# US Treasury Sanctions VPN Provider 1VPNS and Crypter Seller for Enabling Ransomware Operations

> OFAC, coordinated with the UK Foreign, Commonwealth & Development Office, sanctioned the no-log VPN service First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yegeniy Vladimirovich Silayev for supplying anonymization and malware-evasion infrastructure to ransomware groups including Anubis, Qilin, and Sinobi. The action follows the May 2026 European law-enforcement takedown of 1VPNS's 33-server infrastructure across 27 countries.

- **Published:** 2026-07-14T00:00:00Z
- **Last reviewed:** 2026-07-14T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1295
- **ID:** TL-2026-1295
- **Severity:** MEDIUM
- **Category:** OTHER
- **Status:** ACTIVE
- **Actor:** 1VPNS
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On July 13, 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) designated three parties under Executive Order 14390 for providing material support to ransomware operations targeting American businesses, hospitals, financial services firms, schools, and municipal governments. The designations targeted First VPN Service (1VPNS), a no-log VPN provider operating since 2014 that advertised on Russian-language cybercrime forums Exploit and XSS and explicitly marketed non-cooperation with law enforcement; its administrator, Ukrainian national Dmytro Rashevskyi (using aliases 'Maksim Sorin' and 'Roman Chabanenko' to purchase hosting and networking infrastructure from providers that would otherwise refuse to deal with a known cybercrime operator); and Yegeniy Vladimirovich Silayev, a Belarusian national who sold 'cryptors' — malware-obfuscation tools designed to disguise ransomware and other malicious payloads as benign software to evade antivirus and EDR detection.

1VPNS's infrastructure — 33 servers spread across 27 countries — was seized in May 2026 during a European law-enforcement operation led by French and Dutch authorities with support from the FBI's Boston Field Office; Rashevskyi was arrested and the service's website and back-end were dismantled, exposing thousands of former users. OFAC's blockchain analysis identified cryptocurrency wallets tied to 1VPNS (5 addresses across Bitcoin, Ethereum, Litecoin, and Tron, concentrated at the high-risk virtual asset exchange Cryptomus) and to Rashevskyi personally (15 addresses spanning Bitcoin, Ethereum, Tron, Litecoin, Dogecoin, Dash, Zcash, and Solana). On-chain tracing links payments from the Anubis ransomware group (two transfers totaling $715 in December 2025 and March 2026), Qilin ($120, January 2026), and the Sinobi Group ($58, February 2026) to designated wallets, evidencing direct financial nexus between the anonymization/cryptor service and active ransomware operations, notwithstanding the small individual transaction sizes typical of infrastructure/subscription payments rather than extortion proceeds themselves.

The designations were coordinated with the United Kingdom's Foreign, Commonwealth & Development Office, which imposed parallel sanctions, reflecting a broader multilateral push to disrupt the criminal-services supply chain (bulletproof hosting, no-log VPNs, and crypters) that underpins modern ransomware-as-a-service operations rather than targeting ransomware operators directly. As designated persons under OFAC, all property and interests in property of 1VPNS, Rashevskyi, and Silayev within U.S. jurisdiction are blocked, and U.S. persons are generally prohibited from engaging in transactions with them; the sanctioned cryptocurrency addresses are also expected to be blocked from services by U.S.-nexus exchanges. Total losses attributed to ransomware groups using the sanctioned infrastructure are described by Treasury as amounting to billions of dollars in damages to U.S. businesses and critical-infrastructure providers.

## MITRE ATT&CK

- T1583.003 Virtual Private Server
- T1583.007 Serverless
- T1588.001 Malware
- T1583.001 Domains
- T1585 Establish Accounts
- T1027.002 Software Packing
- T1027 Obfuscated Files or Information
- T1685 Disable or Modify Tools
- T1036 Masquerading
- T1090.003 Multi-hop Proxy
- T1090.002 External Proxy
- T1071 Application Layer Protocol
- T1567 Exfiltration Over Web Service
- T1486 Data Encrypted for Impact
- T1657 Financial Theft

## Sources

- [US sanctions VPN, malware providers linked to ransomware gangs](https://www.bleepingcomputer.com/news/security/us-sanctions-vpn-malware-providers-linked-to-ransomware-gangs/)
- [Treasury Sanctions Malware and Infrastructure Providers Supporting Ransomware Attacks Against Americans](https://home.treasury.gov/news/press-releases/sb0559)
- [OFAC Sanctions FirstVPN and Ransomware Enablers Behind Attacks on Americans](https://www.trmlabs.com/resources/blog/ofac-sanctions-firstvpn-and-ransomware-enablers-behind-attacks-on-americans)
- [U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support](https://thehackernews.com/2026/07/us-sanctions-first-vpn-service-and.html)
- [VPN service favored by ransomware groups is sanctioned by US](https://therecord.media/first-vpn-administrator-us-sanctions-ransomware-groups)
- ["Cryptors" - US Department Of Treasury Sanctions Malware Enablers](https://www.crowdfundinsider.com/2026/07/291454-cryptors-us-department-of-treasury-sanctions-malware-enablers/)
- [First VPN Service sanctioned by US over sales to ransomware groups](https://www.mlex.com/mlex/articles/2500269/first-vpn-service-sanctioned-by-us-over-sales-to-ransomware-groups)
- [Sanctioning Ransomware Enablers in Coordinated International Action](https://www.state.gov/releases/office-of-the-spokesperson/2026/07/sanctioning-ransomware-enablers-in-coordinated-international-action)
- [U.S. Treasury Sanctions VPN Provider 1VPNS Over Cybercrime](https://www.technadu.com/u-s-treasury-sanctions-vpn-provider-1vpns-over-cybercrime/630993/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1295
