sends ~$58 to 1VPNS-linked cryptocurrency address
  • Anubis ransomware group sends second tracked payment to 1VPNS-linked wallet infrastructure
  • Executive Order 14390 signed, directing US agencies to harden systems against foreign cybercrime
  • Joint European/North American law enforcement operation (with FBI Boston Field Office support) dismantles 1VPNS website and supporting infrastructure
  • CISA, NSA, FBI, and 12 partner nations publish joint advisory AA26-194A, 'Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting,' detailing FSB Center 16 SNMP-based router exploitation and CVE-2018-0171/CVE-2008-4128 usage
  • OFAC designates 1VPNS, Dmytro Rashevskyi, and Yevgeniy Silayev under Executive Order 13694 (as amended); UK FCDO sanctions 24 individuals/entities including GRU Unit 29155 leadership and Lumma Stealer operators; EU sanctions 9 individuals/4 entities
  • Coverage of the sanctions action and its links to FSB Center 16 router exploitation published by The Hacker News and other outlets

Sources cited for US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller

Threats related to US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller

Detection coverage for TL-2026-1290

As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1290 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats