news.mlab.sh
Back to the feed
threat-intel

VPN service favored by ransomware groups is sanctioned by US

High
Summary

The U.S. government has sanctioned a VPN service, First VPN, and its administrator, citing their role in enabling ransomware attacks against critical U.S. infrastructure. The sanctions target not only the VPN providers but also the tool suppliers who facilitate these attacks, aiming to disrupt a significant number of ransomware groups' operations.

The U.S. government has imposed sanctions on First VPN, a VPN service, and its Ukrainian administrator, Dmytro Rashevskyi, due to their alleged support of ransomware groups targeting American municipalities, hospitals, and businesses. According to a Treasury Department press release, First VPN provided ransomware operators with tools to conceal their identities, disguise malicious software, and evade detection, resulting in billions of dollars in losses to U.S. critical infrastructure. Dmytro Rashevskyi utilized fake identities to acquire infrastructure from companies hesitant to work with him due to complaints about illegal activity originating from First VPN servers. A separate individual, Yegeniy Vladimirovich Silayev, a Belarusian national, was also designated for allegedly selling “cryptors,” methods designed to make malware more difficult to detect and more effective. First VPN has operated since 2014 and has been promoted on Russian cybercrime forums and dark web sites for its ability to support botnets and scammers, while promising anonymity to its users. European law enforcement agencies took down First VPN in May, following concerns about its use by cybercriminals. The Treasury Department emphasized that these sanctions represent a significant disruption to a large number of ransomware groups’ operations by targeting both the VPN providers and the tool suppliers.

Read the full article at The Record