Threat reportOtherTL-2026-1291

OFAC Sanctions First VPN Service (1VPNS), Administrator Dmytro Rashevskyi, and Cryptor Vendor Yevgeniy Silayev for Enabling Ransomware Attacks on U.S. Critical Infrastructure

mediumACTIVE

OFAC Sanctions First VPN Service (1VPNS), Administrator (TL-2026-1291), also tracked as First VPN Service sanctions, is a medium-severity other threat, first published 2026-07-14. It is attributed to 1VPNS (Russia) with high confidence, maps to 18 MITRE ATT&CK techniques (T1005, T1027, T1027.002), and is covered by 9 detection rules and 16 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
18MITRE ATT&CK
Actors
11VPNS
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-1291

Threat ID
TL-2026-1291
Also known as
First VPN Service sanctions, 1VPNS OFAC designation
Severity
MEDIUM
Status
ACTIVE
Category
OTHER
First published
Last reviewed
Attribution
1VPNS
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
health, financial services, government administration, municipal government, critical infrastructure, cybercrime infrastructure supply chain
Target regions
united states of america, united kingdom
Detection rules
9
Indicators of compromise
16

Malware and tooling in OFAC Sanctions First VPN Service (1VPNS), Administrator

Malware and tooling: Anubis Ransomware, Qilin Ransomware, Sinobi Ransomware, Cryptor (Silayev malware-obfuscation service)

How OFAC Sanctions First VPN Service (1VPNS), Administrator works

On July 13, 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC), coordinated with the UK Foreign, Commonwealth & Development Office, sanctioned First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and Belarusian cryptor vendor Yevgeniy Vladimirovich Silayev for supplying anonymizing VPN infrastructure and malware-obfuscation services to ransomware actors that attacked U.S. hospitals, financial firms, and municipalities since 2014. A May 2026 international law-enforcement operation, supported by the FBI Boston Field Office and European authorities, had already dismantled 1VPNS's website and server infrastructure.

The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) designated three parties on July 13, 2026, under Executive Order 13694 (as amended) and Executive Order 14390 (March 2026), for materially supporting ransomware operations against American businesses, hospitals, financial-services firms, and municipal governments. The action targeted the ransomware-enabling supply chain rather than a ransomware operator directly, reflecting an evolving OFAC strategy of sanctioning bulletproof-hosting and anonymization infrastructure providers that ransomware affiliates depend on for operational security.

First VPN Service (1VPNS) has advertised anonymous VPN and server-rental services on Russian-language cybercriminal forums, including Exploit and XSS, since 2014. The service marketed a strict no-logs policy and publicly refused to cooperate with law-enforcement requests concerning abuse originating from its infrastructure. Ransomware actors used 1VPNS servers to conceal the origin of intrusions, stage and deploy malicious payloads, and manage stolen victim data during extortion operations. 1VPNS also operated a peer-to-peer Jabber messaging service used by its criminal clientele for operational communications.

Dmytro Rashevskyi, identified as the administrator of 1VPNS, used false identities -- "Maksim Sorin" and "Roman Chabanenko" -- to purchase servers and infrastructure from hosting providers that would otherwise have rejected him over prior abuse complaints tied to 1VPNS-originated malicious activity. OFAC's designation lists digital-currency addresses attributable to Rashevskyi across Bitcoin, Ethereum, Litecoin, Dogecoin, Dash, Zcash, and Solana (15 addresses total), including two confirmed Bitcoin addresses: 1MTndG4K51RRMvkzyvguaHnQpiMLnxFGzM and 1DfyWkiXVVqWfcSduj23qTDis9kb2qvRDa. Five additional digital-currency addresses spanning Bitcoin, Ethereum, Litecoin, and Tron were attributed directly to 1VPNS and traced to the high-risk, Russia-linked payment processor Cryptomus.

Yevgeniy Vladimirovich Silayev, a Belarusian national, separately supplied "cryptor" services -- malware-obfuscation tooling that repackages ransomware payloads and loaders to evade antivirus and EDR signature/behavioral detection -- to ransomware operators. Cryptor services are a standard component of the ransomware-as-a-service supply chain, sold independently of the ransomware payload itself to help affiliates bypass endpoint defenses prior to deployment.

On-chain analysis cited in the designation and by blockchain-intelligence firm TRM Labs documented direct payments from ransomware operators to 1VPNS infrastructure, including transactions attributed to the Anubis ransomware group (December 13, 2025 and March 15-16, 2026), Qilin ransomware (January 11, 2026), and the Sinobi group (February 8, 2026), establishing a traceable financial relationship between the sanctioned infrastructure providers and active ransomware operations.

