# US Treasury Sanctions VPN and Malware Providers Powering Ransomware Campaigns, Dismantles Billion-Dollar Criminal Infrastructure
The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has taken decisive action against the criminal enablers behind ransomware attacks, sanctioning First VPN Service (1VPNS), its administrator, and a malware tool developer in a coordinated international enforcement operation. The move represents a strategic shift in how authorities are disrupting ransomware ecosystems—targeting not just the attackers themselves, but the infrastructure and tool providers that make their operations possible.
## The Sanctions Action
On July 14, OFAC designated 1VPNS and its administrator, Dmytro Rashevskyi, along with Yegeniy Vladimirovich Silayev, a Belarusian national who sells cryptors (malware obfuscation tools). Under the sanctions, all property belonging to these individuals and entities within U.S. jurisdiction is blocked, and U.S. persons and businesses are prohibited from conducting transactions with them.
"These actors supplied ransomware groups with tools to hide their identities, disguise malicious software, and evade detection—enabling attacks that have caused billions of dollars in losses to U.S. critical infrastructure providers," said State Department spokesperson Thomas Pigott in a statement.
The enforcement action was coordinated with the United Kingdom's Foreign, Commonwealth & Development Office, and came the same week the European Union and UK jointly sanctioned dozens of Russian individuals and entities over state-coordinated hacking operations.
## First VPN Service: A Decade of Criminal Enablement
1VPNS emerged in 2014 as a virtual private network provider with an explicit criminal clientele. The service openly advertised on underground cybercriminal forums that it maintained zero-log policies, kept no records of user activity or identities, and would refuse to cooperate with law enforcement requests.
The VPN service became ubiquitous in the ransomware underworld. According to Europol, 1VPNS's infrastructure "surfaced in nearly every major cybercrime investigation" the agency supported, making it one of the most widely deployed anonymization tools for criminal operations globally.
To maintain its criminal operations despite abuse complaints, Rashevskyi employed deception tactics:
### Victims and Impact
Ransomware campaigns leveraging 1VPNS infrastructure victimized:
| Sector | Examples |
|--------|----------|
| Healthcare | U.S. hospitals (specific names redacted in official statements) |
| Finance | Banks and financial services firms |
| Government | Municipal governments and public agencies |
| Critical Infrastructure | Power grids, water systems, and other essential services |
Officials estimate that ransomware operations using 1VPNS have caused billions of dollars in cumulative losses across the United States.
## Operation Saffron: The International Takedown
While the current sanctions mark the formal U.S. response, the actual dismantling of 1VPNS occurred months earlier. In May 2026, European law enforcement executed "Operation Saffron," a coordinated takedown led by French and Dutch authorities with support from the FBI's Boston Field Office.
### The Operational Timeline
December 2021: Law enforcement agencies began infiltrating 1VPNS infrastructure, placing undercover operatives inside the VPN's systems to gather intelligence.
May 2026: Full takedown executed. The operation resulted in:
The intelligence collected during Operation Saffron provided authorities with a comprehensive view of the criminal ecosystem using 1VPNS—a database that will inform ongoing investigations into ransomware groups worldwide.
## Cryptors: The Second Weapon
The second prong of the sanctions targets Yegeniy Silayev, a developer and seller of cryptors—sophisticated obfuscation tools that help ransomware and other malware evade antivirus, endpoint detection and response (EDR), and other defensive technologies.
### How Cryptors Work
Cryptors (also called crypters or packers) are legitimate security tools repurposed for criminal use. They work by:
1. Encrypting the malware payload to hide its true code from signature-based detection
2. Modifying file hashes so antivirus databases no longer recognize the threat
3. Injecting obfuscation layers that confuse behavioral analysis systems
4. Stripping metadata that identifies the malware family
For ransomware groups, cryptors are essential commodities. Without them, static signatures and heuristic detection would catch most variants. With them, a single ransomware strain can spawn dozens of "new" samples that pass through defenses undetected.
Silayev's cryptor services are particularly dangerous because they target high-volume detection systems that organizations rely on. By making each ransomware deployment unique, his tools force defenders to implement more sophisticated detection logic—or miss the attack entirely.
## The Broader Picture: Attacking the Supply Chain
Historically, law enforcement focused on arresting ransomware operators themselves—the LockBit gang, the BlackCat/ALPHV crew, Cl0p operators, and others. These arrests matter, but they often create a "whack-a-mole" dynamic: bust one group, another rises to fill the void.
The current sanctions strategy reflects a different approach: disrupting the criminal supply chain. By targeting infrastructure providers, anonymization services, and tool developers, authorities aim to raise the baseline cost of launching ransomware operations. Even if new ransomware groups form, they'll face friction acquiring the tools and infrastructure they need.
## Implications for Organizations
### Immediate Risks
The sanctions do not eliminate 1VPNS or Silayev's cryptors—they've already been infiltrated and partially dismantled. However:
### Strategic Considerations for Defenders
Organizations should treat this as a reminder of fundamental defensive principles:
Detection diversification: Don't rely on signature-based antivirus. Implement behavior-based detection, network monitoring, and threat hunting to catch variants that evade encryption-based obfuscation.
Lateral movement blocking: Even if ransomware bypasses initial defenses, segmentation and access controls can limit its spread across your environment.
Backup hygiene: Assume encryption will eventually succeed against some percentage of attacks. Maintain offline, immutable backups that ransomware cannot reach.
Threat intelligence: Track which ransomware groups have been disrupted and which remain operational. Adjust your threat model accordingly.
## What's Next
The sanctions represent the opening move in a broader campaign against ransomware infrastructure. Expect:
---
## HackWire Analysis
The strategic importance of these sanctions lies not in 1VPNS's complete elimination—that already happened in May—but in signaling and escalation. By formally sanctioning infrastructure providers alongside the service's dismantlement, OFAC is declaring that the U.S. views anonymization tools and obfuscation services as legitimate targets for financial and legal punishment.
This matters because it changes the calculus for legitimate VPN providers, cryptography tool developers, and hosting companies. A provider considering whether to ignore abuse complaints about ransomware users now faces concrete risk: sanctions, asset freezes, and criminal liability. That friction is real.
However, the sanctions regime has a critical blind spot: they only reach providers and tool developers who operate in jurisdictions where enforcement is credible. Silayev, a Belarusian national, may face limited practical consequences if Belarus does not cooperate with U.S. enforcement. Similarly, criminal infrastructure providers operating in Russia, North Korea, or other adversarial jurisdictions remain beyond practical reach.
The more important dynamic is territorial—European law enforcement's willingness to seize 1VPNS infrastructure and share the intelligence with U.S. partners. That cooperation created the intelligence base for effective sanctions and ongoing investigations. As ransomware groups migrate to alternative providers, expect law enforcement to target them with similar speed. The message is not "we can eliminate ransomware," but "we can and will disrupt the infrastructure that enables it at scale."
For defenders, the immediate lesson is pragmatic: ransomware groups will experience supply-chain friction over the next 6-12 months as they adapt to the loss of trusted infrastructure. That's not a window to relax vigilance—it's a period of increased urgency to implement detection and response capabilities before attackers stabilize on new tools and providers.
— HackWire Editorial
## Related Coverage