US Treasury (OFAC) and UK Sanction First VPN Service (1VPNS), Administrator Dmytro Rashevskyi, and Cryptor Seller Yevgeniy Silayev for Enabling Anubis and Sinobi Ransomware Operations
US Treasury (OFAC) and UK Sanction First VPN Service (TL-2026-1316), also tracked as OFAC 1VPNS Designation, is a high-severity ransomware operation, first published 2026-07-14. It is attributed to Anubis Ransomware with high confidence, affects SonicWall SonicOS SSL-VPN, references 1 CVE (CVE-2024-53704), maps to 29 MITRE ATT&CK techniques (T1005, T1021, T1027), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-1316
- Threat ID
- TL-2026-1316
- Also known as
- OFAC 1VPNS Designation, Treasury Ransomware Enabler Sanctions July 2026
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-07-14
- Last reviewed
- 2026-07-14
- Attribution
- Anubis Ransomware
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- financial services, health, government administration, manufacturing, construction, education, professional services
- Target regions
- united states of america, united kingdom, Global
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in US Treasury (OFAC) and UK Sanction First VPN Service
Malware and tooling: AgendaCrypt, anubis, sinobi, 1VPNS Jabber messaging service
OFAC, jointly with the UK's FCDO, designated First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev under E.O. 13694 (as amended by E.O. 14390) for materially supporting Anubis, Sinobi, and Qilin ransomware operations against US businesses, hospitals, financial-services firms, and municipal governments. The designation follows a May 2026 Europol-led takedown of 1VPNS infrastructure, supported by the FBI's Boston Field Office.
How US Treasury (OFAC) and UK Sanction First VPN Service works
On July 13, 2026, the US Department of the Treasury's Office of Foreign Assets Control (OFAC), acting jointly with the United Kingdom's Foreign, Commonwealth & Development Office (FCDO), announced sanctions against three parties that provided material technical and financial support to ransomware operators attacking American organizations: First VPN Service (1VPNS), a bulletproof-style VPN provider; its alleged administrator, Ukrainian national Dmytro Rashevskyi; and Yevgeniy Vladimirovich Silayev, a Belarusian national who sold "cryptor" (malware-obfuscation) services to ransomware affiliates.
1VPNS has operated since 2014, advertising on cybercriminal forums (including Exploit and XSS) that it retains no logs of subscriber identity or activity and will not cooperate with law-enforcement requests. It also ran a peer-to-peer Jabber messaging service used by criminal customers. Ransomware operators used 1VPNS infrastructure to anonymize command-and-control traffic, conceal the origin of intrusions, stage and deploy ransomware payloads, and manage exfiltrated victim data during double-extortion negotiations. Rashevskyi is alleged to have used false identities -- "Maksim Sorin" and "Roman Chabanenko" -- to procure server and hosting infrastructure from providers that would otherwise have refused service due to prior abuse complaints.
Blockchain analysis (cited by OFAC and TRM Labs) ties at least three ransomware operations to direct payments to 1VPNS: the Anubis ransomware group sent a total of $715 in two tranches (December 13, 2025 and March 15-16, 2026); Qilin ransomware sent $120 on January 11, 2026; and Sinobi Group sent $58 on February 8, 2026. OFAC designated five cryptocurrency addresses (spanning Bitcoin, Ethereum, Litecoin, and Tron) tied to 1VPNS, all traced to the high-risk exchange Cryptomus, plus fifteen additional addresses (Bitcoin, Ethereum, Tron, Litecoin, Dogecoin, Dash, Zcash, Solana) tied personally to Rashevskyi.
Silayev's cryptor service is used by ransomware affiliates to repackage malware binaries so that they evade signature- and heuristic-based antivirus/EDR detection prior to deployment -- a widely used commodity service in the ransomware-as-a-service (RaaS) supply chain that materially lowers the technical barrier for affiliates to execute successful intrusions.
The sanctions action follows a May 2026 international law-enforcement operation, led by European authorities with support from the FBI's Boston Field Office, that took down the 1VPNS website and seized associated servers and domains, and arrested the alleged administrator. The July 2026 OFAC/UK designation freezes any US-touching assets of the designated parties, prohibits US persons from transacting with them, and is intended to disrupt the anonymization and obfuscation supply chain that underpins ransomware operations including Anubis and Sinobi -- both of which have caused significant losses to US critical infrastructure, healthcare, and municipal-government victims.
Anubis (active since ~November 2024, RaaS subscription priced around $723) is a Go-based ransomware notable for an integrated wiper mode (`/WIPEMODE`) that irreversibly zeroes out file contents after encryption, defeating recovery even if a ransom is paid; it encrypts using the Elliptic Curve Integrated Encryption Scheme (ECIES) and has targeted healthcare, construction, professional-services, and government victims via spear-phishing.
Sinobi (emerged mid-2025, RaaS subscription priced around $58) is assessed as a probable rebrand of the Lynx/INC ransomware lineage (63.2% function similarity to Lynx, 55.9% to INC Ransom) and has claimed 274+ victims across 27 countries as of July 2026, concentrated in US mid-market manufacturing, construction, and healthcare organizations. Sinobi affiliates have gained initial access via exploitation of CVE-2024-53704 (SonicWall SSLVPN improper authentication / session-cookie handling bypass), followed by AnyDesk deployment, Active Directory and credential-store enumeration, RClone-based cloud exfiltration, and Curve-25519/AES-128-CTR file encryption appending the `.SINOBI` extension.
