Threat reportRansomwareTL-2026-1314
US/EU/UK Sanction Vitaly Kovalev ("Stern"), Trickbot/Conti Administrator Linked to $300M+ in Ransomware Payments
US/EU/UK Sanction Vitaly Kovalev ("Stern"), Trickbot/Conti (TL-2026-1314), also tracked as Wizard Spider, is a high-severity ransomware operation, first published 2026-07-14. It is attributed to Vitaly Kovalev (Russia) with high confidence, affects Media Land LLC Bulletproof hosting infrastructure (ML.Cloud LLC), maps to 25 MITRE ATT&CK techniques (T1003, T1005, T1021), and is covered by 9 detection rules and 30 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 25MITRE ATT&CK
- Actors
- 2Vitaly Kovalev
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 30Indicators of compromise
Key facts for TL-2026-1314
- Threat ID
- TL-2026-1314
- Also known as
- Wizard Spider, Trickbot Gang, Conti Team, ITG23
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution
- Vitaly Kovalev, Trickbot-Conti Syndicate
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- government administration, health, finance, critical infrastructure, energy, water, education, local government, manufacturing, legal, insurance
- Target regions
- united states of america, united kingdom, European Union, ukraine, Global
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in US/EU/UK Sanction Vitaly Kovalev ("Stern"), Trickbot/Conti
Malware and tooling: 3am, BitPaymer, Black Basta - S1070, Conti, Diavol - S0659, Karakurt, LockBit, LummaC2, QuantumLocker, Royal Ransom (ELF), Ryuk, Trickbot
How US/EU/UK Sanction Vitaly Kovalev ("Stern"), Trickbot/Conti works
On July 13, 2026 the United States (OFAC), European Union, and United Kingdom jointly sanctioned Vitaly Nikolayevich Kovalev ("Stern"), the CEO-like administrator of the Trickbot/Conti criminal syndicate whose wallets received over $300 million in ransom payments across Trickbot, Conti, Ryuk, Diavol, Karakurt, Royal, 3AM, Quantum, and BitPaymer operations. The same coordinated action designated First VPN Service (1VPNS) and its administrator, bulletproof hosting provider Media Land LLC and its owner/executives, LummaC2 infostealer developers, a GRU Unit 29155 officer and his front company Impuls LLC (linked to the WhisperGate wiper), and pro-Russia hacktivist groups Cyber Army of Russia Reborn (CARR) and Z-Pentest.
On July 13, 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC), the European Union, and the United Kingdom (via the National Crime Agency and Foreign, Commonwealth & Development Office) executed a coordinated sanctions action against Vitaly Nikolayevich Kovalev, identified by German and Anglo-American law enforcement as "Stern," the top administrator of the Trickbot cybercrime syndicate. Investigators describe Kovalev as a CEO-like figure who controlled budgets, hiring, and operational direction across a rebranding chain of ransomware strains that grew out of the original Trickbot banking-trojan infrastructure: Ryuk, Conti, Diavol, Karakurt (a data-extortion-only offshoot), Royal, 3AM, Quantum, and BitPaymer. Blockchain analysis attributes over $300 million in ransom proceeds to cryptocurrency wallets associated with Kovalev, spanning Bitcoin, Ethereum, Litecoin, Zcash, Dash, TRON, Dogecoin, and Solana. Kovalev, also known by the online monikers "Ben" and "Bentley," was first sanctioned by the US and UK on February 9, 2023 alongside six other Trickbot members (Valery Sedletski "Strix", Valentin Karyagin "Globus", Maksim Mikhailov "Baget", Dmitry Pleshevskiy "Iseldor", Mikhail Iskritskiy "Tropa", and Ivan Vakhromeyev "Mushroom"); eleven additional members were designated in a follow-on action, bringing the cumulative Trickbot sanctions tally to 19 individuals by July 2026. The NCA assesses the group extorted at least £27 million from 149 UK victims — including the Scottish Environment Protection Agency, Redcar and Cleveland Council, and Eurofins forensic laboratory — and roughly $180 million globally in 2021 alone.
