OFAC Sanctions First VPN Service (1VPNS), Administrator Dmytro Rashevskyi, and Cryptor Vendor Yevgeniy Silayev for Enabling Ransomware Attacks on U.S. Critical Infrastructure — Threadlinqs Intelligence
As of 2026-07-14, OFAC Sanctions First VPN Service (1VPNS), Administrator Dmytro Rashevskyi, and Cryptor Vendor Yevgeniy Silayev for Enabling Ransomware Attacks on U.S. Critical Infrastructure is a medium-severity other threat attributed to 1VPNS (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-1291 · Severity: MEDIUM · Status: ACTIVE · Category: OTHER
Attribution: 1VPNS · Russia · FINANCIAL
On July 13, 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC), coordinated with the UK Foreign, Commonwealth & Development Office, sanctioned First VPN Service (1VPNS), its
The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) designated three parties on July 13, 2026, under Executive Order 13694 (as amended) and Executive Order 14390 (March 2026), for materially supporting ransomware operations against American businesses, hospitals, financial-services firms, and municipal governments. The action targeted the ransomware-enabling supply chain rather than a ransomware operator directly, reflecting an evolving OFAC strategy of sanctioning bulletproof-hosting and anonymization infrastructure providers that ransomware affiliates depend on for operational security.
First VPN Service (1VPNS) has advertised anonymous VPN and server-rental services on Russian-language cybercriminal forums, including Exploit and XSS, since 2014. The service marketed a strict no-logs policy and publicly refused to cooperate with law-enforcement requests concerning abuse originating from its infrastructure. Ransomware actors used 1VPNS servers to conceal the origin of intrusions, stage and deploy malicious payloads, and manage stolen victim data during extortion operations. 1VPNS also operated a peer-to-peer Jabber messaging service used by its criminal clientele for operational communications.
Dmytro Rashevskyi, identified as the administrator of 1VPNS, used false identities -- "Maksim Sorin" and "Roman Chabanenko" -- to purchase servers and infrastructure from hosting providers that would otherwise have rejected him over prior abuse complaints tied to 1VPNS-originated malicious activity. OFAC's designation lists digital-currency addresses attributable to Rashevskyi across Bitcoin, Ethereum, Litecoin, Dogecoin, Dash, Zcash, and Solana (15 addresses total), including two confirmed Bitcoin addresses: 1MTndG4K51RRMvkzyvguaHnQpiMLnxFGzM and 1DfyWkiXVVqWfcSduj23qTDis9kb2qvRDa. Five additional digital-currency addresses spanning Bitcoin, Ethereum, Litecoin, and Tron were attributed directly to 1VPNS and traced to the high-risk, Russia-linked payment processor Cryptomus.
Yevgeniy Vladimirovich Silayev, a Belarusian national, separately supplied "cryptor" services -- malware-obfuscation tooling that repackages ransomware payloads and loaders to evade antivirus and EDR signature/behavioral detection -- to ransomware operators. Cryptor services are a standard component of the ransomware-as-a-service supply chain, sold independently of the ransomware payload itself to help affiliates bypass endpoint defenses prior to deployment.
On-chain analysis cited in the designation and by blockchain-intelligence firm TRM Labs documented direct payments from ransomware operators to 1VPNS infrastructure, including transactions attributed to the Anubis ransomware group (December 13, 2025 and March 15-16, 2026), Qilin ransomware (January 11, 2026), and the Sinobi group (February 8, 2026), establishing a traceable financial relationship between the sanctioned infrastructure providers and active ransomware operations.
A May 2026 international law-enforcement operation, coordinated between European authorities and the FBI's Boston Field Office, seized and disrupted 1VPNS's website and hosting infrastructure ahead of the July 2026 sanctions action, combining an operational takedown with a financial-sanctions follow-through intended to permanently sever 1VPNS's and its administrator's access to the U.S. financial system. The July 13 action was coordinated with the United Kingdom's Foreign, Commonwealth & Development Office (FCDO), which sanctioned additional cybercriminals and ransomware enablers the same day as part of a joint international response. Treasury officials stated the sanctioned infrastructure enabled ransomware attacks that caused billions of dollars in losses to U.S. businesses and critical-infrastructure providers. All three designees are now listed on OFAC's Specially Designated Nationals (SDN) list, prohibiting U.S. persons from engaging in transactions with them and blocking any U.S.-touching assets.
Target sectors: health, financial services, government administration, municipal government, critical infrastructure, cybercrime infrastructure supply chain
Target regions: united states of america, united kingdom
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
OTHER, MEDIUM, threat intelligence, cybersecurity, T1583.003, T1583.004, T1583.006, T1588.001, T1588.002, T1585, T1608.001, T1027, T1027.002, T1562.001