A May 2026 international law-enforcement operation, coordinated between European authorities and the FBI's Boston Field Office, seized and disrupted 1VPNS's website and hosting infrastructure ahead of the July 2026 sanctions action, combining an operational takedown with a financial-sanctions follow-through intended to permanently sever 1VPNS's and its administrator's access to the U.S. financial system. The July 13 action was coordinated with the United Kingdom's Foreign, Commonwealth & Development Office (FCDO), which sanctioned additional cybercriminals and ransomware enablers the same day as part of a joint international response. Treasury officials stated the sanctioned infrastructure enabled ransomware attacks that caused billions of dollars in losses to U.S. businesses and critical-infrastructure providers. All three designees are now listed on OFAC's Specially Designated Nationals (SDN) list, prohibiting U.S. persons from engaging in transactions with them and blocking any U.S.-touching assets.

MITRE ATT&CK techniques used in TL-2026-1291

Collection

T1005 Data from Local System

Defense Evasion

T1027 Obfuscated Files or Information; T1027.002 Software Packing; T1036 Masquerading

Command and Control

T1071 Application Layer Protocol; T1090.002 External Proxy

command-and-control

T1090.003 Multi-hop Proxy

Impact

T1486 Data Encrypted for Impact; T1657 Financial Theft

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583.003 Virtual Private Server; T1583.004 Server; T1583.006 Web Services; T1585 Establish Accounts; T1588.001 Malware; T1588.002 Tool; T1608.001 Upload Malware

defense-impairment

T1685 Disable or Modify Tools

Remediation for OFAC Sanctions First VPN Service (1VPNS), Administrator

Immediate actions

  • Verify no organizational financial relationships or payment processing ties exist with the newly designated SDN entities (1VPNS, Dmytro Rashevskyi, Yevgeniy Vladimirovich Silayev) or their known aliases
  • Screen outbound network connections and VPN egress traffic for known 1VPNS infrastructure ranges and update perimeter blocklists as authoritative IOC lists are published
  • Flag and block the cryptocurrency addresses attributed to Rashevskyi and 1VPNS in transaction-monitoring and blockchain-analytics tooling

Workarounds

  • Treat traffic from residual 1VPNS-associated exit infrastructure as high risk pending full decommissioning confirmation post the May 2026 law-enforcement takedown

Longer-term hardening

  • Incorporate ransomware-enabling infrastructure providers (bulletproof VPN/hosting, cryptor vendors) into threat-intelligence infrastructure tracking, not just ransomware payload/group tracking
  • Deploy EDR/antivirus with behavioral and heuristic detection capable of catching cryptor-obfuscated payloads that evade static signature matching
  • Maintain updated blockchain transaction-monitoring rules for high-risk exchanges and payment processors such as Cryptomus that ransomware-adjacent infrastructure providers rely on

Timeline of OFAC Sanctions First VPN Service (1VPNS), Administrator

  • First VPN Service (1VPNS) begins advertising no-logs VPN and server-rental infrastructure on Russian-language cybercriminal forums including Exploit and XSS.
  • On-chain evidence shows the Anubis ransomware group paying 1VPNS-linked infrastructure ($715), per TRM Labs blockchain analysis cited in the OFAC designation.
  • On-chain evidence shows the Qilin ransomware group paying 1VPNS-linked infrastructure ($120).
  • On-chain evidence shows the Sinobi ransomware group paying 1VPNS-linked infrastructure ($58).
  • Additional on-chain payment from the Anubis ransomware group to 1VPNS-linked infrastructure (spanning March 15-16, 2026).
  • International law-enforcement operation, coordinated between European authorities and the FBI's Boston Field Office, seizes and disrupts 1VPNS's website and server infrastructure.
  • U.S. Department of State publishes a coordinated statement on the international sanctions action targeting ransomware enablers.
  • OFAC designates 1VPNS, administrator Dmytro Rashevskyi, and cryptor vendor Yevgeniy Vladimirovich Silayev to the SDN list under Executive Order 13694 (as amended) and Executive Order 14390, coordinated with the UK FCDO's parallel sanctions action.
  • Cybersecurity trade press (Cyber Security News, The Record, TechNadu, Crowdfund Insider) reports on the OFAC designation and its implications for ransomware-enabling infrastructure providers.

Sources cited for OFAC Sanctions First VPN Service (1VPNS), Administrator

Detection coverage for TL-2026-1291

As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1291 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats