Infosecurity

Washington sanctions VPN service that helped ransomware gangs hide in plain sight

Published

on

A crackdown with a new target

On Monday, the U.S. Treasury Department slapped sanctions on a VPN provider and its Ukrainian administrator, accusing them of giving ransomware gangs the digital cover they needed to hit American cities, hospitals, schools and businesses. The move marks a notable shift: instead of going after the attackers themselves, Washington is now squeezing the people who sell them the tools to stay invisible.

The sanctioned service, First VPN Service (1VPNS), has been a favorite on Russian-speaking cybercrime forums for years. According to the Treasury, it provided ransomware operators with ways to “hide their identities, disguise malicious software, and evade detection — enabling attacks that have caused billions of dollars in losses to U.S. critical infrastructure providers.”

That’s a hefty charge. And it’s part of a broader strategy that targets not just the gangs, but the entire ecosystem that supports them.

Who got hit and why

The sanctions name two individuals. The first is Dmytro Rashevskyi, a Ukrainian national who ran 1VPNS. The Treasury says Rashevskyi used fake identities to buy infrastructure from companies that might otherwise have refused to work with him — largely because internet service providers had complained about illegal activity coming from 1VPNS servers.

The second is Yegeniy Vladimirovich Silayev, a Belarusian national. Silayev isn’t affiliated with 1VPNS, but he’s accused of selling “cryptors” — software that cloaks malware as harmless files, making it far harder for antivirus tools to detect. Think of it as a digital disguise kit for malicious code.

What the sanctions actually do

For anyone in the U.S., doing business with these designees is now off the table. That’s the immediate legal effect. But sanctions carry another weight, too: a reputational hit that often scares off customers and partners. In the cybercrime world, where trust is already thin, being blacklisted by Washington can be a serious blow to revenue.

The Treasury didn’t name specific ransomware groups that used 1VPNS. It did say that many gangs bought internet infrastructure from the service, and that the VPN was marketed on dark web forums for its ability to support botnets and scammers of all stripes — all while promising total anonymity.

Not a new operation

This isn’t the first time 1VPNS has been in the crosshairs. In May, European law enforcement agencies and the FBI took the service down, saying it had long been a haven for fraudsters and ransomware operators. The service has operated since 2014, and its selling point was simple: no logs, no cooperation with law enforcement.

Rashevskyi marketed 1VPNS as low-risk precisely because “it does not keep logs of users’ identities or activities, and that it refuses to cooperate with law enforcement investigations into illegal activity originating from the servers it rents to customers,” according to the Treasury.

VPNs themselves aren’t evil, of course. Millions of people use them for privacy and security. But like any powerful tool, they can be twisted for malicious ends. The question is how far governments will go to police that gray zone.

Why this approach matters

Targeting infrastructure providers is a smart play. Instead of chasing individual hackers — who often operate from countries with little extradition appetite — the U.S. and its allies are cutting off the services that make large-scale attacks possible. Disrupt one VPN provider, and you disrupt operations for dozens of gangs at once.

That’s the theory, anyway. In practice, the effects can be harder to measure. Cybercriminals are adaptable; they’ll likely move to other services or build their own. But each sanction, each takedown, raises the cost of doing business in the underground economy.

For U.S. critical infrastructure providers — the hospitals, water systems and power grids that have been hit repeatedly — the hope is that these measures will eventually make ransomware less profitable. That’s a long game, and Monday’s action is just one move on the board.

If you’re watching the broader fight against ransomware, this is a trend worth following. The U.S. has increasingly used sanctions as a tool against cybercrime, and the list of designated entities keeps growing. For more on how these operations unfold, check out our coverage of ransomware attack response and cybercrime sanctions enforcement.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version