Skip to content
U.S. Sanctions First VPN Service (1VPNS) and Belarusian Cryptor Provider for Enabling ...

U.S. Sanctions First VPN Service (1VPNS) and Belarusian Cryptor Provider for Enabling ...

Rescana July 14, 2026

On July 13, 2026, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) announced unprecedented sanctions against the operators of First VPN Service (also known as 1VPNS ) and a Belarusian malware cryptor seller, marking the first time a VPN provider has been formally sanctioned for facilitating ransomware operations. The sanctions target *, the Ukrainian administrator of *1VPNS , and ****, a Belarusian national who developed and sold advanced cryptor tools to ransomware groups. These actors provided critical infrastructure and technical capabilities that enabled ransomware operators to evade detection, obscure attack origins, and maximize the impact of their campaigns against U.S. businesses and critical infrastructure. The action underscores the growing focus of U.S. authorities on disrupting the cybercrime ecosystem at its technical roots, not just targeting ransomware operators but also the enablers who provide essential anonymization and evasion services.

The U.S. Treasury’s action against First VPN Service and the associated cryptor seller represents a significant escalation in the fight against ransomware. This section provides a detailed technical analysis of the sanctioned entities, their operational methods, and the broader implications for the threat landscape.

First VPN Service (1VPNS) operated as a commercial VPN provider since at least 2014, advertising itself on both legitimate and underground cybercriminal forums. The service’s core selling points included a strict “no logs” policy, refusal to cooperate with law enforcement, and technical features designed to maximize user anonymity. These characteristics made 1VPNS a preferred choice for ransomware groups and other cybercriminals seeking to obfuscate their activities.

**** specialized in the development and sale of custom cryptors—malware obfuscation tools that enable threat actors to bypass endpoint detection and response (EDR) solutions, antivirus engines, and network security controls. His cryptors were tailored for ransomware payloads, allowing them to evade both static and dynamic analysis by security products.

1VPNS provided multi-hop proxy and VPN services that allowed ransomware operators to:

Silayev’s cryptors were advanced software wrappers that encrypted, packed, or otherwise obfuscated ransomware binaries. Key technical features included:

These cryptors were sold privately to vetted ransomware groups, with updates and support provided to ensure continued effectiveness against evolving security controls.

The combination of 1VPNS and Silayev’s cryptors created a robust technical ecosystem for ransomware operators. Attackers could:

According to open-source intelligence and U.S. government statements, 1VPNS infrastructure was linked to numerous high-profile ransomware attacks affecting U.S. hospitals, financial institutions, municipal governments, and critical infrastructure providers. The service was a common denominator in several incidents where attackers successfully exfiltrated data and disrupted operations, resulting in billions of dollars in damages.

While the U.S. Treasury did not attribute the use of 1VPNS and Silayev’s cryptors to specific ransomware families in its public release, independent threat intelligence reporting has associated these services with groups operating LockBit , Conti , and other major ransomware strains. The simultaneous sanctions by the U.K. and E.U. against Russian state-linked cyber units (including GRU Unit 29155 and FSB Centre 16 ) highlight the overlap between criminal and state- cyber operations, though no direct attribution to an APT group was made in the U.S. action.

While the U.S. Treasury did not publish specific indicators of compromise (IOCs) in its release, organizations are strongly advised to consult the latest FBI and CISA advisories for updated lists of:

Key MITRE ATT&CK techniques observed in these campaigns include:

In May 2026, European law enforcement, with support from the FBI, dismantled the 1VPNS infrastructure, seizing servers and taking down associated domains. The U.S. sanctions freeze any assets under U.S. jurisdiction and prohibit U.S. persons from engaging in transactions with the designated individuals and entities.

Organizations are urged to:

The sanctions against 1VPNS and Silayev’s cryptor operation signal a new phase in the global response to ransomware. By targeting the technical enablers of cybercrime, U.S. authorities are seeking to disrupt the supply chain that allows ransomware groups to operate with impunity. This approach raises the stakes for service providers who knowingly cater to cybercriminals and underscores the importance of robust due diligence and threat intelligence in third-party risk management.

Rescana’s Third-Party Risk Management (TPRM) platform empowers organizations to continuously monitor, assess, and mitigate cyber risks across their entire supply chain. Our advanced threat intelligence and automation capabilities help you stay ahead of emerging threats, ensure compliance, and protect your business from the evolving tactics of ransomware operators and their enablers. If you have any questions this advisory or need assistance with your cyber risk management program, we are happy to help at [email protected].

Extracted Entities