US sanctions VPN, malware providers for enabling ransomware attacks
The US Treasury Department's Office of Foreign Assets Control (OFAC) has sanctioned two individuals and one entity for enabling ransomware attacks against US organizations. The sanctions target First VPN Service (1VPNS) and its administrator, Dmytro Rashevskyi, as well as…
Intelligence analysis by Llama

The US has sanctioned two individuals and one entity for enabling ransomware attacks against US organizations. The sanctions target First VPN Service (1VPNS) and its administrator, Dmytro Rashevskyi, as well as Belarusian national Yegeniy Vladimirovich Silayev, who sells cryptors used by ransomware groups.
Imagine you're playing a game where you have to protect your virtual castle from bad guys. The bad guys are using special tools to hide their identities and make it harder for you to catch them. The US government is trying to stop these bad guys by taking away their tools and making it harder for them to hide.
Analysis
A $60B Vote of Confidence
The US Treasury Department's Office of Foreign Assets Control (OFAC) has taken a significant step in combating cybercrime by sanctioning two individuals and one entity for enabling ransomware attacks against US organizations. The sanctions target First VPN Service (1VPNS) and its administrator, Dmytro Rashevskyi, as well as Belarusian national Yegeniy Vladimirovich Silayev, who sells cryptors used by ransomware groups.
The investigation into 1VPNS began in December 2021, with law enforcement officers infiltrating the VPN's infrastructure and collecting its user database before it was dismantled. Throughout the joint operation, the authorities seized 33 servers linked to 1VPNs across 27 countries, arrested its administrator, and exposed thousands of users associated with ransomware, fraud, and other malicious activity worldwide.
The sanctions come after European law enforcement took down 1VPNS's website and infrastructure in May with support from the FBI's Boston Field Office, as part of a joint action dubbed 'Operation Saffron' led by French and Dutch authorities. The action was coordinated with the United Kingdom's Foreign, Commonwealth & Development Office.
Under these sanctions, all property of the designated individuals and entities within US jurisdiction is blocked, while US persons and businesses are barred from transactions involving them. This is a significant step in dismantling the broader networks that sustain cybercriminal activity worldwide.
Why Cursor?
The sanctions are significant because they target not just ransomware operators but the service providers and tool suppliers who make their attacks possible. This is a major step in dismantling the broader networks that sustain cybercriminal activity worldwide.
The US has been working closely with its international partners to combat cybercrime, and this action is a testament to the effectiveness of this collaboration. The sanctions send a clear message to cybercriminals that the US will not tolerate their activities and will take all necessary steps to protect its citizens and businesses.
The Road Ahead
The sanctions are a significant step in the right direction, but there is still much work to be done. The US must continue to work with its international partners to combat cybercrime and dismantle the broader networks that sustain it.
The sanctions also highlight the importance of cybersecurity awareness and education. Individuals and businesses must be aware of the risks associated with cybercrime and take all necessary steps to protect themselves. This includes using secure VPNs, keeping software up to date, and being cautious when clicking on links or downloading attachments.
Key points
- The US Treasury Department's Office of Foreign Assets Control (OFAC) has sanctioned two individuals and one entity for enabling ransomware attacks against US organizations.
- The sanctions target First VPN Service (1VPNS) and its administrator, Dmytro Rashevskyi, as well as Belarusian national Yegeniy Vladimirovich Silayev, who sells cryptors used by ransomware groups.
- The investigation into 1VPNS began in December 2021, with law enforcement officers infiltrating the VPN's infrastructure and collecting its user database before it was dismantled.
- The sanctions come after European law enforcement took down 1VPNS's website and infrastructure in May with support from the FBI's Boston Field Office, as part of a joint action dubbed 'Operation Saffron' led by French and Dutch authorities.
The sanctions are a significant step in the right direction, and the US must continue to work with its international partners to combat cybercrime and dismantle the broader networks that sustain it. This will help to protect US citizens and businesses from the risks associated with cybercrime.
The sanctions may not be enough to stop the cybercriminals, and they may find ways to circumvent the restrictions. Additionally, the sanctions may have unintended consequences, such as driving the cybercriminals underground and making it harder to track them.



