US Treasury (OFAC) and UK Sanction First VPN Service (1VPNS), Administrator Dmytro Rashevskyi, and Cryptor Seller Yevgeniy Silayev for Enabling Anubis and Sinobi Ransomware Operations

US Treasury (OFAC) and UK Sanction First VPN Service (TL-2026-1316), also tracked as OFAC 1VPNS Designation, is a high-severity ransomware operation, first published 2026-07-14. It is attributed to Anubis Ransomware with high confidence, affects SonicWall SonicOS SSL-VPN, references 1 CVE (CVE-2024-53704), maps to 29 MITRE ATT&CK techniques (T1005, T1021, T1027), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-1316

Threat ID
TL-2026-1316
Also known as
OFAC 1VPNS Designation, Treasury Ransomware Enabler Sanctions July 2026
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
2026-07-14
Last reviewed
2026-07-14
Attribution
Anubis Ransomware
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
financial services, health, government administration, manufacturing, construction, education, professional services
Target regions
united states of america, united kingdom, Global
Detection rules
9
Indicators of compromise
20

Malware and tooling in US Treasury (OFAC) and UK Sanction First VPN Service

Malware and tooling: AgendaCrypt, anubis, sinobi, 1VPNS Jabber messaging service

OFAC, jointly with the UK's FCDO, designated First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev under E.O. 13694 (as amended by E.O. 14390) for materially supporting Anubis, Sinobi, and Qilin ransomware operations against US businesses, hospitals, financial-services firms, and municipal governments. The designation follows a May 2026 Europol-led takedown of 1VPNS infrastructure, supported by the FBI's Boston Field Office.

How US Treasury (OFAC) and UK Sanction First VPN Service works

On July 13, 2026, the US Department of the Treasury's Office of Foreign Assets Control (OFAC), acting jointly with the United Kingdom's Foreign, Commonwealth & Development Office (FCDO), announced sanctions against three parties that provided material technical and financial support to ransomware operators attacking American organizations: First VPN Service (1VPNS), a bulletproof-style VPN provider; its alleged administrator, Ukrainian national Dmytro Rashevskyi; and Yevgeniy Vladimirovich Silayev, a Belarusian national who sold "cryptor" (malware-obfuscation) services to ransomware affiliates.

1VPNS has operated since 2014, advertising on cybercriminal forums (including Exploit and XSS) that it retains no logs of subscriber identity or activity and will not cooperate with law-enforcement requests. It also ran a peer-to-peer Jabber messaging service used by criminal customers. Ransomware operators used 1VPNS infrastructure to anonymize command-and-control traffic, conceal the origin of intrusions, stage and deploy ransomware payloads, and manage exfiltrated victim data during double-extortion negotiations. Rashevskyi is alleged to have used false identities -- "Maksim Sorin" and "Roman Chabanenko" -- to procure server and hosting infrastructure from providers that would otherwise have refused service due to prior abuse complaints.

Blockchain analysis (cited by OFAC and TRM Labs) ties at least three ransomware operations to direct payments to 1VPNS: the Anubis ransomware group sent a total of $715 in two tranches (December 13, 2025 and March 15-16, 2026); Qilin ransomware sent $120 on January 11, 2026; and Sinobi Group sent $58 on February 8, 2026. OFAC designated five cryptocurrency addresses (spanning Bitcoin, Ethereum, Litecoin, and Tron) tied to 1VPNS, all traced to the high-risk exchange Cryptomus, plus fifteen additional addresses (Bitcoin, Ethereum, Tron, Litecoin, Dogecoin, Dash, Zcash, Solana) tied personally to Rashevskyi.

Silayev's cryptor service is used by ransomware affiliates to repackage malware binaries so that they evade signature- and heuristic-based antivirus/EDR detection prior to deployment -- a widely used commodity service in the ransomware-as-a-service (RaaS) supply chain that materially lowers the technical barrier for affiliates to execute successful intrusions.

The sanctions action follows a May 2026 international law-enforcement operation, led by European authorities with support from the FBI's Boston Field Office, that took down the 1VPNS website and seized associated servers and domains, and arrested the alleged administrator. The July 2026 OFAC/UK designation freezes any US-touching assets of the designated parties, prohibits US persons from transacting with them, and is intended to disrupt the anonymization and obfuscation supply chain that underpins ransomware operations including Anubis and Sinobi -- both of which have caused significant losses to US critical infrastructure, healthcare, and municipal-government victims.

Anubis (active since ~November 2024, RaaS subscription priced around $723) is a Go-based ransomware notable for an integrated wiper mode (`/WIPEMODE`) that irreversibly zeroes out file contents after encryption, defeating recovery even if a ransom is paid; it encrypts using the Elliptic Curve Integrated Encryption Scheme (ECIES) and has targeted healthcare, construction, professional-services, and government victims via spear-phishing.

