← Back to Crime & Security

U.S. Treasury Sanctions Ukrainian Administrator and Belarusian Malware Seller for Ransomware Support

Crime & SecurityAI-Generated & Algorithmically Scored··1 UPDATE

AI-generated from multiple sources. Verify before acting on this reporting.

Update

WASHINGTON — Further details have emerged regarding the U.S. Treasury's sanctions against Ukrainian administrator Dmytro Rashevskyi and Belarusian malware seller Yegeniy Vladimirovich Silayev. New reports confirm additional instances where these individuals facilitated ransomware campaigns targeting American infrastructure, expanding on the initial allegations of enabling malicious cyber activities. The fresh information underscores a broader pattern of collaboration between the designated actors to support illicit financial operations through virtual private network services and malware distribution. These developments reinforce the Treasury Department's assessment that Rashevskyi and Silayev played critical roles in sustaining ransomware ecosystems harmful to U.S. interests. Officials indicate that these newly surfaced activities align with previous findings, solidifying the justification for the July 14 designations under existing executive orders targeting transnational criminal networks.

Original Report —

WASHINGTON — The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) designated a Ukrainian administrator, a Belarusian malware seller, and a virtual private network service provider on Monday for enabling ransomware attacks against American targets.

The sanctions, announced July 14, target Dmytro Rashevskyi of Ukraine and Yegeniy Vladimirovich Silayev of Belarus. The Treasury Department stated that the individuals facilitated malicious cyber activities by providing critical infrastructure to criminal networks operating globally. Also sanctioned is First VPN Service (1VPNS), a provider accused of offering anonymization tools specifically tailored for ransomware actors.

OFAC officials said Rashevskyi and Silayev played central roles in coordinating attacks that disrupted American businesses, healthcare systems, and government entities. The designation marks an escalation in U.S. efforts to dismantle the ecosystem supporting cybercriminals who demand payment in cryptocurrency to restore access to encrypted data.

Rashevskyi is identified as a key administrator within a ransomware infrastructure based in Ukraine. Silayev, operating from Belarus, was cited for developing and selling malware used to infiltrate victim networks before deploying encryption payloads. The Treasury Department noted that both individuals have worked with multiple criminal groups known for targeting U.S. interests.

First VPN Service (1VPNS) faces sanctions for allegedly providing secure communication channels that allowed these actors to evade detection by law enforcement agencies. By masking the digital footprints of attackers, the service enabled ransomware operators to launch campaigns against Americans while remaining anonymous. The Treasury stated that 1VPNS knowingly catered to cybercriminals rather than legitimate users seeking privacy.

The sanctions freeze any assets the designated individuals and entities hold within U.S. jurisdiction and prohibit American persons from engaging in transactions with them. Violations of these restrictions could result in severe civil or criminal penalties.

This action follows a series of high-profile ransomware incidents over the past year that have cost American organizations millions of dollars in ransoms, recovery costs, and lost productivity. The Treasury Department emphasized that disrupting the financial lifelines of cybercriminals is essential to protecting national security interests.

Ukrainian and Belarusian authorities were not immediately available for comment regarding their cooperation with U.S. enforcement efforts or any domestic actions taken against Rashevskyi and Silayev. It remains unclear whether either individual has been arrested in their respective countries or if they are currently operating from safe havens outside of law enforcement reach.

The designation also raises questions about the broader network of service providers supporting ransomware operations globally. While 1VPNS is now sanctioned, similar services may continue to operate under different names or jurisdictions, posing ongoing challenges for international cybersecurity coordination.

Discussion

0 / 2000