MITRE ATT&CK techniques used in TL-2026-1316
Collection
Lateral Movement
T1021 Remote Services; T1570 Lateral Tool Transfer
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Execution
T1059 Command and Scripting Interpreter
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1134 Access Token Manipulation
Command and Control
T1071 Application Layer Protocol; T1090 Proxy
Discovery
T1087 Account Discovery; T1482 Domain Trust Discovery
Credential Access
T1110 Brute Force; T1555 Credentials from Password Stores
Initial Access
T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1566 Phishing
Persistence
command-and-control
Impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery
Resource Development
T1583 Acquire Infrastructure; T1588 Obtain Capabilities
defense-impairment
Affected products and versions in US Treasury (OFAC) and UK Sanction First VPN Service
- SonicWall — SonicOS SSL-VPN
Vulnerable versions: Gen 7 SonicOS prior to patched builds
Fixed in: SonicOS versions with CVE-2024-53704 patch applied - Multiple — US businesses, hospitals, financial-services firms, and municipal governments (Anubis/Sinobi victims)
Vulnerable versions: N/A - organizational targeting, not software version
Fixed in: N/A
Remediation for US Treasury (OFAC) and UK Sanction First VPN Service
Patches
- SonicWall SSL-VPN: apply vendor patch for CVE-2024-53704
Immediate actions
- Block outbound/inbound traffic to known 1VPNS-associated IP ranges and Jabber messaging infrastructure at the perimeter
- Patch SonicWall SSL-VPN appliances against CVE-2024-53704 (session-cookie authentication bypass) immediately -- this is the confirmed Sinobi initial-access vector
- Enforce MFA on all SSL-VPN and remote-access services
- Restrict or monitor RClone, AnyDesk, and other legitimate remote-access/exfiltration tool execution via application allowlisting
- Ensure offline, immutable backups exist given Anubis's destructive wiper mode makes ransom payment non-recoverable
Workarounds
- Disable SonicWall SSLVPN externally-facing access where patching is not immediately possible
- Rotate all VPN session cookies/tokens following any suspected SonicWall compromise
Longer-term hardening
- Deploy EDR with behavioral detection tuned for LOLBin abuse, credential-store access (T1555), and shadow-copy deletion
- Implement network segmentation to limit lateral movement via SMB/RDP/WinRM
- Establish a threat-intel feed subscription for updated 1VPNS/Cryptomus-linked infrastructure and cryptocurrency addresses
- Conduct regular tabletop exercises for double-extortion ransomware scenarios including data-wipe contingencies
CVEs associated with US Treasury (OFAC) and UK Sanction First VPN Service
Weaknesses (CWE) in US Treasury (OFAC) and UK Sanction First VPN Service
CWE-287, CWE-306
Timeline of US Treasury (OFAC) and UK Sanction First VPN Service
- First VPN Service (1VPNS) begins advertising anonymized, no-log VPN and Jabber messaging infrastructure on cybercriminal forums Exploit and XSS.
- Anubis ransomware-as-a-service first identified in the wild, initially branded 'Sphinx', written in Go with ECIES encryption.
- Sinobi ransomware operation emerges as an assessed rebrand of the Lynx/INC ransomware lineage, adopting a closed hybrid RaaS affiliate model.
- Anubis operators add an integrated wiper capability (/WIPEMODE) that irreversibly zeroes file contents post-encryption, eliminating recovery even after ransom payment.
- Anubis ransomware group sends first tranche of cryptocurrency payment to First VPN Service infrastructure.
- Qilin ransomware group sends $120 in cryptocurrency to First VPN Service.
- Sinobi Group sends $58 in cryptocurrency to First VPN Service.
- Anubis ransomware group sends second tranche of cryptocurrency payment (through March 16, 2026) to First VPN Service, bringing its total to $715.
- European law-enforcement authorities, supported by the FBI's Boston Field Office, take down the 1VPNS website, seize associated servers and domains, and arrest the alleged administrator.
- US Department of State issues a coordinated statement on the international sanctions action targeting ransomware enablers.
- OFAC, acting jointly with the UK's FCDO, designates First VPN Service (1VPNS), Dmytro Rashevskyi, and Yevgeniy Vladimirovich Silayev under Executive Order 13694 (as amended by E.O. 14390), freezing US-touching assets and prohibiting transactions.
- CyberScoop, BleepingComputer, The Record, The Hacker News, and other outlets report on the sanctions and their ties to Anubis and Sinobi ransomware operations.
Sources cited for US Treasury (OFAC) and UK Sanction First VPN Service
- US sanctions first VPN service tied to ransomware operations
- Treasury Sanctions Malware and Infrastructure Providers Supporting Ransomware Attacks Against Americans
- OFAC Sanctions FirstVPN and Ransomware Enablers Behind Attacks on Americans
- U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
- US sanctions VPN, malware providers for enabling ransomware attacks
- VPN service favored by ransomware groups is sanctioned by US
- Sanctioning Ransomware Enablers in Coordinated International Action
- Anubis: A Closer Look at an Emerging Ransomware with Built-in Wiper
- Anubis: A Deep Dive into the Emerging Ransomware
- Anubis Ransomware Adds Destructive Wiper Capability
- Dark Web Profile: Anubis Ransomware
- Sinobi Ransomware Explained: Intrusion Methods, Encryption, and Incident Response
- Dark Web Profile: Sinobi Ransomware
- Threat Actor Profile Sinobi
- sinobi-ransomware-cyber-threat-profile (TTPs, IoCs, IoAs)
Threats related to US Treasury (OFAC) and UK Sanction First VPN Service
- Sinobi Ransomware: Curve-25519/AES-128-CTR Encryption with Shadow Copy and Backup Destruction (Lynx/INC Rebrand)
- 2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)
- Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates 1TB from Coca-Cola's Fairlife Dairy Subsidiary, Halting US Production
- Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2 (CVE-2025-5777) Exploitation Wave
- City of Coweta, Oklahoma Hit by Anubis Ransomware Attack
- GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334 Organizations
Detection coverage for TL-2026-1316
As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1316 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.