Sinobi (emerged mid-2025, RaaS subscription priced around $58) is assessed as a probable rebrand of the Lynx/INC ransomware lineage (63.2% function similarity to Lynx, 55.9% to INC Ransom) and has claimed 274+ victims across 27 countries as of July 2026, concentrated in US mid-market manufacturing, construction, and healthcare organizations. Sinobi affiliates have gained initial access via exploitation of CVE-2024-53704 (SonicWall SSLVPN improper authentication / session-cookie handling bypass), followed by AnyDesk deployment, Active Directory and credential-store enumeration, RClone-based cloud exfiltration, and Curve-25519/AES-128-CTR file encryption appending the `.SINOBI` extension.

MITRE ATT&CK techniques used in TL-2026-1316

Collection

T1005 Data from Local System

Lateral Movement

T1021 Remote Services; T1570 Lateral Tool Transfer

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Execution

T1059 Command and Scripting Interpreter

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1134 Access Token Manipulation

Command and Control

T1071 Application Layer Protocol; T1090 Proxy

Discovery

T1087 Account Discovery; T1482 Domain Trust Discovery

Credential Access

T1110 Brute Force; T1555 Credentials from Password Stores

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1566 Phishing

Persistence

T1136 Create Account

command-and-control

T1219 Remote Access Tools

Impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery

Resource Development

T1583 Acquire Infrastructure; T1588 Obtain Capabilities

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in US Treasury (OFAC) and UK Sanction First VPN Service

  • SonicWall — SonicOS SSL-VPN
    Vulnerable versions: Gen 7 SonicOS prior to patched builds
    Fixed in: SonicOS versions with CVE-2024-53704 patch applied
  • Multiple — US businesses, hospitals, financial-services firms, and municipal governments (Anubis/Sinobi victims)
    Vulnerable versions: N/A - organizational targeting, not software version
    Fixed in: N/A

Remediation for US Treasury (OFAC) and UK Sanction First VPN Service

Patches

  • SonicWall SSL-VPN: apply vendor patch for CVE-2024-53704

Immediate actions

  • Block outbound/inbound traffic to known 1VPNS-associated IP ranges and Jabber messaging infrastructure at the perimeter
  • Patch SonicWall SSL-VPN appliances against CVE-2024-53704 (session-cookie authentication bypass) immediately -- this is the confirmed Sinobi initial-access vector
  • Enforce MFA on all SSL-VPN and remote-access services
  • Restrict or monitor RClone, AnyDesk, and other legitimate remote-access/exfiltration tool execution via application allowlisting
  • Ensure offline, immutable backups exist given Anubis's destructive wiper mode makes ransom payment non-recoverable

Workarounds

  • Disable SonicWall SSLVPN externally-facing access where patching is not immediately possible
  • Rotate all VPN session cookies/tokens following any suspected SonicWall compromise

Longer-term hardening

  • Deploy EDR with behavioral detection tuned for LOLBin abuse, credential-store access (T1555), and shadow-copy deletion
  • Implement network segmentation to limit lateral movement via SMB/RDP/WinRM
  • Establish a threat-intel feed subscription for updated 1VPNS/Cryptomus-linked infrastructure and cryptocurrency addresses
  • Conduct regular tabletop exercises for double-extortion ransomware scenarios including data-wipe contingencies

CVEs associated with US Treasury (OFAC) and UK Sanction First VPN Service

CVE-2024-53704

Weaknesses (CWE) in US Treasury (OFAC) and UK Sanction First VPN Service

CWE-287, CWE-306

Timeline of US Treasury (OFAC) and UK Sanction First VPN Service

  • First VPN Service (1VPNS) begins advertising anonymized, no-log VPN and Jabber messaging infrastructure on cybercriminal forums Exploit and XSS.
  • Anubis ransomware-as-a-service first identified in the wild, initially branded 'Sphinx', written in Go with ECIES encryption.
  • Sinobi ransomware operation emerges as an assessed rebrand of the Lynx/INC ransomware lineage, adopting a closed hybrid RaaS affiliate model.
  • Anubis operators add an integrated wiper capability (/WIPEMODE) that irreversibly zeroes file contents post-encryption, eliminating recovery even after ransom payment.
  • Anubis ransomware group sends first tranche of cryptocurrency payment to First VPN Service infrastructure.
  • Qilin ransomware group sends $120 in cryptocurrency to First VPN Service.
  • Sinobi Group sends $58 in cryptocurrency to First VPN Service.
  • Anubis ransomware group sends second tranche of cryptocurrency payment (through March 16, 2026) to First VPN Service, bringing its total to $715.
  • European law-enforcement authorities, supported by the FBI's Boston Field Office, take down the 1VPNS website, seize associated servers and domains, and arrest the alleged administrator.
  • US Department of State issues a coordinated statement on the international sanctions action targeting ransomware enablers.
  • OFAC, acting jointly with the UK's FCDO, designates First VPN Service (1VPNS), Dmytro Rashevskyi, and Yevgeniy Vladimirovich Silayev under Executive Order 13694 (as amended by E.O. 14390), freezing US-touching assets and prohibiting transactions.
  • CyberScoop, BleepingComputer, The Record, The Hacker News, and other outlets report on the sanctions and their ties to Anubis and Sinobi ransomware operations.

Sources cited for US Treasury (OFAC) and UK Sanction First VPN Service

Threats related to US Treasury (OFAC) and UK Sanction First VPN Service

Detection coverage for TL-2026-1316

As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1316 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats