Threat reportRansomwareTL-2026-1314

US/EU/UK Sanction Vitaly Kovalev ("Stern"), Trickbot/Conti Administrator Linked to $300M+ in Ransomware Payments

highACTIVE

US/EU/UK Sanction Vitaly Kovalev ("Stern"), Trickbot/Conti (TL-2026-1314), also tracked as Wizard Spider, is a high-severity ransomware operation, first published 2026-07-14. It is attributed to Vitaly Kovalev (Russia) with high confidence, affects Media Land LLC Bulletproof hosting infrastructure (ML.Cloud LLC), maps to 25 MITRE ATT&CK techniques (T1003, T1005, T1021), and is covered by 9 detection rules and 30 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
25MITRE ATT&CK
Actors
2Vitaly Kovalev
Detection rules
9SPL · KQL · Sigma
IOCs
30Indicators of compromise

Key facts for TL-2026-1314

Threat ID
TL-2026-1314
Also known as
Wizard Spider, Trickbot Gang, Conti Team, ITG23
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
Last reviewed
Attribution
Vitaly Kovalev, Trickbot-Conti Syndicate
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
government administration, health, finance, critical infrastructure, energy, water, education, local government, manufacturing, legal, insurance
Target regions
united states of america, united kingdom, European Union, ukraine, Global
Detection rules
9
Indicators of compromise
30

Malware and tooling in US/EU/UK Sanction Vitaly Kovalev ("Stern"), Trickbot/Conti

Malware and tooling: 3am, BitPaymer, Black Basta - S1070, Conti, Diavol - S0659, Karakurt, LockBit, LummaC2, QuantumLocker, Royal Ransom (ELF), Ryuk, Trickbot

How US/EU/UK Sanction Vitaly Kovalev ("Stern"), Trickbot/Conti works

On July 13, 2026 the United States (OFAC), European Union, and United Kingdom jointly sanctioned Vitaly Nikolayevich Kovalev ("Stern"), the CEO-like administrator of the Trickbot/Conti criminal syndicate whose wallets received over $300 million in ransom payments across Trickbot, Conti, Ryuk, Diavol, Karakurt, Royal, 3AM, Quantum, and BitPaymer operations. The same coordinated action designated First VPN Service (1VPNS) and its administrator, bulletproof hosting provider Media Land LLC and its owner/executives, LummaC2 infostealer developers, a GRU Unit 29155 officer and his front company Impuls LLC (linked to the WhisperGate wiper), and pro-Russia hacktivist groups Cyber Army of Russia Reborn (CARR) and Z-Pentest.

On July 13, 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC), the European Union, and the United Kingdom (via the National Crime Agency and Foreign, Commonwealth & Development Office) executed a coordinated sanctions action against Vitaly Nikolayevich Kovalev, identified by German and Anglo-American law enforcement as "Stern," the top administrator of the Trickbot cybercrime syndicate. Investigators describe Kovalev as a CEO-like figure who controlled budgets, hiring, and operational direction across a rebranding chain of ransomware strains that grew out of the original Trickbot banking-trojan infrastructure: Ryuk, Conti, Diavol, Karakurt (a data-extortion-only offshoot), Royal, 3AM, Quantum, and BitPaymer. Blockchain analysis attributes over $300 million in ransom proceeds to cryptocurrency wallets associated with Kovalev, spanning Bitcoin, Ethereum, Litecoin, Zcash, Dash, TRON, Dogecoin, and Solana. Kovalev, also known by the online monikers "Ben" and "Bentley," was first sanctioned by the US and UK on February 9, 2023 alongside six other Trickbot members (Valery Sedletski "Strix", Valentin Karyagin "Globus", Maksim Mikhailov "Baget", Dmitry Pleshevskiy "Iseldor", Mikhail Iskritskiy "Tropa", and Ivan Vakhromeyev "Mushroom"); eleven additional members were designated in a follow-on action, bringing the cumulative Trickbot sanctions tally to 19 individuals by July 2026. The NCA assesses the group extorted at least £27 million from 149 UK victims — including the Scottish Environment Protection Agency, Redcar and Cleveland Council, and Eurofins forensic laboratory — and roughly $180 million globally in 2021 alone.

The July 2026 action folded in Kovalev's supporting criminal ecosystem. First VPN Service (1VPNS) and its administrator Dmytro Rashevskyi were designated for providing anonymization infrastructure whose principal clientele was ransomware operators; European law enforcement had already dismantled 1VPNS's website and back-end infrastructure in May 2026. Yevgeniy Vladimirovich Silayev, a Belarusian national, was sanctioned as a "cryptor" provider — supplying crypting/obfuscation services that shield malware from antivirus and EDR detection. Media Land LLC (also operating as ML.Cloud LLC), a Russian bulletproof hosting provider run by Alexander Alexandrovich Volosovik (aliases "Yalishanda," "Downlow," "Stas_vl") since 2016, was designated along with executives Kirill Zatolokin (payments collection) and Yulia Pankova (legal/finance); Media Land's resilient infrastructure has knowingly hosted LockBit, Evil Corp, and BlackBasta operations and was first sanctioned by OFAC in November 2025. Maksim Evgenevich Voronin ("Daugn0") and Maksim Aleksandrovich Gordienko ("Lummaseller") were designated as developers/distributors of LummaC2, a commercial malware-as-a-service infostealer used to harvest browser credentials, cryptocurrency-wallet data, and system information at scale; a prior multinational takedown of LummaC2 infrastructure (DOJ, Europol, Japan) occurred in May 2025.

The action also carried a state-linked component: Evgeniy Viktorovich Bashev, an officer of Russia's GRU Unit 29155 (Main Directorate of the General Staff), was sanctioned along with his front company Impuls LLC (OOO IMPULS), which the EU says supplied technical/material support — server infrastructure, payments, and cover — for GRU cyberattacks, and which the UK says recruited hackers from Russian universities. Unit 29155 is separately attributed with deploying the WhisperGate wiper against more than 70 Ukrainian government systems in early 2022 ahead of the full-scale invasion, with officers Dmitriy Voronov, Aleksandr Shepelev, and Roman Puntus previously identified as tasking and funding Russian cybercriminals — including Bashev and Sultan Omarov — to extend GRU offensive-cyber capability. Rounding out the action, pro-Russia hacktivist personas Cyber Army of Russia Reborn (CARR, also referred to as Z-Pentest) were re-flagged; CARR/Z-Pentest, active since Russia's 2022 invasion of Ukraine and assessed as GRU-founded/funded/directed, has previously damaged US drinking-water system controls (spilling hundreds of thousands of gallons) and disrupted a Los Angeles meat-processing facility with an ammonia leak; members Yuliya Pankratova and Denis Olegovich Degtyarenko were first sanctioned in July 2024 and face separate US criminal trials in 2026.

Sanctions consequences include asset freezes, global travel bans, and exclusion from the US/EU/UK financial systems; ransom payment to designated persons, including in cryptocurrency, is itself prohibited for US persons under OFAC rules, adding legal exposure for victim organizations and incident-response/insurance firms that facilitate payment to affiliates operating under this syndicate's umbrella.

MITRE ATT&CK techniques used in TL-2026-1314

Credential Access

T1003 OS Credential Dumping; T1555 Credentials from Password Stores

Collection

T1005 Data from Local System; T1560 Archive Collected Data

Lateral Movement

T1021 Remote Services

Defense Evasion

T1027 Obfuscated Files or Information

Discovery

T1046 Network Service Discovery; T1082 System Information Discovery

Privilege Escalation

T1055 Process Injection

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1090 Proxy

Initial Access

T1190 Exploit Public-Facing Application; T1566 Phishing

Impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1657 Financial Theft

Persistence

T1547 Boot or Logon Autostart Execution

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1588 Obtain Capabilities

Reconnaissance

T1591 Gather Victim Org Information

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in US/EU/UK Sanction Vitaly Kovalev ("Stern"), Trickbot/Conti

  • Media Land LLC — Bulletproof hosting infrastructure (ML.Cloud LLC)
    Vulnerable versions: all active infrastructure as of 2026-07-13
  • First VPN Service — 1VPNS anonymization/VPN service
    Vulnerable versions: infrastructure dismantled 2026-05
  • Impuls LLC (OOO IMPULS) — GRU Unit 29155 support infrastructure
    Vulnerable versions: all active infrastructure as of 2026-07-13

