US/EU/UK Sanction Vitaly Kovalev ("Stern"), Trickbot/Conti Administrator Linked to $300M+ in Ransomware Payments — Threadlinqs Intelligence
As of 2026-07-14, US/EU/UK Sanction Vitaly Kovalev ("Stern"), Trickbot/Conti Administrator Linked to $300M+ in Ransomware Payments is a high-severity ransomware threat attributed to Vitaly Kovalev (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-1314 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: Vitaly Kovalev · Russia · FINANCIAL
On July 13, 2026 the United States (OFAC), European Union, and United Kingdom jointly sanctioned Vitaly Nikolayevich Kovalev ("Stern"), the CEO-like administrator of the Trickbot/Conti criminal
On July 13, 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC), the European Union, and the United Kingdom (via the National Crime Agency and Foreign, Commonwealth & Development Office) executed a coordinated sanctions action against Vitaly Nikolayevich Kovalev, identified by German and Anglo-American law enforcement as "Stern," the top administrator of the Trickbot cybercrime syndicate. Investigators describe Kovalev as a CEO-like figure who controlled budgets, hiring, and operational direction across a rebranding chain of ransomware strains that grew out of the original Trickbot banking-trojan infrastructure: Ryuk, Conti, Diavol, Karakurt (a data-extortion-only offshoot), Royal, 3AM, Quantum, and BitPaymer. Blockchain analysis attributes over $300 million in ransom proceeds to cryptocurrency wallets associated with Kovalev, spanning Bitcoin, Ethereum, Litecoin, Zcash, Dash, TRON, Dogecoin, and Solana. Kovalev, also known by the online monikers "Ben" and "Bentley," was first sanctioned by the US and UK on February 9, 2023 alongside six other Trickbot members (Valery Sedletski "Strix", Valentin Karyagin "Globus", Maksim Mikhailov "Baget", Dmitry Pleshevskiy "Iseldor", Mikhail Iskritskiy "Tropa", and Ivan Vakhromeyev "Mushroom"); eleven additional members were designated in a follow-on action, bringing the cumulative Trickbot sanctions tally to 19 individuals by July 2026. The NCA assesses the group extorted at least £27 million from 149 UK victims — including the Scottish Environment Protection Agency, Redcar and Cleveland Council, and Eurofins forensic laboratory — and roughly $180 million globally in 2021 alone.
The July 2026 action folded in Kovalev's supporting criminal ecosystem. First VPN Service (1VPNS) and its administrator Dmytro Rashevskyi were designated for providing anonymization infrastructure whose principal clientele was ransomware operators; European law enforcement had already dismantled 1VPNS's website and back-end infrastructure in May 2026. Yevgeniy Vladimirovich Silayev, a Belarusian national, was sanctioned as a "cryptor" provider — supplying crypting/obfuscation services that shield malware from antivirus and EDR detection. Media Land LLC (also operating as ML.Cloud LLC), a Russian bulletproof hosting provider run by Alexander Alexandrovich Volosovik (aliases "Yalishanda," "Downlow," "Stas_vl") since 2016, was designated along with executives Kirill Zatolokin (payments collection) and Yulia Pankova (legal/finance); Media Land's resilient infrastructure has knowingly hosted LockBit, Evil Corp, and BlackBasta operations and was first sanctioned by OFAC in November 2025. Maksim Evgenevich Voronin ("Daugn0") and Maksim Aleksandrovich Gordienko ("Lummaseller") were designated as developers/distributors of LummaC2, a commercial malware-as-a-service infostealer used to harvest browser credentials, cryptocurrency-wallet data, and system information at scale; a prior multinational takedown of LummaC2 infrastructure (DOJ, Europol, Japan) occurred in May 2025.
The action also carried a state-linked component: Evgeniy Viktorovich Bashev, an officer of Russia's GRU Unit 29155 (Main Directorate of the General Staff), was sanctioned along with his front company Impuls LLC (OOO IMPULS), which the EU says supplied technical/material support — server infrastructure, payments, and cover — for GRU cyberattacks, and which the UK says recruited hackers from Russian universities. Unit 29155 is separately attributed with deploying the WhisperGate wiper against more than 70 Ukrainian government systems in early 2022 ahead of the full-scale invasion, with officers Dmitriy Voronov, Aleksandr Shepelev, and Roman Puntus previously identified as tasking and funding Russian cybercriminals — including Bashev and Sultan Omarov — to extend GRU offensive-cyber capability. Rounding out the action, pro-Russia hacktivist personas Cyber Army of Russia Reborn (CARR, also referred to as Z-Pentest) were re-fla
Target sectors: government administration, health, finance, critical infrastructure, energy, water, education, local government, manufacturing, legal, insurance
Target regions: united states of america, united kingdom, European Union, ukraine, Global
Related threats
- US Treasury (OFAC) and UK Sanction First VPN Service (1VPNS), Administrator Dmytro Rashevskyi, and Cryptor Seller Yevgeniy Silayev for Enabling Anubis and Sinobi Ransomware Operations
- US Indicts Alleged Operators of Media Land Bulletproof Hosting Service Used by LockBit, BlackSuit, and Play Ransomware
- Russian Bulletproof Hosting Operators Indicted: Media Land / ML.Cloud Facilitated $62M+ in Ransomware, Phishing, and Fraud
- Armenian National Karen Vardanyan Pleads Guilty to Ryuk Ransomware Conspiracy (District of Oregon)
- TrickBot Banking Trojan (Anchor_DNS) Uses DNS Tunneling Over westurn.in for Covert C2
- ReHub: Russian-Language Cybercrime Marketplace Sponsoring DragonForce, LockBit, CHAOS, Anubis, The Gentlemen, and DevMan Ransomware Affiliate Programs
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1591, T1583, T1584, T1588, T1566, T1190, T1204, T1059, T1547, T1055