Threat reportOtherTL-2026-1295
US Treasury Sanctions VPN Provider 1VPNS and Crypter Seller for Enabling Ransomware Operations
US Treasury Sanctions VPN Provider 1VPNS and Crypter Seller (TL-2026-1295), also tracked as Operation Saffron, is a medium-severity other threat, first published 2026-07-14. It is attributed to 1VPNS with high confidence, maps to 15 MITRE ATT&CK techniques (T1027, T1027.002, T1036), and is covered by 9 detection rules and 21 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 15MITRE ATT&CK
- Actors
- 11VPNS
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 21Indicators of compromise
Key facts for TL-2026-1295
- Threat ID
- TL-2026-1295
- Also known as
- Operation Saffron
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- OTHER
- First published
- Last reviewed
- Attribution
- 1VPNS
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- businesses, hospitals, health, financial services, government administration, municipal government, critical infrastructure, education
- Target regions
- united states of america, Europe
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in US Treasury Sanctions VPN Provider 1VPNS and Crypter Seller
Malware and tooling: AgendaCrypt, Sinobi Group, anubis, Cryptor (Silayev's malware obfuscation tool)
How US Treasury Sanctions VPN Provider 1VPNS and Crypter Seller works
OFAC, coordinated with the UK Foreign, Commonwealth & Development Office, sanctioned the no-log VPN service First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yegeniy Vladimirovich Silayev for supplying anonymization and malware-evasion infrastructure to ransomware groups including Anubis, Qilin, and Sinobi. The action follows the May 2026 European law-enforcement takedown of 1VPNS's 33-server infrastructure across 27 countries.
On July 13, 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) designated three parties under Executive Order 14390 for providing material support to ransomware operations targeting American businesses, hospitals, financial services firms, schools, and municipal governments. The designations targeted First VPN Service (1VPNS), a no-log VPN provider operating since 2014 that advertised on Russian-language cybercrime forums Exploit and XSS and explicitly marketed non-cooperation with law enforcement; its administrator, Ukrainian national Dmytro Rashevskyi (using aliases 'Maksim Sorin' and 'Roman Chabanenko' to purchase hosting and networking infrastructure from providers that would otherwise refuse to deal with a known cybercrime operator); and Yegeniy Vladimirovich Silayev, a Belarusian national who sold 'cryptors' — malware-obfuscation tools designed to disguise ransomware and other malicious payloads as benign software to evade antivirus and EDR detection.
1VPNS's infrastructure — 33 servers spread across 27 countries — was seized in May 2026 during a European law-enforcement operation led by French and Dutch authorities with support from the FBI's Boston Field Office; Rashevskyi was arrested and the service's website and back-end were dismantled, exposing thousands of former users. OFAC's blockchain analysis identified cryptocurrency wallets tied to 1VPNS (5 addresses across Bitcoin, Ethereum, Litecoin, and Tron, concentrated at the high-risk virtual asset exchange Cryptomus) and to Rashevskyi personally (15 addresses spanning Bitcoin, Ethereum, Tron, Litecoin, Dogecoin, Dash, Zcash, and Solana). On-chain tracing links payments from the Anubis ransomware group (two transfers totaling $715 in December 2025 and March 2026), Qilin ($120, January 2026), and the Sinobi Group ($58, February 2026) to designated wallets, evidencing direct financial nexus between the anonymization/cryptor service and active ransomware operations, notwithstanding the small individual transaction sizes typical of infrastructure/subscription payments rather than extortion proceeds themselves.
The designations were coordinated with the United Kingdom's Foreign, Commonwealth & Development Office, which imposed parallel sanctions, reflecting a broader multilateral push to disrupt the criminal-services supply chain (bulletproof hosting, no-log VPNs, and crypters) that underpins modern ransomware-as-a-service operations rather than targeting ransomware operators directly. As designated persons under OFAC, all property and interests in property of 1VPNS, Rashevskyi, and Silayev within U.S. jurisdiction are blocked, and U.S. persons are generally prohibited from engaging in transactions with them; the sanctioned cryptocurrency addresses are also expected to be blocked from services by U.S.-nexus exchanges. Total losses attributed to ransomware groups using the sanctioned infrastructure are described by Treasury as amounting to billions of dollars in damages to U.S. businesses and critical-infrastructure providers.
MITRE ATT&CK techniques used in TL-2026-1295
Defense Evasion
T1027 Obfuscated Files or Information; T1027.002 Software Packing; T1036 Masquerading
Command and Control
T1071 Application Layer Protocol; T1090.002 External Proxy; T1090.003 Multi-hop Proxy
Impact
T1486 Data Encrypted for Impact; T1657 Financial Theft
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1583.001 Domains; T1583.003 Virtual Private Server; T1583.007 Serverless; T1585 Establish Accounts; T1588.001 Malware
defense-impairment
Remediation for US Treasury Sanctions VPN Provider 1VPNS and Crypter Seller
Immediate actions
- Block all U.S.-nexus transactions with designated cryptocurrency addresses associated with 1VPNS, Dmytro Rashevskyi, and their known chains (Bitcoin, Ethereum, Litecoin, Tron, Dogecoin, Dash, Zcash, Solana)
- Review OFAC's Specially Designated Nationals (SDN) list entries for 1VPNS, Dmytro Rashevskyi, and Yegeniy Vladimirovich Silayev and screen customers/counterparties against them
- Flag and investigate any historical connectivity logs, VPN egress IPs, or payment records tied to 1VPNS infrastructure for retrospective compromise assessment
- Notify compliance and legal teams of designation to ensure sanctions-screening systems are updated
Longer-term hardening
- Incorporate bulletproof-hosting and no-log-VPN provider intelligence (e.g., forums Exploit, XSS) into threat-intelligence feeds for proactive blocking
- Expand blockchain-analytics-driven sanctions screening for ransomware-adjacent virtual asset service providers such as Cryptomus
- Strengthen EDR/AV signature and behavioral-detection coverage against generic 'cryptor'/obfuscation techniques used to evade static detection
- Participate in public-private information sharing on ransomware-enabling infrastructure providers to support future disruption actions
Timeline of US Treasury Sanctions VPN Provider 1VPNS and Crypter Seller
- First VPN Service (1VPNS) begins operations, advertising a no-log policy and non-cooperation with law enforcement on cybercrime forums Exploit and XSS.
- European law enforcement (French and Dutch authorities, with FBI Boston Field Office support) opens the investigation into 1VPNS that becomes the takedown operation.
- First identified payment from the Anubis ransomware group to a designated 1VPNS/Rashevskyi cryptocurrency wallet, part of a $715 total across two transfers.
- Qilin ransomware group sends a $120 payment to a designated wallet linked to the sanctioned infrastructure.
- Sinobi Group sends a $58 payment to a designated wallet linked to the sanctioned infrastructure.
- Executive Order 14390 issued, providing the sanctions authority later used against 1VPNS, Rashevskyi, and Silayev.
- Second Anubis ransomware group payment tranche recorded, completing the $715 total identified by blockchain analysis.
- European law enforcement (Operation Saffron) seizes 1VPNS's 33 servers across 27 countries, dismantles the website and back-end, and arrests administrator Dmytro Rashevskyi, exposing thousands of former users.
- OFAC, coordinated with the UK Foreign, Commonwealth & Development Office, publicly designates 1VPNS, Dmytro Rashevskyi, and Yegeniy Vladimirovich Silayev as Specially Designated Nationals for supporting ransomware operations against Americans.
- Security and mainstream media (BleepingComputer, The Hacker News, The Record, TRM Labs) publish coverage of the sanctions action and associated blockchain analysis.
Sources cited for US Treasury Sanctions VPN Provider 1VPNS and Crypter Seller
- US sanctions VPN, malware providers linked to ransomware gangs
- Treasury Sanctions Malware and Infrastructure Providers Supporting Ransomware Attacks Against Americans
- OFAC Sanctions FirstVPN and Ransomware Enablers Behind Attacks on Americans
- U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
- VPN service favored by ransomware groups is sanctioned by US
- "Cryptors" - US Department Of Treasury Sanctions Malware Enablers
- First VPN Service sanctioned by US over sales to ransomware groups
- Sanctioning Ransomware Enablers in Coordinated International Action
- U.S. Treasury Sanctions VPN Provider 1VPNS Over Cybercrime
Detection coverage for TL-2026-1295
As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1295 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.