Remediation for US/EU/UK Sanction Vitaly Kovalev ("Stern"), Trickbot/Conti

Immediate actions

  • Screen counterparties, insurers, and incident-response/ransom-negotiation vendors against the updated OFAC SDN list before any payment involving this syndicate's affiliates
  • Block network egress and VPN endpoints associated with First VPN Service (1VPNS) infrastructure
  • Review historical netflow/DNS logs for connections to known Media Land LLC / ML.Cloud LLC bulletproof-hosting ASNs and IP ranges
  • Hunt for LummaC2 infostealer indicators (browser credential theft, unusual outbound HTTPS beacons) across endpoint telemetry
  • Audit backup immutability and offline recovery capability given continued Ryuk/Conti-lineage ransomware activity (Royal, 3AM, Quantum, BitPaymer)

Workarounds

  • Treat any ransomware demand referencing Conti, Ryuk, Diavol, Karakurt, Royal, 3AM, Quantum, or BitPaymer as potentially tied to a sanctioned entity and consult legal counsel before considering payment
  • Where 1VPNS or Media Land infrastructure is identified in an intrusion, preserve logs and report to national law enforcement given the active designation

Longer-term hardening

  • Establish a sanctions-compliance workflow that screens ransom-payment requests against OFAC/EU/UK designated-persons lists in real time
  • Deploy EDR/XDR with behavioral detection for credential-theft and ransomware pre-encryption staging activity
  • Segment OT/ICS networks from IT networks to reduce blast radius from hacktivist groups (CARR/Z-Pentest) targeting water and energy sectors
  • Maintain layered email security and user-awareness training against Trickbot-lineage phishing loaders
  • Coordinate with national CERTs/law enforcement on victim notification if legacy Trickbot/Conti/Ryuk infections are discovered

Timeline of US/EU/UK Sanction Vitaly Kovalev ("Stern"), Trickbot/Conti

  • Alexander Volosovik ('Yalishanda') establishes Media Land LLC, which grows into a bulletproof hosting provider for LockBit, Evil Corp, and BlackBasta ransomware operations.
  • GRU Unit 29155, later linked to sanctioned officer Evgeniy Bashev and front company Impuls LLC, deploys the WhisperGate wiper against more than 70 Ukrainian government systems ahead of Russia's full-scale invasion.
  • US and UK jointly sanction seven Trickbot members, including Vitaly Kovalev under aliases 'Ben' and 'Bentley', for extorting at least £27 million from 149 UK victims.
  • US and UK sanction 11 additional Trickbot/Conti members, bringing the group's cumulative sanctioned-member count toward 19.
  • US Treasury sanctions CARR/Z-Pentest members Yuliya Pankratova and Denis Olegovich Degtyarenko for cyberattacks on US critical infrastructure, including water systems and a meat-processing facility.
  • DOJ, Europol, and Japanese law enforcement coordinate a takedown of LummaC2 infostealer infrastructure; CISA publishes advisory AA25-141B.
  • OFAC first sanctions Media Land LLC as a bulletproof hosting provider supporting ransomware operations.
  • European law enforcement dismantles First VPN Service (1VPNS) website and back-end infrastructure.
  • US (OFAC), EU, and UK jointly sanction Vitaly Kovalev ('Stern'), 1VPNS and administrator Dmytro Rashevskyi, cryptor provider Yevgeniy Silayev, Media Land executives (Volosovik, Zatolokin, Pankova), LummaC2 developers Voronin and Gordienko, GRU Unit 29155 officer Evgeniy Bashev and Impuls LLC, and hacktivist groups CARR/Z-Pentest.
  • TL-Intel Harness ingests and documents the July 13, 2026 coordinated sanctions action via Chainalysis, Treasury, NCA, and press reporting.

Sources cited for US/EU/UK Sanction Vitaly Kovalev ("Stern"), Trickbot/Conti

Detection coverage for TL-2026-1314

As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1314 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
30 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats