Treasury Targets Ransomware’s Support Layer

Ransomware crews depend on rented concealment and hosting as much as they depend on their own operators. Treasury is now sanctioning that support layer, which can disrupt how multiple gangs hide their traffic, disguise malware, and buy infrastructure at once. The designations hit First VPN Service (1VPNS), its Ukrainian administrator Dmytro Rashevskyi, and Belarusian national Yegeniy Vladimirovich Silayev, who sold malware "cryptors." Treasury linked the service to attacks on U.S. municipalities, hospitals, schools, and businesses, and said many ransomware groups used it to source internet infrastructure. The action follows the May takedown of First VPN by European law enforcement and the FBI. For defenders, the shift is that ransomware risk now extends upstream into the providers that make campaigns easier to run and harder to attribute. That matters most for teams that track ransomware ecosystems, not just the groups named in an intrusion report.

Part of the PlainSec briefing for 2026-07-15

Sources