US Treasury (OFAC) and UK Sanction First VPN Service (1VPNS), Administrator Dmytro Rashevskyi, and Cryptor Seller Yevgeniy Silayev for Enabling Anubis and Sinobi Ransomware Operations — Threadlinqs Intelligence
As of 2026-07-14, US Treasury (OFAC) and UK Sanction First VPN Service (1VPNS), Administrator Dmytro Rashevskyi, and Cryptor Seller Yevgeniy Silayev for Enabling Anubis and Sinobi Ransomware Operations is a high-severity ransomware threat attributed to Anubis Ransomware, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1316 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: Anubis Ransomware · FINANCIAL
OFAC, jointly with the UK's FCDO, designated First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev under E.O. 13694 (as amended
On July 13, 2026, the US Department of the Treasury's Office of Foreign Assets Control (OFAC), acting jointly with the United Kingdom's Foreign, Commonwealth & Development Office (FCDO), announced sanctions against three parties that provided material technical and financial support to ransomware operators attacking American organizations: First VPN Service (1VPNS), a bulletproof-style VPN provider; its alleged administrator, Ukrainian national Dmytro Rashevskyi; and Yevgeniy Vladimirovich Silayev, a Belarusian national who sold "cryptor" (malware-obfuscation) services to ransomware affiliates.
1VPNS has operated since 2014, advertising on cybercriminal forums (including Exploit and XSS) that it retains no logs of subscriber identity or activity and will not cooperate with law-enforcement requests. It also ran a peer-to-peer Jabber messaging service used by criminal customers. Ransomware operators used 1VPNS infrastructure to anonymize command-and-control traffic, conceal the origin of intrusions, stage and deploy ransomware payloads, and manage exfiltrated victim data during double-extortion negotiations. Rashevskyi is alleged to have used false identities -- "Maksim Sorin" and "Roman Chabanenko" -- to procure server and hosting infrastructure from providers that would otherwise have refused service due to prior abuse complaints.
Blockchain analysis (cited by OFAC and TRM Labs) ties at least three ransomware operations to direct payments to 1VPNS: the Anubis ransomware group sent a total of $715 in two tranches (December 13, 2025 and March 15-16, 2026); Qilin ransomware sent $120 on January 11, 2026; and Sinobi Group sent $58 on February 8, 2026. OFAC designated five cryptocurrency addresses (spanning Bitcoin, Ethereum, Litecoin, and Tron) tied to 1VPNS, all traced to the high-risk exchange Cryptomus, plus fifteen additional addresses (Bitcoin, Ethereum, Tron, Litecoin, Dogecoin, Dash, Zcash, Solana) tied personally to Rashevskyi.
Silayev's cryptor service is used by ransomware affiliates to repackage malware binaries so that they evade signature- and heuristic-based antivirus/EDR detection prior to deployment -- a widely used commodity service in the ransomware-as-a-service (RaaS) supply chain that materially lowers the technical barrier for affiliates to execute successful intrusions.
The sanctions action follows a May 2026 international law-enforcement operation, led by European authorities with support from the FBI's Boston Field Office, that took down the 1VPNS website and seized associated servers and domains, and arrested the alleged administrator. The July 2026 OFAC/UK designation freezes any US-touching assets of the designated parties, prohibits US persons from transacting with them, and is intended to disrupt the anonymization and obfuscation supply chain that underpins ransomware operations including Anubis and Sinobi -- both of which have caused significant losses to US critical infrastructure, healthcare, and municipal-government victims.
Anubis (active since ~November 2024, RaaS subscription priced around $723) is a Go-based ransomware notable for an integrated wiper mode (`/WIPEMODE`) that irreversibly zeroes out file contents after encryption, defeating recovery even if a ransom is paid; it encrypts using the Elliptic Curve Integrated Encryption Scheme (ECIES) and has targeted healthcare, construction, professional-services, and government victims via spear-phishing.
Sinobi (emerged mid-2025, RaaS subscription priced around $58) is assessed as a probable rebrand of the Lynx/INC ransomware lineage (63.2% function similarity to Lynx, 55.9% to INC Ransom) and has claimed 274+ victims across 27 countries as of July 2026, concentrated in US mid-market manufacturing, construction, and healthcare organizations. Sinobi affiliates have gained initial access via exploitation of CVE-2024-53704 (SonicWall SSLVPN improper authentication / session-cookie handling bypass), followed by AnyDesk deployment, Active Direct
Weaknesses (CWE)
CWE-287, CWE-306
Target sectors: financial services, health, government administration, manufacturing, construction, education, professional services
Target regions: united states of america, united kingdom, Global
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, CVE-2024-53704, T1190, T1566, T1133, T1059, T1136, T1219, T1134, T1068, T1562, T1027