
Coordinated U.S., EU and UK sanctions expanded from alleged Trickbot leader Vitaly Nikolayevich Kovalev to VPN, hosting and malware providers accused of enabling ransomware operations.
Joint sanctions by the U.S., EU and UK targeted alleged hackers, cybercrime groups and infrastructure providers, broadening pressure on the ecosystem that authorities say supports ransomware. Chainalysis said EU-sanctioned Russian national Vitaly Nikolayevich Kovalev, known as “Stern,” was identified as an alleged senior TrickBot Group leader, with wallets tied to him receiving more than $300 million in ransom payments. Authorities and blockchain investigators have described him as a “CEO-like” figure within the Trickbot and Conti operations, overseeing budgets, hiring and attack planning. The group was said to have more than 100 members, pay salaries in Bitcoin and have hit more than 1,000 organizations worldwide, including Ireland’s Health Service Executive in May 2021, with an estimated $180 million acquired in 2021 alone. OFAC and EU measures also reached VPN, hosting and malware service providers, identified crypto wallet addresses across multiple blockchains and published on-chain addresses that may make it harder for sanctioned actors to move funds through exchanges and financial services.