news.mlab.sh
Back to the feed
threat-intel

U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support

High
Summary

The U.S. Treasury Department has sanctioned a VPN service provider, First VPN Service (1VPNS), and its administrator, Dmytro Rashevskyi, for enabling ransomware groups to carry out attacks against U.S. companies and institutions. Simultaneously, the U.K. and E.U. have imposed sanctions on Russian individuals and entities, including members of Russia's Main Intelligence Directorate (GRU) and cybercriminals involved in deploying tools like Lumma Stealer, targeting routers and critical infrastructure. This action follows a new FBI advisory highlighting Russian FSB Center 16's exploitation of vulnerable routers to conduct cyber espionage.

The U.S. Treasury Department has designated First VPN Service (1VPNS), a VPN service provider, and its administrator, Dmytro Rashevskyi, for facilitating malicious activities by ransomware groups. The department alleges that 1VPNS was used by these groups to obscure the origins of ransomware attacks, deploy malware, and manage exfiltrated data, resulting in billions of dollars in losses for American businesses and critical infrastructure providers. Rashevskyi has used false identities, including ‘Maksim Sorin’ and ‘Roman Chabanenko,’ to acquire infrastructure from companies hesitant to work with him due to complaints about illegal activity originating from 1VPNS servers.

The actions coincide with the U.K. and E.U. sanctioning Russian cyber networks for their “persistent and increasingly reckless attempts to sow chaos and division across Europe.” These sanctions target 24 individuals and entities behind destructive cyber and hybrid operations, including members of Russia’s Main Intelligence Directorate (GRU) – Vyacheslav Stafeyev, Ivan Senin, and Ivan Kasyanenko – and cybercriminals involved in deploying tools like Lumma Stealer, which collects sensitive information from compromised devices at scale. Russia is said to have used Lumma Stealer’s stolen credentials to conduct cyber espionage operations globally to support the Kremlin’s objectives.

Furthermore, the U.S. Federal Bureau of Investigation (FBI) has issued an advisory highlighting the tactics of Russian FSB Center 16 cyber actors, who exploit poorly configured and vulnerable networking devices, primarily routers, to gain access to critical infrastructure networks. These actors scan for devices with active Simple Network Management Protocol (SNMP) agents using common or default community strings, copying device configurations to attacker-controlled servers. They also leverage common vulnerabilities and exposures (CVEs) in Cisco devices, such as CVE-2018-0171 and CVE-2008-4128, to identify and exploit these appliances. The CISA has added CVE-2008-4128 to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply the fixes by July 16, 2026.

The sanctions are part of a broader effort to counter Russia’s malicious cyber activity and protect critical infrastructure. The U.S. and E.U. are aiming to hold those responsible accountable for these actions and deter future attempts to disrupt European stability.

Read the full article at The Hacker News