Threat reportOtherTL-2026-1291
OFAC Sanctions First VPN Service (1VPNS), Administrator Dmytro Rashevskyi, and Cryptor Vendor Yevgeniy Silayev for Enabling Ransomware Attacks on U.S. Critical Infrastructure
OFAC Sanctions First VPN Service (1VPNS), Administrator (TL-2026-1291), also tracked as First VPN Service sanctions, is a medium-severity other threat, first published 2026-07-14. It is attributed to 1VPNS (Russia) with high confidence, maps to 18 MITRE ATT&CK techniques (T1005, T1027, T1027.002), and is covered by 9 detection rules and 16 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 18MITRE ATT&CK
- Actors
- 11VPNS
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 16Indicators of compromise
Key facts for TL-2026-1291
- Threat ID
- TL-2026-1291
- Also known as
- First VPN Service sanctions, 1VPNS OFAC designation
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- OTHER
- First published
- Last reviewed
- Attribution
- 1VPNS
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- health, financial services, government administration, municipal government, critical infrastructure, cybercrime infrastructure supply chain
- Target regions
- united states of america, united kingdom
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in OFAC Sanctions First VPN Service (1VPNS), Administrator
Malware and tooling: Anubis Ransomware, Qilin Ransomware, Sinobi Ransomware, Cryptor (Silayev malware-obfuscation service)
How OFAC Sanctions First VPN Service (1VPNS), Administrator works
On July 13, 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC), coordinated with the UK Foreign, Commonwealth & Development Office, sanctioned First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and Belarusian cryptor vendor Yevgeniy Vladimirovich Silayev for supplying anonymizing VPN infrastructure and malware-obfuscation services to ransomware actors that attacked U.S. hospitals, financial firms, and municipalities since 2014. A May 2026 international law-enforcement operation, supported by the FBI Boston Field Office and European authorities, had already dismantled 1VPNS's website and server infrastructure.
The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) designated three parties on July 13, 2026, under Executive Order 13694 (as amended) and Executive Order 14390 (March 2026), for materially supporting ransomware operations against American businesses, hospitals, financial-services firms, and municipal governments. The action targeted the ransomware-enabling supply chain rather than a ransomware operator directly, reflecting an evolving OFAC strategy of sanctioning bulletproof-hosting and anonymization infrastructure providers that ransomware affiliates depend on for operational security.
First VPN Service (1VPNS) has advertised anonymous VPN and server-rental services on Russian-language cybercriminal forums, including Exploit and XSS, since 2014. The service marketed a strict no-logs policy and publicly refused to cooperate with law-enforcement requests concerning abuse originating from its infrastructure. Ransomware actors used 1VPNS servers to conceal the origin of intrusions, stage and deploy malicious payloads, and manage stolen victim data during extortion operations. 1VPNS also operated a peer-to-peer Jabber messaging service used by its criminal clientele for operational communications.
Dmytro Rashevskyi, identified as the administrator of 1VPNS, used false identities -- "Maksim Sorin" and "Roman Chabanenko" -- to purchase servers and infrastructure from hosting providers that would otherwise have rejected him over prior abuse complaints tied to 1VPNS-originated malicious activity. OFAC's designation lists digital-currency addresses attributable to Rashevskyi across Bitcoin, Ethereum, Litecoin, Dogecoin, Dash, Zcash, and Solana (15 addresses total), including two confirmed Bitcoin addresses: 1MTndG4K51RRMvkzyvguaHnQpiMLnxFGzM and 1DfyWkiXVVqWfcSduj23qTDis9kb2qvRDa. Five additional digital-currency addresses spanning Bitcoin, Ethereum, Litecoin, and Tron were attributed directly to 1VPNS and traced to the high-risk, Russia-linked payment processor Cryptomus.
Yevgeniy Vladimirovich Silayev, a Belarusian national, separately supplied "cryptor" services -- malware-obfuscation tooling that repackages ransomware payloads and loaders to evade antivirus and EDR signature/behavioral detection -- to ransomware operators. Cryptor services are a standard component of the ransomware-as-a-service supply chain, sold independently of the ransomware payload itself to help affiliates bypass endpoint defenses prior to deployment.
On-chain analysis cited in the designation and by blockchain-intelligence firm TRM Labs documented direct payments from ransomware operators to 1VPNS infrastructure, including transactions attributed to the Anubis ransomware group (December 13, 2025 and March 15-16, 2026), Qilin ransomware (January 11, 2026), and the Sinobi group (February 8, 2026), establishing a traceable financial relationship between the sanctioned infrastructure providers and active ransomware operations.
A May 2026 international law-enforcement operation, coordinated between European authorities and the FBI's Boston Field Office, seized and disrupted 1VPNS's website and hosting infrastructure ahead of the July 2026 sanctions action, combining an operational takedown with a financial-sanctions follow-through intended to permanently sever 1VPNS's and its administrator's access to the U.S. financial system. The July 13 action was coordinated with the United Kingdom's Foreign, Commonwealth & Development Office (FCDO), which sanctioned additional cybercriminals and ransomware enablers the same day as part of a joint international response. Treasury officials stated the sanctioned infrastructure enabled ransomware attacks that caused billions of dollars in losses to U.S. businesses and critical-infrastructure providers. All three designees are now listed on OFAC's Specially Designated Nationals (SDN) list, prohibiting U.S. persons from engaging in transactions with them and blocking any U.S.-touching assets.
MITRE ATT&CK techniques used in TL-2026-1291
Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1027.002 Software Packing; T1036 Masquerading
Command and Control
T1071 Application Layer Protocol; T1090.002 External Proxy
command-and-control
Impact
T1486 Data Encrypted for Impact; T1657 Financial Theft
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1583.003 Virtual Private Server; T1583.004 Server; T1583.006 Web Services; T1585 Establish Accounts; T1588.001 Malware; T1588.002 Tool; T1608.001 Upload Malware
defense-impairment
Remediation for OFAC Sanctions First VPN Service (1VPNS), Administrator
Immediate actions
- Verify no organizational financial relationships or payment processing ties exist with the newly designated SDN entities (1VPNS, Dmytro Rashevskyi, Yevgeniy Vladimirovich Silayev) or their known aliases
- Screen outbound network connections and VPN egress traffic for known 1VPNS infrastructure ranges and update perimeter blocklists as authoritative IOC lists are published
- Flag and block the cryptocurrency addresses attributed to Rashevskyi and 1VPNS in transaction-monitoring and blockchain-analytics tooling
Workarounds
- Treat traffic from residual 1VPNS-associated exit infrastructure as high risk pending full decommissioning confirmation post the May 2026 law-enforcement takedown
Longer-term hardening
- Incorporate ransomware-enabling infrastructure providers (bulletproof VPN/hosting, cryptor vendors) into threat-intelligence infrastructure tracking, not just ransomware payload/group tracking
- Deploy EDR/antivirus with behavioral and heuristic detection capable of catching cryptor-obfuscated payloads that evade static signature matching
- Maintain updated blockchain transaction-monitoring rules for high-risk exchanges and payment processors such as Cryptomus that ransomware-adjacent infrastructure providers rely on
Timeline of OFAC Sanctions First VPN Service (1VPNS), Administrator
- First VPN Service (1VPNS) begins advertising no-logs VPN and server-rental infrastructure on Russian-language cybercriminal forums including Exploit and XSS.
- On-chain evidence shows the Anubis ransomware group paying 1VPNS-linked infrastructure ($715), per TRM Labs blockchain analysis cited in the OFAC designation.
- On-chain evidence shows the Qilin ransomware group paying 1VPNS-linked infrastructure ($120).
- On-chain evidence shows the Sinobi ransomware group paying 1VPNS-linked infrastructure ($58).
- Additional on-chain payment from the Anubis ransomware group to 1VPNS-linked infrastructure (spanning March 15-16, 2026).
- International law-enforcement operation, coordinated between European authorities and the FBI's Boston Field Office, seizes and disrupts 1VPNS's website and server infrastructure.
- U.S. Department of State publishes a coordinated statement on the international sanctions action targeting ransomware enablers.
- OFAC designates 1VPNS, administrator Dmytro Rashevskyi, and cryptor vendor Yevgeniy Vladimirovich Silayev to the SDN list under Executive Order 13694 (as amended) and Executive Order 14390, coordinated with the UK FCDO's parallel sanctions action.
- Cybersecurity trade press (Cyber Security News, The Record, TechNadu, Crowdfund Insider) reports on the OFAC designation and its implications for ransomware-enabling infrastructure providers.
Sources cited for OFAC Sanctions First VPN Service (1VPNS), Administrator
- US Treasury Sanctions First VPN Service that Helped Ransomware Actors Attack Organizations
- Treasury Sanctions Malware and Infrastructure Providers Supporting Ransomware Attacks Against Americans
- OFAC Sanctions FirstVPN and Ransomware Enablers Behind Attacks on Americans
- VPN service favored by ransomware groups is sanctioned by US
- "Cryptors" - US Department Of Treasury Sanctions Malware Enablers
- U.S. Treasury Sanctions VPN Provider 1VPNS Over Cybercrime
- Sanctioning Ransomware Enablers in Coordinated International Action
- Cyber-related Designations; Cuba Designations - OFAC Recent Actions
- US Treasury sanctions malware providers tied to cyberattacks
- EU and UK blacklist Russia's cyber operators over efforts to destabilize Europe
Detection coverage for TL-2026-1291
As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1291 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.