# US/EU/UK Sanction Vitaly Kovalev ("Stern"), Trickbot/Conti Administrator Linked to $300M+ in Ransomware Payments

> On July 13, 2026 the United States (OFAC), European Union, and United Kingdom jointly sanctioned Vitaly Nikolayevich Kovalev ("Stern"), the CEO-like administrator of the Trickbot/Conti criminal syndicate whose wallets received over $300 million in ransom payments across Trickbot, Conti, Ryuk, Diavol, Karakurt, Royal, 3AM, Quantum, and BitPaymer operations. The same coordinated action designated First VPN Service (1VPNS) and its administrator, bulletproof hosting provider Media Land LLC and its owner/executives, LummaC2 infostealer developers, a GRU Unit 29155 officer and his front company Impuls LLC (linked to the WhisperGate wiper), and pro-Russia hacktivist groups Cyber Army of Russia Reborn (CARR) and Z-Pentest.

- **Published:** 2026-07-14T00:00:00Z
- **Last reviewed:** 2026-07-14T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1314
- **ID:** TL-2026-1314
- **Severity:** HIGH
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Actor:** Vitaly Kovalev (Russia)
- **Detections:** 9 · **IOCs:** 30 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On July 13, 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC), the European Union, and the United Kingdom (via the National Crime Agency and Foreign, Commonwealth & Development Office) executed a coordinated sanctions action against Vitaly Nikolayevich Kovalev, identified by German and Anglo-American law enforcement as "Stern," the top administrator of the Trickbot cybercrime syndicate. Investigators describe Kovalev as a CEO-like figure who controlled budgets, hiring, and operational direction across a rebranding chain of ransomware strains that grew out of the original Trickbot banking-trojan infrastructure: Ryuk, Conti, Diavol, Karakurt (a data-extortion-only offshoot), Royal, 3AM, Quantum, and BitPaymer. Blockchain analysis attributes over $300 million in ransom proceeds to cryptocurrency wallets associated with Kovalev, spanning Bitcoin, Ethereum, Litecoin, Zcash, Dash, TRON, Dogecoin, and Solana. Kovalev, also known by the online monikers "Ben" and "Bentley," was first sanctioned by the US and UK on February 9, 2023 alongside six other Trickbot members (Valery Sedletski "Strix", Valentin Karyagin "Globus", Maksim Mikhailov "Baget", Dmitry Pleshevskiy "Iseldor", Mikhail Iskritskiy "Tropa", and Ivan Vakhromeyev "Mushroom"); eleven additional members were designated in a follow-on action, bringing the cumulative Trickbot sanctions tally to 19 individuals by July 2026. The NCA assesses the group extorted at least £27 million from 149 UK victims — including the Scottish Environment Protection Agency, Redcar and Cleveland Council, and Eurofins forensic laboratory — and roughly $180 million globally in 2021 alone.

The July 2026 action folded in Kovalev's supporting criminal ecosystem. First VPN Service (1VPNS) and its administrator Dmytro Rashevskyi were designated for providing anonymization infrastructure whose principal clientele was ransomware operators; European law enforcement had already dismantled 1VPNS's website and back-end infrastructure in May 2026. Yevgeniy Vladimirovich Silayev, a Belarusian national, was sanctioned as a "cryptor" provider — supplying crypting/obfuscation services that shield malware from antivirus and EDR detection. Media Land LLC (also operating as ML.Cloud LLC), a Russian bulletproof hosting provider run by Alexander Alexandrovich Volosovik (aliases "Yalishanda," "Downlow," "Stas_vl") since 2016, was designated along with executives Kirill Zatolokin (payments collection) and Yulia Pankova (legal/finance); Media Land's resilient infrastructure has knowingly hosted LockBit, Evil Corp, and BlackBasta operations and was first sanctioned by OFAC in November 2025. Maksim Evgenevich Voronin ("Daugn0") and Maksim Aleksandrovich Gordienko ("Lummaseller") were designated as developers/distributors of LummaC2, a commercial malware-as-a-service infostealer used to harvest browser credentials, cryptocurrency-wallet data, and system information at scale; a prior multinational takedown of LummaC2 infrastructure (DOJ, Europol, Japan) occurred in May 2025.

The action also carried a state-linked component: Evgeniy Viktorovich Bashev, an officer of Russia's GRU Unit 29155 (Main Directorate of the General Staff), was sanctioned along with his front company Impuls LLC (OOO IMPULS), which the EU says supplied technical/material support — server infrastructure, payments, and cover — for GRU cyberattacks, and which the UK says recruited hackers from Russian universities. Unit 29155 is separately attributed with deploying the WhisperGate wiper against more than 70 Ukrainian government systems in early 2022 ahead of the full-scale invasion, with officers Dmitriy Voronov, Aleksandr Shepelev, and Roman Puntus previously identified as tasking and funding Russian cybercriminals — including Bashev and Sultan Omarov — to extend GRU offensive-cyber capability. Rounding out the action, pro-Russia hacktivist personas Cyber Army of Russia Reborn (CARR, also referred to as Z-Pentest) were re-flagged; CARR/Z-Pentest, active since Russia's 2022 invasion of Ukraine and assessed as GRU-founded/funded/directed, has previously damaged US drinking-water system controls (spilling hundreds of thousands of gallons) and disrupted a Los Angeles meat-processing facility with an ammonia leak; members Yuliya Pankratova and Denis Olegovich Degtyarenko were first sanctioned in July 2024 and face separate US criminal trials in 2026.

Sanctions consequences include asset freezes, global travel bans, and exclusion from the US/EU/UK financial systems; ransom payment to designated persons, including in cryptocurrency, is itself prohibited for US persons under OFAC rules, adding legal exposure for victim organizations and incident-response/insurance firms that facilitate payment to affiliates operating under this syndicate's umbrella.

## MITRE ATT&CK

- T1591 Gather Victim Org Information
- T1583 Acquire Infrastructure
- T1584 Compromise Infrastructure
- T1588 Obtain Capabilities
- T1566 Phishing
- T1190 Exploit Public-Facing Application
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1547 Boot or Logon Autostart Execution
- T1055 Process Injection
- T1027 Obfuscated Files or Information
- T1685 Disable or Modify Tools
- T1555 Credentials from Password Stores
- T1003 OS Credential Dumping
- T1082 System Information Discovery
- T1046 Network Service Discovery
- T1021 Remote Services
- T1005 Data from Local System
- T1560 Archive Collected Data
- T1071 Application Layer Protocol
- T1090 Proxy
- T1567 Exfiltration Over Web Service
- T1486 Data Encrypted for Impact
- T1485 Data Destruction
- T1657 Financial Theft

## Sources

- [Cyber Sanctions: Trickbot Administrator - July 2026](https://www.chainalysis.com/blog/cyber-sanctions-trickbot-administrator-july-2026/)
- [United States and United Kingdom Sanction Additional Members of the Russia-Based Trickbot Cybercrime Gang](https://home.treasury.gov/news/press-releases/jy1714)
- [United States and United Kingdom Sanction Members of Russia-Based Trickbot Cybercrime Gang](https://home.treasury.gov/news/press-releases/jy1256)
- [Ransomware criminals sanctioned in joint UK/US crackdown on international cyber crime](https://www.nationalcrimeagency.gov.uk/news/ransomware-criminals-sanctioned-in-joint-uk-us-crackdown-on-international-cyber-crime)
- [Prolific bulletproof hosting service sanctioned by the UK and allies](https://www.nationalcrimeagency.gov.uk/news/prolific-bulletproof-hosting-service-sanctioned-by-the-uk-and-allies)
- [EU and Britain target Russian intelligence officers over a major cyberspying campaign](https://www.france24.com/en/europe/20260713-eu-and-uk-slap-sanctions-on-russian-spies-and-hackers-over-cyberattacks)
- [EU and UK Jointly Sanction 9 Russians and 4 Firms Over Cyberattacks on Europe and Ukraine](https://www.kyivpost.com/post/80252)
- [Russian bulletproof hosting provider sanctioned over ransomware ties](https://www.bleepingcomputer.com/news/security/us-sanctions-russian-bulletproof-hosting-provider-media-land-over-ransomware-ties/)
- [Cyber Army of Russia Reborn / Z-Pentest](https://rewardsforjustice.net/rewards/carr-and-z-pentest/)
- [Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations](https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-141b)
- [UK and US sanction 11 Russians connected to notorious Trickbot group](https://therecord.media/eleven-russians-trickbot-sanctioned)
- [Profile: GRU cyber and hybrid threat operations](https://www.gov.uk/government/publications/profile-gru-cyber-and-hybrid-threat-operations/profile-gru-cyber-and-hybrid-threat-operations)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1314
