# OFAC Sanctions First VPN Service (1VPNS), Administrator Dmytro Rashevskyi, and Cryptor Vendor Yevgeniy Silayev for Enabling Ransomware Attacks on U.S. Critical Infrastructure

> On July 13, 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC), coordinated with the UK Foreign, Commonwealth & Development Office, sanctioned First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and Belarusian cryptor vendor Yevgeniy Vladimirovich Silayev for supplying anonymizing VPN infrastructure and malware-obfuscation services to ransomware actors that attacked U.S. hospitals, financial firms, and municipalities since 2014. A May 2026 international law-enforcement operation, supported by the FBI Boston Field Office and European authorities, had already dismantled 1VPNS's website and server infrastructure.

- **Published:** 2026-07-14T00:00:00Z
- **Last reviewed:** 2026-07-14T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1291
- **ID:** TL-2026-1291
- **Severity:** MEDIUM
- **Category:** OTHER
- **Status:** ACTIVE
- **Actor:** 1VPNS (Russia)
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)

## Description

The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) designated three parties on July 13, 2026, under Executive Order 13694 (as amended) and Executive Order 14390 (March 2026), for materially supporting ransomware operations against American businesses, hospitals, financial-services firms, and municipal governments. The action targeted the ransomware-enabling supply chain rather than a ransomware operator directly, reflecting an evolving OFAC strategy of sanctioning bulletproof-hosting and anonymization infrastructure providers that ransomware affiliates depend on for operational security.

First VPN Service (1VPNS) has advertised anonymous VPN and server-rental services on Russian-language cybercriminal forums, including Exploit and XSS, since 2014. The service marketed a strict no-logs policy and publicly refused to cooperate with law-enforcement requests concerning abuse originating from its infrastructure. Ransomware actors used 1VPNS servers to conceal the origin of intrusions, stage and deploy malicious payloads, and manage stolen victim data during extortion operations. 1VPNS also operated a peer-to-peer Jabber messaging service used by its criminal clientele for operational communications.

Dmytro Rashevskyi, identified as the administrator of 1VPNS, used false identities -- "Maksim Sorin" and "Roman Chabanenko" -- to purchase servers and infrastructure from hosting providers that would otherwise have rejected him over prior abuse complaints tied to 1VPNS-originated malicious activity. OFAC's designation lists digital-currency addresses attributable to Rashevskyi across Bitcoin, Ethereum, Litecoin, Dogecoin, Dash, Zcash, and Solana (15 addresses total), including two confirmed Bitcoin addresses: 1MTndG4K51RRMvkzyvguaHnQpiMLnxFGzM and 1DfyWkiXVVqWfcSduj23qTDis9kb2qvRDa. Five additional digital-currency addresses spanning Bitcoin, Ethereum, Litecoin, and Tron were attributed directly to 1VPNS and traced to the high-risk, Russia-linked payment processor Cryptomus.

Yevgeniy Vladimirovich Silayev, a Belarusian national, separately supplied "cryptor" services -- malware-obfuscation tooling that repackages ransomware payloads and loaders to evade antivirus and EDR signature/behavioral detection -- to ransomware operators. Cryptor services are a standard component of the ransomware-as-a-service supply chain, sold independently of the ransomware payload itself to help affiliates bypass endpoint defenses prior to deployment.

On-chain analysis cited in the designation and by blockchain-intelligence firm TRM Labs documented direct payments from ransomware operators to 1VPNS infrastructure, including transactions attributed to the Anubis ransomware group (December 13, 2025 and March 15-16, 2026), Qilin ransomware (January 11, 2026), and the Sinobi group (February 8, 2026), establishing a traceable financial relationship between the sanctioned infrastructure providers and active ransomware operations.

A May 2026 international law-enforcement operation, coordinated between European authorities and the FBI's Boston Field Office, seized and disrupted 1VPNS's website and hosting infrastructure ahead of the July 2026 sanctions action, combining an operational takedown with a financial-sanctions follow-through intended to permanently sever 1VPNS's and its administrator's access to the U.S. financial system. The July 13 action was coordinated with the United Kingdom's Foreign, Commonwealth & Development Office (FCDO), which sanctioned additional cybercriminals and ransomware enablers the same day as part of a joint international response. Treasury officials stated the sanctioned infrastructure enabled ransomware attacks that caused billions of dollars in losses to U.S. businesses and critical-infrastructure providers. All three designees are now listed on OFAC's Specially Designated Nationals (SDN) list, prohibiting U.S. persons from engaging in transactions with them and blocking any U.S.-touching assets.

## MITRE ATT&CK

- T1583.003 Virtual Private Server
- T1583.004 Server
- T1583.006 Web Services
- T1588.001 Malware
- T1588.002 Tool
- T1585 Establish Accounts
- T1608.001 Upload Malware
- T1027 Obfuscated Files or Information
- T1027.002 Software Packing
- T1685 Disable or Modify Tools
- T1090.003 Multi-hop Proxy
- T1036 Masquerading
- T1090.002 External Proxy
- T1071 Application Layer Protocol
- T1005 Data from Local System
- T1567 Exfiltration Over Web Service
- T1486 Data Encrypted for Impact
- T1657 Financial Theft

## Sources

- [US Treasury Sanctions First VPN Service that Helped Ransomware Actors Attack Organizations](https://cybersecuritynews.com/first-vpn-service-sanctioned/)
- [Treasury Sanctions Malware and Infrastructure Providers Supporting Ransomware Attacks Against Americans](https://home.treasury.gov/news/press-releases/sb0559)
- [OFAC Sanctions FirstVPN and Ransomware Enablers Behind Attacks on Americans](https://www.trmlabs.com/resources/blog/ofac-sanctions-firstvpn-and-ransomware-enablers-behind-attacks-on-americans)
- [VPN service favored by ransomware groups is sanctioned by US](https://therecord.media/first-vpn-administrator-us-sanctions-ransomware-groups)
- ["Cryptors" - US Department Of Treasury Sanctions Malware Enablers](https://www.crowdfundinsider.com/2026/07/291454-cryptors-us-department-of-treasury-sanctions-malware-enablers/)
- [U.S. Treasury Sanctions VPN Provider 1VPNS Over Cybercrime](https://www.technadu.com/u-s-treasury-sanctions-vpn-provider-1vpns-over-cybercrime/630993/)
- [Sanctioning Ransomware Enablers in Coordinated International Action](https://www.state.gov/releases/office-of-the-spokesperson/2026/07/sanctioning-ransomware-enablers-in-coordinated-international-action)
- [Cyber-related Designations; Cuba Designations - OFAC Recent Actions](https://ofac.treasury.gov/recent-actions/20260713)
- [US Treasury sanctions malware providers tied to cyberattacks](https://news.az/news/us-treasury-sanctions-malware-providers-tied-to-cyberattacks)
- [EU and UK blacklist Russia's cyber operators over efforts to destabilize Europe](https://www.helpnetsecurity.com/2026/07/13/eu-uk-russia-cyber-activity-sanctions/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1291