The July 2026 action folded in Kovalev's supporting criminal ecosystem. First VPN Service (1VPNS) and its administrator Dmytro Rashevskyi were designated for providing anonymization infrastructure whose principal clientele was ransomware operators; European law enforcement had already dismantled 1VPNS's website and back-end infrastructure in May 2026. Yevgeniy Vladimirovich Silayev, a Belarusian national, was sanctioned as a "cryptor" provider — supplying crypting/obfuscation services that shield malware from antivirus and EDR detection. Media Land LLC (also operating as ML.Cloud LLC), a Russian bulletproof hosting provider run by Alexander Alexandrovich Volosovik (aliases "Yalishanda," "Downlow," "Stas_vl") since 2016, was designated along with executives Kirill Zatolokin (payments collection) and Yulia Pankova (legal/finance); Media Land's resilient infrastructure has knowingly hosted LockBit, Evil Corp, and BlackBasta operations and was first sanctioned by OFAC in November 2025. Maksim Evgenevich Voronin ("Daugn0") and Maksim Aleksandrovich Gordienko ("Lummaseller") were designated as developers/distributors of LummaC2, a commercial malware-as-a-service infostealer used to harvest browser credentials, cryptocurrency-wallet data, and system information at scale; a prior multinational takedown of LummaC2 infrastructure (DOJ, Europol, Japan) occurred in May 2025.
The action also carried a state-linked component: Evgeniy Viktorovich Bashev, an officer of Russia's GRU Unit 29155 (Main Directorate of the General Staff), was sanctioned along with his front company Impuls LLC (OOO IMPULS), which the EU says supplied technical/material support — server infrastructure, payments, and cover — for GRU cyberattacks, and which the UK says recruited hackers from Russian universities. Unit 29155 is separately attributed with deploying the WhisperGate wiper against more than 70 Ukrainian government systems in early 2022 ahead of the full-scale invasion, with officers Dmitriy Voronov, Aleksandr Shepelev, and Roman Puntus previously identified as tasking and funding Russian cybercriminals — including Bashev and Sultan Omarov — to extend GRU offensive-cyber capability. Rounding out the action, pro-Russia hacktivist personas Cyber Army of Russia Reborn (CARR, also referred to as Z-Pentest) were re-flagged; CARR/Z-Pentest, active since Russia's 2022 invasion of Ukraine and assessed as GRU-founded/funded/directed, has previously damaged US drinking-water system controls (spilling hundreds of thousands of gallons) and disrupted a Los Angeles meat-processing facility with an ammonia leak; members Yuliya Pankratova and Denis Olegovich Degtyarenko were first sanctioned in July 2024 and face separate US criminal trials in 2026.
Sanctions consequences include asset freezes, global travel bans, and exclusion from the US/EU/UK financial systems; ransom payment to designated persons, including in cryptocurrency, is itself prohibited for US persons under OFAC rules, adding legal exposure for victim organizations and incident-response/insurance firms that facilitate payment to affiliates operating under this syndicate's umbrella.
MITRE ATT&CK techniques used in TL-2026-1314
Credential Access
T1003 OS Credential Dumping; T1555 Credentials from Password Stores
Collection
T1005 Data from Local System; T1560 Archive Collected Data
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information
Discovery
T1046 Network Service Discovery; T1082 System Information Discovery
Privilege Escalation
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1090 Proxy
Initial Access
T1190 Exploit Public-Facing Application; T1566 Phishing
Impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1657 Financial Theft
Persistence
T1547 Boot or Logon Autostart Execution
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1588 Obtain Capabilities
Reconnaissance
T1591 Gather Victim Org Information
defense-impairment
Affected products and versions in US/EU/UK Sanction Vitaly Kovalev ("Stern"), Trickbot/Conti
- Media Land LLC — Bulletproof hosting infrastructure (ML.Cloud LLC)
Vulnerable versions: all active infrastructure as of 2026-07-13 - First VPN Service — 1VPNS anonymization/VPN service
Vulnerable versions: infrastructure dismantled 2026-05 - Impuls LLC (OOO IMPULS) — GRU Unit 29155 support infrastructure
Vulnerable versions: all active infrastructure as of 2026-07-13
Remediation for US/EU/UK Sanction Vitaly Kovalev ("Stern"), Trickbot/Conti
Immediate actions
- Screen counterparties, insurers, and incident-response/ransom-negotiation vendors against the updated OFAC SDN list before any payment involving this syndicate's affiliates
- Block network egress and VPN endpoints associated with First VPN Service (1VPNS) infrastructure
- Review historical netflow/DNS logs for connections to known Media Land LLC / ML.Cloud LLC bulletproof-hosting ASNs and IP ranges
- Hunt for LummaC2 infostealer indicators (browser credential theft, unusual outbound HTTPS beacons) across endpoint telemetry
- Audit backup immutability and offline recovery capability given continued Ryuk/Conti-lineage ransomware activity (Royal, 3AM, Quantum, BitPaymer)
Workarounds
- Treat any ransomware demand referencing Conti, Ryuk, Diavol, Karakurt, Royal, 3AM, Quantum, or BitPaymer as potentially tied to a sanctioned entity and consult legal counsel before considering payment
- Where 1VPNS or Media Land infrastructure is identified in an intrusion, preserve logs and report to national law enforcement given the active designation
Longer-term hardening
- Establish a sanctions-compliance workflow that screens ransom-payment requests against OFAC/EU/UK designated-persons lists in real time
- Deploy EDR/XDR with behavioral detection for credential-theft and ransomware pre-encryption staging activity
- Segment OT/ICS networks from IT networks to reduce blast radius from hacktivist groups (CARR/Z-Pentest) targeting water and energy sectors
- Maintain layered email security and user-awareness training against Trickbot-lineage phishing loaders
- Coordinate with national CERTs/law enforcement on victim notification if legacy Trickbot/Conti/Ryuk infections are discovered
Timeline of US/EU/UK Sanction Vitaly Kovalev ("Stern"), Trickbot/Conti
- Alexander Volosovik ('Yalishanda') establishes Media Land LLC, which grows into a bulletproof hosting provider for LockBit, Evil Corp, and BlackBasta ransomware operations.
- GRU Unit 29155, later linked to sanctioned officer Evgeniy Bashev and front company Impuls LLC, deploys the WhisperGate wiper against more than 70 Ukrainian government systems ahead of Russia's full-scale invasion.
- US and UK jointly sanction seven Trickbot members, including Vitaly Kovalev under aliases 'Ben' and 'Bentley', for extorting at least £27 million from 149 UK victims.
- US and UK sanction 11 additional Trickbot/Conti members, bringing the group's cumulative sanctioned-member count toward 19.
- US Treasury sanctions CARR/Z-Pentest members Yuliya Pankratova and Denis Olegovich Degtyarenko for cyberattacks on US critical infrastructure, including water systems and a meat-processing facility.
- DOJ, Europol, and Japanese law enforcement coordinate a takedown of LummaC2 infostealer infrastructure; CISA publishes advisory AA25-141B.
- OFAC first sanctions Media Land LLC as a bulletproof hosting provider supporting ransomware operations.
- European law enforcement dismantles First VPN Service (1VPNS) website and back-end infrastructure.
- US (OFAC), EU, and UK jointly sanction Vitaly Kovalev ('Stern'), 1VPNS and administrator Dmytro Rashevskyi, cryptor provider Yevgeniy Silayev, Media Land executives (Volosovik, Zatolokin, Pankova), LummaC2 developers Voronin and Gordienko, GRU Unit 29155 officer Evgeniy Bashev and Impuls LLC, and hacktivist groups CARR/Z-Pentest.
- TL-Intel Harness ingests and documents the July 13, 2026 coordinated sanctions action via Chainalysis, Treasury, NCA, and press reporting.
Sources cited for US/EU/UK Sanction Vitaly Kovalev ("Stern"), Trickbot/Conti
- Cyber Sanctions: Trickbot Administrator - July 2026
- United States and United Kingdom Sanction Additional Members of the Russia-Based Trickbot Cybercrime Gang
- United States and United Kingdom Sanction Members of Russia-Based Trickbot Cybercrime Gang
- Ransomware criminals sanctioned in joint UK/US crackdown on international cyber crime
- Prolific bulletproof hosting service sanctioned by the UK and allies
- EU and Britain target Russian intelligence officers over a major cyberspying campaign
- EU and UK Jointly Sanction 9 Russians and 4 Firms Over Cyberattacks on Europe and Ukraine
- Russian bulletproof hosting provider sanctioned over ransomware ties
- Cyber Army of Russia Reborn / Z-Pentest
- Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations
- UK and US sanction 11 Russians connected to notorious Trickbot group
- Profile: GRU cyber and hybrid threat operations
Detection coverage for TL-2026-1314
As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1314 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.