US Treasury Sanctions VPN Provider 1VPNS and Crypter Seller for Enabling Ransomware Operations — Threadlinqs Intelligence
As of 2026-07-14, US Treasury Sanctions VPN Provider 1VPNS and Crypter Seller for Enabling Ransomware Operations is a medium-severity other threat attributed to 1VPNS, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-1295 · Severity: MEDIUM · Status: ACTIVE · Category: OTHER
Attribution: 1VPNS · FINANCIAL
OFAC, coordinated with the UK Foreign, Commonwealth & Development Office, sanctioned the no-log VPN service First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and Belarusian cryptor
On July 13, 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) designated three parties under Executive Order 14390 for providing material support to ransomware operations targeting American businesses, hospitals, financial services firms, schools, and municipal governments. The designations targeted First VPN Service (1VPNS), a no-log VPN provider operating since 2014 that advertised on Russian-language cybercrime forums Exploit and XSS and explicitly marketed non-cooperation with law enforcement; its administrator, Ukrainian national Dmytro Rashevskyi (using aliases 'Maksim Sorin' and 'Roman Chabanenko' to purchase hosting and networking infrastructure from providers that would otherwise refuse to deal with a known cybercrime operator); and Yegeniy Vladimirovich Silayev, a Belarusian national who sold 'cryptors' — malware-obfuscation tools designed to disguise ransomware and other malicious payloads as benign software to evade antivirus and EDR detection.
1VPNS's infrastructure — 33 servers spread across 27 countries — was seized in May 2026 during a European law-enforcement operation led by French and Dutch authorities with support from the FBI's Boston Field Office; Rashevskyi was arrested and the service's website and back-end were dismantled, exposing thousands of former users. OFAC's blockchain analysis identified cryptocurrency wallets tied to 1VPNS (5 addresses across Bitcoin, Ethereum, Litecoin, and Tron, concentrated at the high-risk virtual asset exchange Cryptomus) and to Rashevskyi personally (15 addresses spanning Bitcoin, Ethereum, Tron, Litecoin, Dogecoin, Dash, Zcash, and Solana). On-chain tracing links payments from the Anubis ransomware group (two transfers totaling $715 in December 2025 and March 2026), Qilin ($120, January 2026), and the Sinobi Group ($58, February 2026) to designated wallets, evidencing direct financial nexus between the anonymization/cryptor service and active ransomware operations, notwithstanding the small individual transaction sizes typical of infrastructure/subscription payments rather than extortion proceeds themselves.
The designations were coordinated with the United Kingdom's Foreign, Commonwealth & Development Office, which imposed parallel sanctions, reflecting a broader multilateral push to disrupt the criminal-services supply chain (bulletproof hosting, no-log VPNs, and crypters) that underpins modern ransomware-as-a-service operations rather than targeting ransomware operators directly. As designated persons under OFAC, all property and interests in property of 1VPNS, Rashevskyi, and Silayev within U.S. jurisdiction are blocked, and U.S. persons are generally prohibited from engaging in transactions with them; the sanctioned cryptocurrency addresses are also expected to be blocked from services by U.S.-nexus exchanges. Total losses attributed to ransomware groups using the sanctioned infrastructure are described by Treasury as amounting to billions of dollars in damages to U.S. businesses and critical-infrastructure providers.
Target sectors: businesses, hospitals, health, financial services, government administration, municipal government, critical infrastructure, education
Target regions: united states of america, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
OTHER, MEDIUM, threat intelligence, cybersecurity, T1583.003, T1583.007, T1588.001, T1583.001, T1585, T1027.002, T1027, T1562.001, T1036, T1090.003